Incident reporting and risk

Guided authority flows and a risk register, next to your evidence.

OptiTech's incident flows guide you through authority reporting with the legal deadlines wired in, so a 24-hour early warning is a checklist instead of a crisis. Use them for NIS2 incidents to MSB, personal data breaches to IMY, and the drills that make the real thing routine.

What makes OptiTech's incident handling different from an alert channel?

  • Deadlines wired in. The countdown starts the moment you open the incident, with each authority's clock (24 hours, 72 hours, one month) visible the whole way. No spreadsheet math under pressure.
  • Pre-filled forms. The MSB and IMY forms populate from your incident data, your on-call contact list is attached, and communication templates for customers, press, and internal channels are one click away.
  • Connected to your controls. Incidents link to the controls that failed, feed the risk register, and land in the same evidence chain your auditor reviews.

Incidents run on the same platform as your evidence, so the post-incident report writes itself from data that already exists.

Run a test drill before you need the real thing. Teams that have drilled once handle the 24-hour deadline as process instead of panic.

Reporting duties are yours

OptiTech pre-fills, tracks, and reminds, but the legal duty to report stays with your organization. Nothing is submitted to an authority without your explicit confirmation.

Get started

A flow, not a form

An incident in OptiTech is always a sequence (detect, assess, report, close) and always produces a record: the timeline, the decisions, who was notified, and what was filed.

That makes the flows a fit for reportable incidents, not for routine alerts. Routine drift (a failed check, a missing signature) stays in the task system with its own lifecycle. An incident starts when something meets your reporting threshold, and the assessment step exists precisely to make that call with the criteria in front of you:

Early warning to MSB              due in 21h 14m
Incident report to MSB            due in 69h 14m
Final report to MSB               due in 29 days

The risk register works the same way in reverse: risks are scored on likelihood times impact, linked to mitigating controls, and updated by reality. When an incident closes, its lessons land as risk updates:

Risk: Ransomware via phishing     score 12 -> 16
Linked controls: 3 verified, 1 drifted
Treatment plan: MFA hardening     owner: Dana Smith

When to use the incident flows

  • NIS2 incidents: significant disruptions to your services, reported to MSB on the three-step clock. See NIS2.
  • Personal data breaches: the GDPR assessment and the 72-hour IMY flow, including notification templates for those affected. See GDPR.
  • DORA incidents: classification and reporting for financial-sector requirements. See DORA.
  • Drills: the full sequence without submitting anything, for onboarding and annual exercises.
  • Customer notifications: incidents that trigger contractual duties to customers, with the communication templates attached.
  • Near misses: log what almost happened, feed the risk register, skip the authority steps.

How incidents fit with your program

Incident handling is a capability, not a silo. The flows draw on everything else the platform knows. Two common shapes:

  • The incident starts in OptiTech. A drifted control escalates: what the check saw becomes the incident's first evidence, and the affected requirement is already linked when you open the flow.
  • The incident starts outside. Your SOC, MSP, or an employee reports something. You open an incident, and OptiTech pulls in the relevant controls, contacts, and deadlines while you assess.

The three deadlines

StepdeadlineWhat OptiTech preparesWhere it goesIncluded on
Early warning24hPre-filled MSB form, on-call listMSBEvery plan
Incident report72hSeverity and impact assessmentMSBEvery plan
Final report1 monthCauses, mitigation, lessonsMSBEvery plan
Breach notification72hRisk assessment, notification textsIMYEvery plan
DORA classificationper DORAClassification and reportSupervisorEnterprise

Need help?

Join our Discord Server to ask questions or see what others are doing with OptiTech. For paid plan support options, see Support.

Was this page helpful?