This document is under active development and has not been finalized.
Skip to content

Escalation & Communication

Escalation Matrix

SeverityInitial NotificationEscalation to Exec. Mgmt.BSI ReportCustomer Notification
CriticalCISO + Exec. Mgmt. immediatelyImmediatelyAssessment within 4hWithout delay if affected
HighCISO within 1hWithin 4hAssessment within 24hIf services are affected
MediumCISO within 24hNext regular reportNo (standard case)Only if directly impacted
LowIT teamNoNoNo

Communication Plan

Internal Communication

RecipientChannelContentTiming
Incident response teamEncrypted messenger / conference callTechnical details, measuresImmediately upon detection
Executive managementDirect conversation or encrypted emailSituation summary, impact, measuresPer escalation matrix
Affected departmentsEmail + meetingImpact on their area, expected durationAfter initial assessment
All employeesOnly if necessary (e.g., phishing wave)Warning + instructions for actionAfter exec. management approval

External Communication

RecipientChannelContentTiming
BSIReporting platformPer §32 reporting model24h / 72h / 1 month
Affected customersDirect notification (email + phone)Nature, scope, measures, recommendationsWithout delay if affected
Data protection authorityReporting portalGDPR Art. 33/34 if personal data affected72 hours
Law enforcementFormal reportIf a criminal offense is suspectedAfter exec. management decision

Customer Notification in Case of Incidents

When a security incident affects customer data or services, the notification includes:

  • Nature and scope of the incident
  • Affected data or services
  • Countermeasures taken
  • Recommended actions for the customer
  • Contact person for inquiries
  • Expected duration of the disruption

NIS2-REGULATED CUSTOMERS

Customers who are themselves subject to NIS2 regulation must report significant security incidents to the BSI within 24 hours. Prompt and complete information from the BAUER GROUP enables these customers to meet their own reporting obligations.

Emergency Contacts

The following contacts are available at all times (including outside business hours):

RoleAvailability
CISO24/7 via mobile phone
IT on-call24/7 via on-call duty
Executive managementReachable via mobile phone
BSI reporting platformOnline portal (24/7)

Documentation licensed under CC BY-NC 4.0 · Code licensed under MIT