{"id":10169,"date":"2026-08-31T05:40:55","date_gmt":"2026-08-31T03:40:55","guid":{"rendered":"https:\/\/qdata.pl\/blog\/nis2-infrastructure-what-must-be-in-the-runbook\/"},"modified":"2026-08-31T07:47:11","modified_gmt":"2026-08-31T05:47:11","slug":"nis2-infrastructure-what-must-be-in-the-runbook","status":"publish","type":"post","link":"https:\/\/qdata.pl\/pl\/blog\/nis2-infrastructure-what-must-be-in-the-runbook\/","title":{"rendered":"NIS2 a infrastruktura: co musi by\u0107 w runbooku"},"content":{"rendered":"<div class=\"qdata-blog-tldr\">\n<h3>TL;DR<\/h3>\n<ul>\n<li>NIS2 accountability lands on management \u2014 but auditors test whether operators can <em>execute<\/em> within legal timelines.<\/li>\n<li>Your runbook must name systems, owners, comms paths and evidence locations \u2014 not generic &#8220;activate IR plan&#8221;.<\/li>\n<li>Early warning (24h) and notification (72h) require pre-agreed severity thresholds and draft templates.<\/li>\n<li>Backup without tested restore is theatre; keep last restore report where legal can find it.<\/li>\n<\/ul>\n<\/div>\n<p>Regulation talk often stops at governance charts. For infrastructure and security teams, NIS2 translates into <strong>time-bound actions<\/strong> when something breaks: classify, contain, notify, preserve evidence, recover. If those actions live only in a PDF that legal reviewed once, the first real incident will invent a new process at 02:00 \u2014 and counsel will ask for timestamps you do not have. NIS2 does not care that your policy folder is thick. It cares whether the person on call can open a runbook, follow steps tied to real systems, and produce evidence that notifications happened within statutory windows.<\/p>\n<p>We have supported essential and important entities across manufacturing, logistics and IT services through NIS2 readiness. The gap is rarely missing policies. It is missing <em>operability<\/em>: severity definitions that five people interpret five ways, backup reports stored on a share only the backup admin knows, and supplier phone numbers that reach voicemail during an outage. Runbooks fix that gap \u2014 not by adding pages, but by naming who does what on which system before adrenaline is involved.<\/p>\n<h2>Runbook sections that must exist on day one<\/h2>\n<p><strong>Severity matrix tied to NIS2 triggers<\/strong> is non-negotiable. Define what constitutes a significant incident for your services: customer outage duration, data categories affected, cross-border impact, ransom demands against critical systems. Map severities to internal crisis team activation, early warning draft, customer communications and regulator notification. Ambiguity here costs days. A managed services provider we advised spent the first eighteen hours of a ransomware event debating whether customer PII was &#8220;affected&#8221; because files were encrypted but not exfiltrated \u2014 while the 24-hour clock ticked.<\/p>\n<p><strong>Kontakt tree with backups<\/strong> must name deputies for CISO, DPO, legal, communications, cloud provider TAM, ISP and MSSP. Include after-hours numbers and contractual escalation clauses \u2014 not &#8220;open a ticket&#8221; as the only path. During a DDoS against a Polish e-commerce operator, the runbook&#8217;s missing secondary ISP contact added four hours to mitigation while sales leadership learned about the outage from Twitter.<\/p>\n<p><strong>Technical preserve-and-contain steps per tier<\/strong> turn generic IR plans into executable checklists. For critical systems document how to isolate a network segment, disable compromised credentials, snapshot logs to immutable storage and maintain chain of custody for disk images. &#8220;Disconnect from network&#8221; is insufficient if you cannot state which switch port, VLAN or security group rule applies. Operators should not improvise containment under legal observation.<\/p>\n<h2>Backup, restore and supplier maps<\/h2>\n<p><strong>Backup and restore proof<\/strong> belongs in the runbook body, not an appendix nobody opens. RPO and RTO per tier, last successful restore test date, who signed it, where reports live. NIS2 emphasises resilience \u2014 untested backup is a finding and a fiction. One industrial client discovered during tabletop that their &#8220;nightly backup&#8221; of a file server had been failing silently for six weeks because a credential rotated without updating the job. The runbook now links directly to the backup console dashboard and names who checks green status daily.<\/p>\n<p><strong>Supplier and sub-processor maps<\/strong> document which incidents require notifying which vendor within which SLA. Cloud shared responsibility means your runbook references provider status pages, support tiers and evidence export procedures. When identity compromise spans Microsoft 365 and your on-prem AD, the runbook should already state who opens the Microsoft case, who preserves Entra sign-in logs and who correlates with on-prem DC logs \u2014 not discover that split at 03:00.<\/p>\n<h2>Early warning and notification mechanics<\/h2>\n<p>Schematami \ud83d\ude42 <strong>24-hour early warning<\/strong> i wi\u0119cej. <strong>72-hour notification<\/strong> obligations punish improvisation. Pre-draft templates with placeholders for affected services, data categories, estimated user impact and containment status. Pre-agree severity thresholds that trigger legal review \u2014 not &#8220;we will call legal if it seems bad.&#8221; Legal needs time to wordsmith; operators need time to preserve evidence. Parallel workstreams require a shared timeline document updated hourly during significant incidents.<\/p>\n<p>Templates should exist in the language regulators expect and in plain language for customer comms \u2014 often different documents, same facts. Store them where on-call can access without hunting through email. A logistics firm keeps draft packs in the incident channel wiki with last-reviewed dates; legal signs quarterly that placeholders still match entity structure after acquisitions.<\/p>\n<h2>Tabletop beats another policy version<\/h2>\n<p>Run a ninety-minute exercise: ransomware on a hybrid file service, or IAM compromise with malicious mail rules. Time each decision \u2014 classify, contain, notify internal leadership, draft early warning, request backup restore. Gaps become runbook edits the same week, not after an audit finding. Tabletops also reveal whether your tooling matches your story: if the runbook says &#8220;export logs to immutable storage&#8221; but nobody has tested the export in six months, fix the tooling or fix the runbook.<\/p>\n<p>Repeat tabletop scenarios quarterly with rotating roles \u2014 the CISO should not always play commander. NIS2 expects organisational capability, not heroics from one person who remembers the 2019 incident. Document lessons learned with ticket IDs; auditors and regulators increasingly ask for exercise history, not only policy existence.<\/p>\n<h2>Scenario: cloud-first SaaS vs hybrid manufacturing<\/h2>\n<p>A cloud-first SaaS vendor&#8217;s runbook emphasises tenant isolation, customer notification lists pulled from CRM, and coordinated status page updates with sub-processor notification clauses in contracts. Evidence lives in ticketing, chat exports and cloud audit logs with retention locked.<\/p>\n<p>A hybrid manufacturer adds OT segments, on-prem historians and physical safety interlocks. The same NIS2 timelines apply, but containment steps reference VLANs touching PLCs and a process safety officer who must approve network isolation that could stop a line. One runbook does not fit both without tier-specific chapters \u2014 and that is correct. What fails is a single generic IR PDF pasted into both environments without customisation.<\/p>\n<h2>What to do next<\/h2>\n<p>Open your incident runbook tonight. Highlight every step that says &#8220;relevant team&#8221; or &#8220;as appropriate&#8221; and replace them with names, systems and links. Schedule a ninety-minute tabletop before your next policy review. Secure infrastructure without operable incident mechanics fails NIS2 in practice. Our <a href=\"\/pl\/service\/secure-public-cloud-infrastructure\/\">Bezpieczna infrastruktura chmury publicznej<\/a> and audit teams align technical controls with runbooks you can execute under pressure \u2014 not binders that only satisfy procurement.<\/p>","protected":false},"excerpt":{"rendered":"<p><span data-no-translation>NIS2 to nie folder polityk. Operatorzy potrzebuj\u0105 runbook\u00f3w: klasyfikacja incydentu, wczesne ostrze\u017cenie 24h, dow\u00f3d restore backupu i eskalacja dostawc\u00f3w \u2014 na realnych systemach, nie og\u00f3lnik\u00f3w \u201euruchom plan IR&#8221;.<\/span><\/p>","protected":false},"author":1,"featured_media":10130,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[64],"tags":[],"class_list":["post-10169","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-security-compliance"],"_links":{"self":[{"href":"https:\/\/qdata.pl\/pl\/wp-json\/wp\/v2\/posts\/10169","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/qdata.pl\/pl\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/qdata.pl\/pl\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/qdata.pl\/pl\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/qdata.pl\/pl\/wp-json\/wp\/v2\/comments?post=10169"}],"version-history":[{"count":2,"href":"https:\/\/qdata.pl\/pl\/wp-json\/wp\/v2\/posts\/10169\/revisions"}],"predecessor-version":[{"id":10179,"href":"https:\/\/qdata.pl\/pl\/wp-json\/wp\/v2\/posts\/10169\/revisions\/10179"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/qdata.pl\/pl\/wp-json\/wp\/v2\/media\/10130"}],"wp:attachment":[{"href":"https:\/\/qdata.pl\/pl\/wp-json\/wp\/v2\/media?parent=10169"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/qdata.pl\/pl\/wp-json\/wp\/v2\/categories?post=10169"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/qdata.pl\/pl\/wp-json\/wp\/v2\/tags?post=10169"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}