Why incident management isn't a luxury
The question isn't whether an IT security incident will happen — it's when. Ransomware, data loss, DDoS attacks, hardware failures, or human error: no system is completely secure. What matters is how quickly and how well-coordinated your organization's response is.
Companies without an emergency plan typically need several weeks on average to restore normal operations after a serious ransomware attack. With good incident management, this can be days or hours.
Business Continuity Management (BCM)
BCM is the overarching framework: how does your organization ensure that critical business processes can be maintained or quickly restored even in an emergency?
Business Impact Analysis (BIA)
Before an emergency plan can be built, you need clarity: which processes are critical? What happens if your ERP system is down for 4 hours? What if it's down for 4 days? The BIA quantifies these impacts — in euros, in customer relationships, in regulatory risk.
Recovery Time Objective (RTO) and Recovery Point Objective (RPO)
Based on the BIA, you define how quickly systems must be restored (RTO) and how much data loss you can tolerate at most (RPO). These targets determine your backup strategy and recovery planning.
IT incident management
Emergency concept
The emergency concept describes the fundamental structure for handling IT emergencies: escalation paths, responsibilities, internal and external communication, and decision-making processes.
It sounds bureaucratic — but in a real emergency, when no one can think calmly, a clear concept is the most valuable tool you have.
Emergency plans (playbooks)
For the most common scenarios, we recommend specific emergency plans (playbooks):
- Ransomware attack: what to do in the first 15 minutes, 2 hours, 24 hours?
- Data breach: how does the internal assessment and external notification process work?
- Critical infrastructure outage: how are backup systems activated?
- Phishing compromise: when is the account locked, when is IT alerted?
Incident response process
When an incident occurs, you need clarity on every step:
- Detection and reporting — how do you learn about an incident? Who reports it to whom?
- Initial assessment — what happened? How severe is it?
- Containment — preventing the damage from spreading.
- Analysis — what exactly happened? Which systems and data are affected?
- Remediation — removing malware, cleaning systems.
- Recovery — restoring systems from secure backups, normalizing operations.
- Post-incident review — what can we learn? What needs to improve?
Emergency exercises
The best emergency concept is useless if no one knows it. We recommend at least one tabletop exercise per year: a simulated emergency scenario played out in a conference room, without affecting real systems.
These exercises reveal gaps in the emergency plan, train the people responsible, and build confidence — for when a real emergency happens.
Coordination with external parties
In an emergency, you're rarely on your own. We support you in coordinating with:
- BSI-CERT: the reporting office for cyberattacks on critical infrastructure
- Public prosecutors / cybercrime units: for incidents with criminal relevance
- Data protection authority: for reportable data breaches (72-hour deadline)
- Insurers: for cyber insurance with notification deadlines
- External IT forensics experts: for evidence preservation and damage analysis
Integration with data protection
Incident management and data protection overlap significantly: a cyberattack in which customer data is exfiltrated is both an IT security incident and a reportable data breach. AGIDAT can cover both perspectives in an integrated way — so you don't have to coordinate between different advisors.