Many companies still imagine a cyberattack like a scene from a movie: the screen goes black, a hacker’s message appears, someone calls IT in panic, and management waits for “the technical people” to fix it.
In reality, the most dangerous moment often looks much quieter.
Email stops working. The accounting system becomes unusually slow. One employee cannot access a client portal. Someone notices strange activity in Microsoft 365. A supplier asks why they received a suspicious invoice from a company mailbox.
At first, nobody says: “We have a cybersecurity incident.”
People say other things.
“Probably a server issue.”
“Let’s check it tomorrow.”
“Maybe it’s just an IT problem.”
“Let’s not create panic.”
And that is exactly where the real problem begins.
After a cyberattack, a company is not only fighting technology. It is fighting time, responsibility and evidence. The first hours may determine not only whether systems can be restored, but also whether the company correctly identifies the event, understands who must be informed, determines whether personal data was affected, evaluates the impact on clients, and decides whether the incident must be reported to a regulator, CSIRT, customer, insurer or data protection authority.
For many small and medium-sized companies, this is an uncomfortable truth: a cyberattack can very quickly stop being a technical problem and become a legal, contractual and board-level problem.
Across the European Union, the regulatory direction is clear. Companies are no longer expected only to “have security”. They are increasingly expected to understand risk, monitor events, respond, document and report serious incidents.
NIS2 introduces cybersecurity obligations for essential and important entities across many sectors of the economy, including energy, transport, healthcare, banking, digital infrastructure, public administration, digital providers, certain areas of manufacturing, chemicals, food, waste management and postal services. Under NIS2, significant incidents follow an escalating reporting logic: an early warning within 24 hours, a fuller notification within 72 hours and a final report later, according to the procedure set out in the directive.
This is not a cosmetic change. It means that a company must be able to quickly assess whether an event is serious, what impact it has and whether it triggers reporting obligations.
The penalties are not symbolic either. NIS2 requires national law to allow maximum fines of at least EUR 10 million or 2% of global annual turnover for essential entities, whichever is higher, and at least EUR 7 million or 1.4% for important entities. The details depend on national implementation, but the message is already clear: cybersecurity is no longer just an internal IT matter.
Then there is GDPR.
Many companies make the mistake of treating a data breach as a separate “privacy issue”, disconnected from cybersecurity. In practice, phishing, ransomware, compromised email accounts, cloud misconfiguration or unauthorized CRM access can very quickly become a personal data breach.
If a breach is likely to result in a risk to the rights and freedoms of individuals, it must generally be reported to the supervisory authority within 72 hours after becoming aware of it. In serious cases, GDPR fines may reach EUR 20 million or 4% of total worldwide annual turnover, whichever is higher.
There is also DORA, especially relevant for the financial sector and its technology suppliers. DORA focuses on digital operational resilience, ICT risk management, incident handling, resilience testing and third-party technology risk. This matters not only for banks or insurers. It also matters for software companies, IT providers, cloud partners, platform operators and service providers working with financial entities.
In practice, regulatory pressure may arrive through the contract.
A larger client may ask a smaller supplier about cybersecurity, incident procedures, business continuity, logging, monitoring and evidence — because the larger client itself is accountable.
And this is the point many smaller companies still miss.
Being small does not automatically mean being outside the problem.
If a company has access to client data, systems, cloud environments, email accounts, APIs, documents, advertising accounts, operational processes or critical business workflows, it may become part of a much larger risk.
Attackers do not always choose the biggest company.
They choose the easiest path in.
That is why a small service provider, software house, accounting office, marketing agency, IT integrator, SaaS vendor, law firm, logistics partner, industrial subcontractor or external system administrator can suddenly find itself in the middle of an issue that is far bigger than expected.
Not because it has become a regulated giant overnight.
But because it serves someone who is regulated, processes protected data or has access that can be used against a larger organization.
The biggest risk is not always the regulatory fine.
The fine is often the final consequence.
Before that comes something that may be even more damaging: loss of trust.
A client may ask:
When did you notice the incident?
Do you have logs?
Which account was compromised?
Was any data copied?
Did the incident affect our information?
Can we continue working with you?
Do we need to report the breach ourselves?
Did your lack of monitoring mean nobody saw the problem for weeks?
At that moment, “we have an IT person” is not enough.
“We have antivirus” is not enough.
“Nothing like this has ever happened before” may even sound dangerous, because the absence of a known incident is not proof of security. Sometimes it is only proof that the company did not have the tools to detect one.
That is why incident reporting should be understood as more than a legal formality. It is a test of organizational maturity.
To report something, a company first has to know that something happened.
To know that something happened, it needs visibility.
To have visibility, it needs to monitor systems, accounts, network activity, access, anomalies and behavior that deviates from normal patterns.
To report responsibly, it needs evidence.
And to have evidence, it needs to collect it before the incident — not after it.
During a crisis, you do not build procedures.
During a crisis, you discover whether your procedures were real.
This is especially important for CEOs. European regulations are increasingly moving cybersecurity from “an IT topic” to a risk management topic. The board does not need to read every technical log, but it should know who qualifies an incident, who contacts legal counsel, who communicates with the client, who has access to evidence, who decides whether a report must be filed and how quickly the company can reconstruct the facts.
Because if a company does not know what happened, when it started, who was affected and what data may have been compromised, then it is not managing an incident.
It is managing assumptions.
And assumptions are a very weak foundation for legal, business and reputational decisions.
Smaller companies should pay attention to one more mechanism: requirements may come not only from regulators, but from the market itself. A larger client, bank, insurer, investor, auditor or business partner may ask about cybersecurity procedures even when the smaller company believes that “NIS2 does not apply to us”.
In practice, without monitoring, logs, incident response procedures and security evidence, a company may lose not because of price or product quality, but because of lack of trust.
This is the point where cybersecurity becomes part of competitiveness.
It does not mean that every small company must immediately build a corporate-level security operations center. But it does mean that companies must stop operating in the dark.
They need to know what is critical. What data they process. Who has access. How they detect unusual events. How they document incidents. Who decides whether to report. How quickly they can reconstruct what happened. And how they can show a client that risk is controlled — not merely declared.
Because the most expensive sentence after a cyberattack is:
“We don’t know.”
We don’t know when it started.
We don’t know whether data left the company.
We don’t know who had access.
We don’t know whether the client is affected.
We don’t know whether we had to report it.
We don’t know whether we reacted too late.
In the new legal and business reality, that lack of knowledge can cost more than the technical failure itself. It can cost a contract, reputation, client trust and, in certain cases, significant financial penalties.
So the question “Who must report a cyber incident after an attack?” is important, but incomplete.
The real question for management is this
Can our company detect, document and responsibly assess an incident before the critical hours are gone?
If the answer is “I don’t know”, that is exactly where the work should begin.
Do smaller companies really understand when a cyberattack stops being only an IT issue and becomes a legal and business obligation?
Are larger clients already asking suppliers about monitoring, logs, procedures and incident response evidence?
Have you seen situations where, after an incident, the biggest problem was not the attack itself, but the lack of evidence and the lack of a clear decision on what had to be reported?
Because many companies today do not need another cybersecurity slogan.
They need a brutally simple answer to one question:
Do we know what we will do in the first 72 hours?
Further reading: our NIS2 network monitoring checklist, the NIS2 readiness overview and what NetSenX detects and how each alert explains itself.
Written by the NetSenX Team at TriStiX S.L. This article is general information, not legal advice. Questions: [email protected].