Technology Law · European Union

Handle a Cybersecurity Incident With Legal Support From the First Hour

Ransomware, a compromised account, a system outage — the first 72 hours decide how bad it gets, and legal duties run in parallel with the technical response. We match you, free of charge, with a lawyer who guides organisations through cybersecurity incidents across Europe.

  • 155+ legal services, 14 practice areas
  • Incident response and reporting specialists
  • No fee to get matched

No commitment. No hidden fees.

Get matched with a lawyer

Tell us about your situation and receive a free, confidential case review.

Free & confidential. No obligation to hire.


14
Legal practice categories
155+
Specialised legal services
24–48h
Average first response
€0
Cost to get matched

Who this is for

A cybersecurity incident triggers overlapping duties that run on tight, parallel timelines

A cybersecurity incident — a ransomware attack, a data exfiltration, a denial-of-service outage, a compromised mailbox or an insider act — sets off a cascade of legal obligations that run alongside the technical recovery. Depending on the facts, an organisation may need to notify a data protection authority under the GDPR, report to a cybersecurity regulator under NIS2 or national equivalents, inform affected individuals, and preserve evidence for potential claims or investigations, all while maintaining operational continuity. The deadlines are short, the thresholds are not always obvious, and the penalties for getting the response wrong can outlast the incident itself. We connect you with a lawyer who coordinates the legal side of incident response across the countries where you operate.


Why response goes wrong

Under pressure, companies focus on restoring systems
and miss the legal clock running in parallel

The technical fix and the legal duties move on different timelines, and the legal one rarely waits.

01

Overlapping reporting duties

The same incident can trigger GDPR notification, cybersecurity-regime reporting and sector-specific obligations, each with its own threshold, deadline and recipient. Missing one because you were handling another is common.

02

Evidence lost in recovery

In the rush to restore services, systems are wiped, logs overwritten and mailboxes purged — destroying exactly the evidence needed for a regulator’s questions or a later claim.

03

Premature or inconsistent statements

Telling customers, staff or the public too early, or in wording that conflicts with a later regulator filing, can create additional liability and complicate the formal response.


What you get

Legal support that runs alongside your technical team

We only match you with lawyers who handle cybersecurity incident response and regulator reporting for organisations in your sector.

Immediate triage

Your lawyer works out quickly which duties the incident triggers, which authorities and individuals must be told, and what must be preserved — giving you a clear legal action plan in the first hours.

Coordinated notifications

GDPR, cybersecurity and sectoral notifications are prepared consistently, filed within the relevant deadlines and kept aligned, so the account you give each authority is coherent and matches across the board.

Evidence preservation

You get guidance on what to retain and how, so the technical recovery does not destroy the records you will need for investigations, regulators or litigation.

Post-incident follow-up

Your lawyer manages regulator correspondence, advises on remediation and lessons learned, and helps you demonstrate the concrete steps you have taken to prevent the same incident happening again.


Coverage

Cybersecurity incident lawyers across Europe

Incident-reporting duties arise under the GDPR and under each member state’s cybersecurity and sectoral laws, and the authorities, deadlines and forms differ by country, so the right lawyer is one who works with your specific regulators. We match cases across the following countries and beyond:

SpainPortugalGermanyFranceItalyNetherlandsBelgiumIrelandAustriaPolandSwedenDenmark+ more EU / EEA countries

Frequently asked

Cybersecurity incidents — common questions

What should I do in the first hours of an incident?

Contain the incident, preserve evidence and start a structured log of events and decisions, then assess your legal duties immediately. Because notification deadlines run from when you become aware, early legal advice helps you avoid missing a window while you focus on recovery.

Which authorities might I need to report to?

Depending on the facts, you may need to notify a data protection authority under the GDPR, a cybersecurity authority under NIS2 or national law, and possibly sector-specific regulators. A lawyer can identify the full set of recipients for your specific incident and markets.

Is every cybersecurity incident reportable?

No — the thresholds differ between regimes. Under the GDPR, notification depends on the risk to individuals, while cybersecurity regimes use their own significance criteria. A legal assessment is needed to decide what actually must be reported.

How long do I have to report an incident?

Timelines vary by regime. GDPR notification is generally due without undue delay and, where feasible, within 72 hours, while cybersecurity regimes may set different windows. Because these run in parallel, you should act immediately and confirm each deadline.

Should I tell customers and staff about the incident?

Not automatically — premature or inconsistent communication can create problems, while in other cases you are legally required to inform affected individuals. A lawyer can advise what to say, to whom, and when, so your messaging supports rather than undermines the response.

Can a lawyer help if we have already started responding?

Yes. A lawyer can join an ongoing response at any point, review what has been done, correct or supplement any notifications already filed, and take over the regulator correspondence and follow-up, so the rest of the response is handled correctly.


Free case review

Get legal support now — the clock is already running

Tell us what has happened and where your organisation operates, and we’ll connect you with a lawyer who handles cybersecurity incident response for businesses like yours — free of charge, with no obligation to hire.