(1) In the case of a significant security incident, the BSI may order essential entities and important entities to notify the recipients of their services without delay of that significant security incident, where it could affect the provision of the respective service. The BSI informs the federal supervisory authority competent for the entity of instructions under the first sentence. Notification under the first sentence may also take place through publication on the entity's website.
(2) Essential entities and important entities from the sectors of finance, social insurance benefits and basic income support for job seekers, digital infrastructure, management of ICT services, and digital services, inform the recipients of their services potentially affected by a significant cyber threat, and the BSI, without delay, of all measures or remedial measures that those recipients can take in response to that threat. The entities at the same time also inform those recipients of the significant cyber threat itself. The obligations under the first or second sentence apply only where, weighing the interests of the entity and of the recipient, the recipient's interests predominate.
Home› Cybersecurity & IT Security› BSIG-EN
Part 3 · IT Security of Entities › Chapter 2 · Risk Management, Reporting, Registration, Verification and Notification Obligations › Section 35
Notification obligations
←→ also move between sections