The IBM X-Force Threat Intelligence Index 2025 puts the median time between initial compromise and detection at 194 days for data breaches. More telling still: 73 percent of organisations take more than 72 hours to contain an incident once detected, and nearly all of them hold a formal incident response plan. That paradox is not anecdotal. It exposes a structural break between documented IR compliance and real operational capability. What CISOs who have lived through a serious breach take away is rarely what the standard frameworks teach.
The regulatory context that turned IR into a binding obligation
Until 2023, cyber incident handling was largely treated as a security good practice. Successive European regulations turned it into a legal requirement with quantified consequences. NIS2 requires notification to competent authorities within 24 hours for significant incidents, with a full report at 72 hours. DORA requires major ICT incident reporting on similar timelines, and adds a counterparty notification obligation for financial entities. GDPR has framed personal data breach notification at 72 hours since 2018.
The combination creates an unprecedented situation: one incident hitting an entity in scope of both NIS2 and DORA, involving personal data, triggers simultaneous notification duties to the national cyber authority, the financial regulator, and the data protection authority, with different deadlines, formats and recipients. Penalties for late or incomplete notification can reach 2 percent of global turnover under GDPR and 1 percent per day under DORA.
That changes the nature of incident response. It is no longer only a technical and organisational problem. It is a governance and communication problem that engages the executive and the board from the first hours.
First lesson: your real problem is detection, not response
Most IR plans are built around mean time to respond as the key metric. CISOs who have been through real incidents point consistently to the earlier one: mean time to detect. A perfectly calibrated IR plan that activates after 60 days of attacker presence cannot undo the damage done in that window.
What real breaches reveal: incidents that run past 72 hours of containment are almost never response failures. They are detection failures. The attacker had time to move laterally, exfiltrate credentials, compromise backups. At that stage the IR plan runs a recovery operation, not a containment one.
The most common design error is investing heavily in response runbooks without investing proportionally in early detection: EDR covering 100 percent of endpoints, a SIEM with tested correlation rules, the ability to spot lateral movement in Active Directory. One CISO at a regulated EU financial entity put it plainly: "We had 47 incident response procedures. We had no behavioural baseline for our service accounts." The attacker had used legitimate service accounts for eleven weeks.
Second lesson: communication kills faster than the incident
The most critical decisions during a cyber incident are not technical. They are communication decisions, internal and external, taken under pressure, on incomplete information, against a regulatory clock.
Premature notification. Under the 24-hour NIS2 clock, an organisation notifies the authority on an incorrect initial qualification. The incident is recategorised 48 hours later. The correction costs more reputationally than a delayed initial notification would have. The fix: separate the preliminary early warning, which may carry partial information once the significance threshold is met, from the full report at 72 hours. Regulators accept initial uncertainty. They do not accept silence.
Uncontrolled internal communication. In the first hours, information travels on unsecured channels the attacker may still be watching if not yet contained. Several documented breaches revealed the attacker had real-time access to IR communications. An IR plan needs an out-of-band channel, dedicated lines or encrypted messaging outside the compromised infrastructure, activated when compromise is suspected, not confirmed.
Communication to the board. NIS2 and DORA explicitly engage director accountability. A board that learns the scale of an incident from the press, or receives technical detail with no regulatory or business context, makes poor decisions. Preparing an executive communication template, framed in business and regulatory risk rather than technical terms, is one of the most consistently missing items in audited IR plans.
Third lesson: playbooks do not cover real incidents
IR plans are built around isolated scenarios: ransomware, phishing, data breach, privileged account compromise. Real incidents rarely involve a single vector. Analysis of significant European breaches in 2024 and 2025 shows a recurring structure: initial access through targeted phishing on a non-MFA account, lateral movement via service accounts, gradual exfiltration over weeks, then a visible trigger, ransomware or third-party notification, that reveals a far older compromise.
What that implies for your playbooks: the operational question during an incident is not "which playbook do we run?" but "what stage of compromise are we at?" The answer determines whether the priority is containment, forensic investigation, or recovery, three different action sequences that cannot run simultaneously on the same resources.
A simple and consistently revealing exercise: take your latest ransomware playbook. Drop the assumption that the incident just started. Ask: if the attacker has been present for 60 days, which steps no longer work? The answers identify your real IR gaps far more effectively than a documentary audit.
Three decisive questions on IR maturity
Have you tested your IR plan with compromised backups? If your backups sit on the same Active Directory as production, ransomware encrypts them too. An IR plan that assumes available, intact backups has not been tested under real incident conditions.
Is your regulatory notification deadline counted from detection or from initial compromise? Under NIS2 the 24-hour clock runs from the moment the entity becomes aware of the incident, not from initial compromise. The distinction has legal implications for where the clock starts.
Who decides on regulatory notification in your organisation, and in how many minutes? That decision must be takeable at three in the morning, without the incumbent CISO, in under 30 minutes. If the answer involves more than two approval layers, your notification deadline is structurally at risk.
Presidio's incident response module centralises incident qualification, NIS2, DORA and GDPR notification templates, and the decision trail for audit. See Presidio →
Conclusion
CISOs who have been through a serious breach share three convictions the standard frameworks do not transmit. Early detection is the only lever that genuinely changes the outcome. Communication, internal and regulatory, is as critical as the technical work and far less prepared. And playbooks are working hypotheses, not algorithms: the operational value comes from the judgement teams build through exercise, not from documentary completeness.
Organisations that progress fastest treat IR as an organisational capability to be practised, not a set of procedures to be filed. The difference is measured in hours during a real incident.
Read next: ICT concentration risk under DORA.
