Six hours to alert ANSSI, 72 hours for a complete report: faced with the NIS2 directive, CISOs no longer have the luxury of doubt.
Agentic security is essential to meeting strict reporting and compliance deadlines, especially when it comes to providing accurate information about system security vulnerabilities.
From the moment signs of a cyber attack are detected on a company’s systems, a race against time begins. IT security professionals must not only block and remediate the breach as quickly as possible, but also adhere to strict deadlines for reporting it to the relevant regulatory authorities.
This reporting process can bring them into contact with up to five different entities, depending on the type of attack and the company’s industry. Each regulatory authority has its own reporting procedures to follow, questions to answer and deadlines to meet.
This is a very complex and multi-layered procedure that companies struggle to navigate. But failure to report an incident would result in serious consequences, including hefty fines, erosion of customer trust and even, in some cases, personal liability for executives.
For example, the NIS2 directive requires large and medium-sized organizations in different critical sectors, such as energy, transport, health, finance and digital infrastructure, to transmit an “early warning” to the competent authority of the country concerned (in France, this is the ANSSI). This alert must be carried out within six hours of the first detection, followed by a full report within 72 hours, as well as regular updates if the attack continues, and finally a final report must be submitted within one month.
The Cyber Resilience Act, which applies to manufacturers of any product with a digital component, follows an approach similar to that of the NIS2 directive. When it comes to personal data breaches, the General Data Protection Regulation (GDPR) requires businesses to report the breach to the competent authority “without undue delay and, where practicable, no later than 72 hours” of detection.
The AI Act, meanwhile, requires providers of “high-risk” AI systems to report incidents within two days, if they involve a “widespread breach” or serious and irreversible disruption of critical infrastructure.
These increased reporting requirements come at a time when businesses across Europe are also facing increasing threats from cybercriminals.
In France, public bodies and businesses alike have experienced a significant increase in data breaches over the past three years. In a report published in May 2025, the CNIL revealed that it received 6,167 data breach notifications last year, an increase of 10% compared to the previous year. She points out that the years 2024 and 2023 also broke records and that, over the last two years, around 80 violations affected at least a million people in France, reflecting a significant increase in the scale of these incidents. Among the organizations targeted in 2025 are the Auchan supermarket chain, three regional health agencies, as well as La Poste.
It’s a big challenge. In the aftermath of a cyberattack, security teams should, within their capabilities, establish an incident response team, identify potential anomalies, limit the spread of the threat, remove malicious elements, and restore affected systems and data. This takes time, and the problem is that the reporting deadlines start long before there is absolute certainty.
Determine the extent of the cyberattack
Although the challenge is daunting, it is not impossible to meet. Companies that succeed have one thing in common: they quickly define the scope of the incident.
During the identification phase of the incident response lifecycle, this involves correlating alerts from endpoints, compromised systems, data accessed, and disrupted operations – gathering information from logs before the situation cools.
The problem is that the evidence is rarely in the same place. When alerts are scattered across ten different tools, the investigation must follow them everywhere. Teams end up working on the periphery of the incident rather than at its center, which makes it difficult to assess its scale.
This has implications that go far beyond the investigation itself. Imprecise assessment of the scope of the incident leads to inaccurate breach notification. It is impossible to report accurately without first determining the extent of the incident.
What an accurate assessment of the extent of the incident requires
Instead, what is needed is a unified database to which all alerts are routed for correlation and analysis. Better yet, this database should provide some degree of automation that can “connect the dots” during an investigation without IT staff having to manually gather all the evidence and sift through it. This type of platform allows businesses to more effectively conduct proactive security operations.
It is by optimizing the time and skills of the security team that AI provides real added value. Automated correlations, machine-generated findings and suggestions free these professionals to focus on what they do best: evaluating, judging and powering their own investigative efforts with insights that would otherwise take hours to emerge.
In the most effective configurations, an “agentic” workflow will determine if and how alerts are related, identify the attack tree, and determine which system and network entities are involved. The result is faster, more accurate investigations and better reporting to regulatory authorities that concisely summarizes the scope of an incident, its impact radius, current status and next steps.
Beyond Compliance: The Case for Operational Resilience
The benefits of this use of technology extend far beyond just timely filing of regulatory reports, of course. Companies that can master faster, more accurate analysis of security incidents are better equipped to respond in almost every way: limiting attacks, reducing damage, accelerating recovery times, and taking proactive steps to strengthen their defenses against similar breaches.
In other words, “agentic” security could be the best way to not only show regulators that an organization is taking IT security risks seriously, but also to transform current risks into future resilience.