# Incident response, and how a Norwegian business runs it

> What counts as a security incident, what you do in the first hour, and who you have to notify in Norway, with the deadlines that already apply.

Source: https://fmcybersecurity.com/en/insights/endpoint/what-incident-response-is-and-how-to-run-it/
Locale: English
Other locale: https://fmcybersecurity.com/insights/endpoint/hva-er-hendelseshandtering/

## Metadata

- Date: 2026-08-02
- Author: kenny-le
- Topic: endpoint
- Format: guide

Here is what incident response is, what you do in the first hour, and who you are legally required to call in Norway.

The Norwegian word is hendelseshåndtering. Norwegian rules put an IKT prefix on the same idea, so you will also meet ikt-hendelseshåndtering and ikt-hendelser in documents from NSM and Finanstilsynet. Whichever word your auditor uses, the work is identical: decide whether something real happened, stop it spreading, find out how it got in, and tell the people the law says you have to tell.

## 1. What counts as a security incident, and what does not

An incident is any event with a negative effect on the security of your network and information systems. That is the definition in [digitalsikkerhetsloven § 4](https://lovdata.no/dokument/NL/lov/2023-12-20-108), and it is broader than most IT managers expect.

Broader does not mean everything. A phishing mail that landed in a quarantine nobody opened is a control working. A file blocked on write by the endpoint agent is a control working. Neither one needs an incident number, and a tuned [EDR](/en/insights/endpoint/edr-and-antivirus-what-the-difference-is/) produces a steady stream of both.

The line I use in the console is one question with three parts. Did anything execute, did anything authenticate, or did anything leave? A detection that ran to execution before it was killed, a login from a country the user was not in, a data transfer to a destination you cannot name: any one of those, and you open an incident. So does encryption you did not start, and any account behaving at 03:00 in a way it never does at 13:00.

Write that rule down before you need it. Teams that argue about whether something counts lose the first thirty minutes to the argument.

## 2. The first hour, where most of the damage is decided

In the first hour you do four things, in this order: start the clock, contain the host, cut the credentials, preserve the evidence.

**Start the clock and write it down.** Open one document. Log every observation with a timestamp and the timezone (CET or CEST, written out). The moment you record as "we became aware" is the moment three separate legal deadlines start counting, so record it deliberately rather than reconstructing it a week later.

**Contain at the network, do not power off.** Shutting a machine down destroys memory and cuts your own visibility at the exact moment you need it. In [CrowdStrike Falcon](/en/partners/crowdstrike/) we use Network Contain instead: [the contained host keeps its connection to the CrowdStrike cloud and to any IPs an administrator has allowlisted, and drops everything else](https://www.crowdstrike.com/en-us/blog/tech-center/network-contain-endpoint-falcon/). The machine stays isolated and stays readable.

**Cut the credentials, not just the password.** Reset the account, then revoke the live sessions and refresh tokens. A password reset alone leaves an attacker holding a valid session. Then list what else that account can reach, and assume they looked.

**Preserve before you clean.** Nobody reimages until someone has written down how the attacker got in. Reimaging first is the cleanest way to lose the answer, and in the cases I have worked, the same route gets used again a few weeks later.

## 3. Who decides, who does, and who talks to the outside

One named incident lead decides. Everyone else executes or waits. That is the whole governance question, and it is worth more at 02:00 than any framework diagram.

Four roles, four names, written on one page while nothing is on fire:

- **Incident lead.** Usually the IT manager. Owns the timeline, the escalation, and the call on when to bring in outside help.
- **Technical responders.** Contain, collect, restore. They do not decide when the company goes public.
- **Management.** Owns the money decisions and the legal notification decision. Shutting down production is a management call, not an analyst call.
- **One external voice.** One named person speaks to customers, press and authorities. Everyone else says "we will come back to you", and means it.

NSM puts this first as well. Principle 4.1 in [NSMs grunnprinsipper for IKT-sikkerhet](https://nsm.no/regelverk-og-hjelp/grunnprinsipper/grunnprinsipper-for-ikt-sikkerhet), version 2.1, is "prepare the organisation for handling incidents", and it comes before the principles about assessing, containing and learning. Preparation is a control, not a nice-to-have.

## 4. What happens after the first hour

The rest of the work splits into three stages, and NSM's grunnprinsipper name them in the order you meet them.

**Assess and classify (4.2).** How far in did they get, what data was reachable, is the access still live. Classification drives everything downstream, including which notification deadline applies to you.

**Contain and handle (4.3).** Remove the access, close the route, restore from a backup you have restored from before. A backup nobody has tested is a hope, not a control.

**Evaluate and learn (4.4).** One page: how they got in, what detected it, what took longest, what changes on Monday. This is the stage every organisation skips and the only one that improves the next incident.

In the reviews I have run, the longest stretch on the timeline is almost never between the first human action and containment. It is between the first signal and the first human who looked at it. That gap is what 24/7 coverage buys, and it is the number worth measuring first.

## 5. Who you must notify in Norway, and by when

Norway has three separate notification regimes with three different clocks. Which ones apply depends on what was affected and which sector you are in.

**Personal data was involved.** Notify Datatilsynet within 72 hours of becoming aware, if the breach is likely to carry medium or high risk for the people affected (GDPR article 33). Datatilsynet is explicit that [a first report may contain temporary and incomplete information](https://www.datatilsynet.no/rettigheter-og-plikter/virksomhetenes-plikter/avvik/digitale-angrep/), and that you supplement it as the picture clears. Do not miss the deadline waiting for certainty. Where the risk to individuals is high, you also have to inform them directly (article 34).

**You provide an essential or digital service under digitalsikkerhetsloven.** The law and its regulation entered into force on 1 October 2025 and implement the EU NIS directive. Notify your supervisory authority within 24 hours of becoming aware, update the notification within 72 hours, and deliver a full incident report within one month ([digitalsikkerhetsforskriften § 17](https://lovdata.no/dokument/SF/forskrift/2025-06-20-1131/KAPITTEL_2)). The covered sectors are energy, transport, health, water supply, banking, financial market infrastructure and digital infrastructure, plus digital service providers. We wrote up the scope in [what Norway's Digital Security Act is](/en/insights/compliance/what-norways-digital-security-act-is/).

**You are a financial firm under DORA.** Report a major incident to Finanstilsynet as soon as possible and within 4 hours of classifying it as major, and no later than 24 hours after becoming aware. First status update within 72 hours, final report within one month of the last status update ([Finanstilsynet's rundskriv on DORA incident reporting](https://www.finanstilsynet.no/nyhetsarkiv/rundskriv/2025/hendelsesrapportering-etter-dora/)).

**Everyone else.** No general duty, but NCSC at NSM takes reports around the clock on 02497 and at cert@ncsc.no. Report anyway. NSM's national framework for handling digital attacks and cyber incidents, updated in 2025, sets out how NCSC and the sector response teams work alongside you rather than over you. Report the crime to your local police district as well.

NIS2 will tighten all of this. Norway is in the EEA and incorporation is still in progress, so there is no transposition date to plan against yet. Plan against the deadlines that already apply, because those are the ones that will be enforced this year.

## 6. When to keep this in-house, and when to buy it

Keep the decisions in-house. Buy the hours.

The decisions cannot be outsourced. Who declares an incident, who talks to customers, who signs off on the notification to Datatilsynet: those stay with you, and any provider who offers to take them off your hands is offering you a problem.

The hours are a different question. The role almost no Norwegian SMB can staff is the person watching at 02:00 on a Sunday in July. We ran the arithmetic on what round-the-clock staffing costs in [what a SOC is, and when you need your own](/en/insights/endpoint/what-a-soc-is-and-when-you-need-your-own/), and for most organisations under a few hundred people the answer is to rent the watch rather than build it.

There are two ways to rent it from us, and they are different products. Secured by FM CyberSecurity, designed for small and medium-sized businesses, runs on our own 24/7 SOC built on CrowdStrike. [CrowdStrike Falcon Complete Next-Gen MDR](/en/services/mdr/), which we deliver to larger SMBs and enterprises, is staffed by CrowdStrike's own analysts, with FM CyberSecurity handling onboarding, detection tuning and local escalation.

Full breach handling is a third thing again: forensics, crisis management, legal coordination. NSM runs a quality scheme for providers that handle ICT incidents, and checking that list is a sensible step before you sign any breach retainer. Detection and first response, which is what MDR covers, is not the same purchase as a forensic investigation team.

## Next action

Open a blank page today and fill in four names, the NCSC number, and the notification deadlines that apply to your sector. If that page does not exist yet, that is the work, and it takes an afternoon.

Then talk to Kenny for a 30-minute look at what your endpoints detect right now and what happens at 02:00 when they do. Bring your last incident log if you have one. We read it before we recommend anything.

While you are at it, [our record of confirmed attacks on Norwegian organisations](/en/insights/attacks/) is a useful way to see what is currently hitting companies your size, and [our guide to data breaches and ransomware in Norway](/en/insights/endpoint/data-breaches-and-ransomware-in-norway/) covers the two incident types that generate most of the notifications above.

## FAQ

### What is the difference between a security incident and a data breach?

An incident is any event with a negative effect on the security of your systems. A breach under GDPR is narrower: a security incident that leads to accidental or unlawful destruction, loss, alteration, or unauthorised disclosure of or access to personal data. Every breach is an incident. Most incidents are not breaches. The distinction decides whether the 72-hour clock to Datatilsynet is running, so make the call explicitly and write down who made it.

### Do we have to notify Datatilsynet about every incident?

No. The duty applies to breaches of personal data security that are likely to carry medium or high risk for the people affected. If the risk is low or absent, there is no report to Datatilsynet, but you still record the assessment internally. Datatilsynet expects to see that you considered the question and why you concluded as you did.

### Should we pay a ransom?

NSM advises against it, on the grounds that payment funds serious crime and marks you as an organisation that pays, which has led to repeat extortion. Kripos gives the same advice. Payment also does not release you from the notification duties above. If you are being extorted, call NCSC on 02497 before you talk to the attacker.

### Do we still need our own incident response plan if we buy MDR?

Yes, and it gets shorter. MDR covers detection, triage and first containment around the clock. It does not cover who tells your largest customer, who decides to halt production, or who signs the Datatilsynet notification. Your plan shrinks to the decisions, the names, and the deadlines. That is roughly one page, and it is the page that matters at 02:00.

### Does NIS2 change these deadlines in Norway?

Not yet. Norway is in the EEA and the incorporation process is still running, so no Norwegian transposition date has been set. Digitalsikkerhetsloven, in force since 1 October 2025, is the law that applies now for essential and digital service providers. Build against its 24-hour, 72-hour and one-month structure, and you will be close to where NIS2 lands when it arrives.

### Is it worth reporting to the police?

Yes. Report to your local police district. Politidirektoratet has said that most cybercrime cases are never reported, which is why the national numbers understate the problem ([politiet.no on datakriminalitet](https://www.politiet.no/rad/datakriminalitet)). Your insurer will usually want a case number too. Reporting to the police is separate from, and does not replace, the notifications to Datatilsynet, your sector supervisory authority or Finanstilsynet.

Drafted with AI assistance, reviewed and edited by Kenny Le and the FM CyberSecurity editorial team.

---

For the full documentation index, see https://fmcybersecurity.com/llms.txt
For the complete corpus as a single document, see https://fmcybersecurity.com/llms-full.txt
