Glossary · Duties and incidents

Full incident report

Definition

A full incident report, called a "full notification" in the Cyber Security and Resilience Bill, is the detailed second report of a reportable incident. It is due within 72 hours of first becoming aware of the incident, the same starting point as the 24-hour initial notification, not 72 hours after it.

When is the full notification due?

Each regulation says the full notification must be given "before the end of the period of 72 hours beginning with that time", where "that time" is the moment of first awareness used for the initial notification. The two clocks start together.

So if you became aware on Monday at 09:00, the initial notification is due by Tuesday 09:00 and the full notification by Thursday 09:00. Reading the deadline as 72 hours after the initial notification would overstate the window by up to a day.

What must the full notification contain?

The content list is the same for each group, adjusted for the type of service. It must be given "so far as known", in writing, and in the form the regulator determines.

  • the organisation's name and the affected service;
  • the time the incident occurred, its duration and whether it is ongoing;
  • information on the nature of the incident;
  • where it was caused by an incident affecting another regulated person, details of that incident and that person;
  • information on the impact, including cross-border impact (for data centres, including impact it could have had);
  • any other information that may help the regulator exercise its functions.

What happens after the full notification?

For data centre operators, a relevant digital service provider and a relevant managed service provider, giving the full notification starts the customer notification duty. The regulator and the CSIRT may also share information with the organisation, other regulated persons or authorities abroad, and in some cases require or make public disclosure.

Regulators can also follow up with an information notice or an inspection if the full notification leaves questions open. Keep the incident record, timeline and evidence behind the report, because the same facts will be tested later.

Incident notification rules compared: OES, data centre, RDSP and RMSP

RuleOES (non-data centre)Data centre OESRDSPRMSP
RegulationReg 11Reg 11AReg 12AReg 14E
Who you notifyDesignated competent authority for the OESDesignated competent authority (Ofcom, cl.4(2))Information CommissionInformation Commission
What makes it reportableHas affected or is affecting the operation or security of the systems, and impact has been, is or is likely to be significant (reg 11(3)-(4))Could have had, has had, is having or is likely to have a significant impact (reg 11A(3))Has affected or is affecting the systems, and impact is or is likely to be significant, with 7 factors (reg 12A(2)-(3))Has affected or is affecting the systems, and impact is or is likely to be significant, with 7 factors (reg 14E(2)-(3))
24-hour initial notificationFrom first awareness (reg 11(6)(a))From first awareness (reg 11A(5)(a))From first awareness (reg 12A(5)(a))From first awareness (reg 14E(5)(a))
72-hour full notificationFrom the same moment of first awareness (reg 11(6)(b))From the same moment (reg 11A(5)(b))From the same moment (reg 12A(5)(b))From the same moment (reg 14E(5)(b))
Customer notification dutyNone in the BillYes, reg 11CYes, reg 12CYes, reg 14G
Copy to the CSIRT (NCSC)At the same time, reg 11(8)At the same time, reg 11A(7)At the same time, reg 12A(7)At the same time, reg 14E(7)

Worked example (illustrative)

Illustrative timeline

A cloud provider's on-call engineer confirms at 14:00 on Wednesday that customer data stores were encrypted by ransomware and the outage is significant. The initial notification to the Information Commission, copied to the NCSC, is due by 14:00 Thursday. The full notification, with timing, nature, impact and any supplier incident that caused it, is due by 14:00 Saturday. Customer notifications follow as soon as reasonably practicable after that.

Where it appears in the Bill

  • New reg 11(5)-(6)OES full notification contents and 72-hour deadline.
  • New reg 11A(4)-(5)Data centre contents and deadline.
  • New reg 12A(4)-(5)RDSP contents and deadline.
  • New reg 14E(4)-(5)RMSP contents and deadline.
  • New reg 18(11)Timing and content failures in the higher penalty band.

References are to HL Bill 32 as brought from the Commons. Read the Bill.

Frequently asked questions

Is the 72-hour report due 72 hours after the 24-hour notification?

No. Both periods begin at the time the organisation is first aware that a reportable incident has occurred or is occurring. The full notification is due 72 hours from that moment, which is 48 hours after the initial notification deadline. This applies to operators of essential services, data centres, digital service providers and managed service providers alike.

What if we do not know everything within 72 hours?

The full notification must contain the listed information "so far as known" to the organisation. You are not expected to have finished the investigation, but you must give what you know by the deadline. Regulators can then use information notices to ask for more, so keep your incident record current as the facts develop.

Does the full notification have to mention a supplier?

Yes, where relevant. If the incident was caused by a separate incident affecting another regulated person, such as a managed service provider or a critical supplier, the full notification must include details of that separate incident and of the regulated person. This helps regulators trace supply chain incidents across several organisations.

Related guidance

Official sources

More in Duties and incidents

Full glossary