(1) A person operating a public telecommunications network or providing publicly available telecommunications services submits to the Federal Network Agency and to the Federal Office for Information Security:
1. without delay, but no later than within 24 hours of becoming aware of a significant security incident, an early warning notification, stating whether it is suspected that the significant security incident is attributable to unlawful or malicious acts, or could have cross-border effects;
2. without delay, but no later than within 72 hours of becoming aware of a significant security incident, an incident notification, confirming or updating the information referred to in point 1 and providing an initial assessment of the significant security incident, including its severity and impact, and, where available, the indicators of compromise;
3. on request by the Federal Network Agency or the Federal Office for Information Security, an intermediate report on relevant status updates;
4. no later than one month after transmission of the notification of the significant security incident under point 2, subject to subsection (2), a final report containing:
a) a detailed description of the significant security incident, including its severity and impact;
b) particulars of the type of threat or underlying cause that is likely to have triggered the security incident;
c) particulars of the remedial measures taken and ongoing;
d) where applicable, the cross-border effects of the significant security incident. Section 42(4) and section 43(4) of the Federal Data Protection Act apply correspondingly.
(2) Where the significant security incident is still ongoing at the time referred to in subsection (1), first sentence, point 4, the party concerned submits, instead of a final report, a progress report at that time and a final report within one month of completion of handling of the significant security incident.
(3) A security incident is deemed significant where
1. it has caused, or can cause, severe operational disruption or financial loss for the operator of public telecommunications networks or provider of publicly available telecommunications services concerned, or
2. it has affected, or can affect, other natural or legal persons through considerable material or non-material damage.
(4) The Federal Network Agency lays down details of the notification procedure. The Federal Network Agency may require a detailed report on the security incident and the remedial measures taken.
(5) The Federal Network Agency transmits an acknowledgement of receipt of the notification to the parties obligated under subsection (1), first sentence, without delay and, where possible, within 24 hours of the early warning notification under subsection (1), first sentence, point 1. The Federal Office for Information Security may, on request by the parties obligated under subsection (1), first sentence, provide additional technical support, guidance, or operational advice on remedial measures. The Federal Office for Information Security informs the Federal Network Agency of measures under the second sentence.
(6) Where necessary, the Federal Network Agency informs the national regulatory authorities of the other Member States of the European Union and the European Union Agency for Cybersecurity of the security incident. Where public awareness is necessary to prevent or address a significant security incident, or where disclosure of the significant security incident is otherwise in the public interest, the Federal Network Agency may, after hearing the parties obligated under subsection (1), first sentence, inform the public or require the parties obligated under subsection (1), first sentence, to provide this information.
(7) In the case of a particular and significant danger of a security incident, the parties obligated under subsection (1), first sentence, inform the users potentially affected by this danger of all possible protective or remedial measures that can be taken by the users, and, where appropriate, of the danger itself. Section 42 of the BSI Act applies correspondingly.
(8) The Federal Network Agency submits to the Commission, the European Union Agency for Cybersecurity, and the Federal Office for Information Security, once a year, a summary report on the notifications received and the remedial measures taken.
Home› Telecommunications & Digital Services› TKG (EN)
Part 10 · Public Safety and Emergency Preparedness › Division 1 · Public Safety › Section 168
Notification of a security incident
←→ also move between sections