Escalation & Communication
Escalation Matrix
| Severity | Initial Notification | Escalation to Exec. Mgmt. | BSI Report | Customer Notification |
|---|---|---|---|---|
| Critical | CISO + Exec. Mgmt. immediately | Immediately | Assessment within 4h | Without delay if affected |
| High | CISO within 1h | Within 4h | Assessment within 24h | If services are affected |
| Medium | CISO within 24h | Next regular report | No (standard case) | Only if directly impacted |
| Low | IT team | No | No | No |
Communication Plan
Internal Communication
| Recipient | Channel | Content | Timing |
|---|---|---|---|
| Incident response team | Encrypted messenger / conference call | Technical details, measures | Immediately upon detection |
| Executive management | Direct conversation or encrypted email | Situation summary, impact, measures | Per escalation matrix |
| Affected departments | Email + meeting | Impact on their area, expected duration | After initial assessment |
| All employees | Only if necessary (e.g., phishing wave) | Warning + instructions for action | After exec. management approval |
External Communication
| Recipient | Channel | Content | Timing |
|---|---|---|---|
| BSI | Reporting platform | Per §32 reporting model | 24h / 72h / 1 month after the 72h notification |
| Affected customers | Direct notification (email + phone) | Nature, scope, measures, recommendations | Without delay if affected |
| Customers as controllers (GDPR) | Direct notification | Personal data breach affecting data BAUER GROUP processes on the customer's behalf, with the information the customer needs for its own notification (Art. 33(2) GDPR) | Without undue delay after becoming aware; deadline per data processing agreement |
| Data protection authority | Reporting portal | Notification under Art. 33 GDPR if personal data is affected; in case of a high risk, additional notification of the data subjects (Art. 34 GDPR) | Authority: without undue delay, where feasible within 72 hours (Art. 33); data subjects: without undue delay (Art. 34) |
| Law enforcement | Criminal complaint | If a criminal offense is suspected | After exec. management decision |
Customer Notification in Case of Incidents
When a security incident affects customer data or services, the notification includes:
- Nature and scope of the incident
- Affected data or services
- Countermeasures taken
- Recommended actions for the customer
- Contact person for inquiries
- Expected duration of the disruption
NIS2-REGULATED CUSTOMERS
Customers who are themselves subject to NIS2 regulation must report significant security incidents to the BSI within 24 hours. Prompt and complete information from the BAUER GROUP enables these customers to meet their own reporting obligations.
Emergency Contacts
The following contacts are available at all times (including outside business hours):
| Role | Availability |
|---|---|
| CISO | 24/7 via mobile phone |
| IT on-call | 24/7 via on-call duty |
| Executive management | Reachable via mobile phone |
| BSI reporting platform | Online portal (24/7) |