9112 Emergency Hub: Austria (AT)

Flag of Austria

This protocol is for critical cyber incidents affecting legal entities operating within Austrian jurisdiction. Ensure all internal containment actions are documented to comply with the strict regulatory deadlines detailed below.

1. Operational & NIS2 Early Warning (24 Hours)

Under NISG/NIS2, operators of essential services must report significant incidents within 24 hours.

2. GDPR Data Breach Notification (72 Hours)

If the incident involves the compromise of personal data, a formal notification must be submitted within 72 hours of becoming aware of the breach.

3. Law Enforcement / Cybercrime (Optional but Recommended)

For incidents involving extortion, ransomware, or state-sponsored actors, coordinate with federal law enforcement parallel to regulatory reporting.

  • Authority: Bundeskriminalamt (BKA) – Cybercrime Competence Center (C4)
  • Contact: C4 Contact Details

← Back to European Master Matrix