9112 Emergency Hub: Germany (DE)

Flag of Germany

This protocol is for critical cyber incidents affecting legal entities operating within German jurisdiction. Ensure all internal containment actions are documented to comply with the strict regulatory deadlines detailed below.

1. Operational & NIS2/BSIG Early Warning (24 Hours)

Operators of essential services (KRITIS) and other regulated entities must report significant cyber incidents within 24 hours.

  • Authority: Bundesamt für Sicherheit in der Informationstechnik (BSI) / CERT-Bund
  • Direct Reporting Portal: BSI Meldestelle (MIP)
  • Emergency Contact: meldestelle@bsi.bund.de

2. GDPR Data Breach Notification (72 Hours)

If the incident involves the compromise of personal data, a formal notification must be submitted within 72 hours.

  • Authority: Federal (BfDI) or respective State Data Protection Authority (Landesdatenschutzbeauftragte)
  • Direct Reporting Portal: BfDI Portal
  • Contact: Via specific state portal depending on HQ location.

3. Law Enforcement / Cybercrime (Optional but Recommended)

For incidents involving extortion, ransomware, or state-sponsored actors, coordinate with federal law enforcement.

  • Authority: Bundeskriminalamt (BKA) or regional ZAC (Zentrale Ansprechstelle Cybercrime)
  • Contact: BKA Cybercrime Contact

← Back to European Master Matrix