When a company is hit by a state-sponsored cyberattack, the first 24 hours look nothing like the textbooks suggest. Containment and recovery are competing directly with mandatory regulatory reporting. Teams are simultaneously trying to scope the incident, gather forensic evidence, and prepare submissions for authorities, while the attack is still live.
This is not a hypothetical. It is how NIS2 works in practice. The directive mandates early warning notification within 24 hours of becoming aware of a significant incident, an interim report within 72 hours, and a final report within one month.¹ None of those deadlines pause because your team is still fighting.
The result is a response process that splits attention at exactly the moment it should be undivided. And the reports, once filed, reach regulators whose primary function is to assess whether the paperwork is complete and calculate an appropriate fine, not to help.
The underlying problem is an evidence gap. When an incident occurs, the first thing a regulator asks is: what access existed, was it authorised, and can you prove it? Answering that question under time pressure, during an active incident, while simultaneously managing containment, is where organisations break down. Evidence gets reconstructed rather than retrieved. Timelines are assembled from fragmented logs. Attribution is uncertain. The report is incomplete, the fine follows, and the organisation that just survived an attack gets attacked again - this time by its own regulator.
GoFirm closes that gap before the incident happens. Every consequential action across sensitive systems - access granted, authorisation confirmed, decision executed - is signed, timestamped, and written to an append-only audit trail at the moment it occurs. Not reconstructed afterwards. Not assembled under pressure. Already there.
When the 24-hour notification window opens, the evidence chain exists. When the regulator asks who had access and whether it was authorised, the answer is in the record. When the final report is due, the timeline of every confirmed authorisation is complete and cryptographically verifiable.
GoFirm doesn’t file the reports. But it means the hardest part of filing them - producing evidence that was never designed to be produced under pressure - is already done.
NIS2 was designed to ensure organisations are prepared. GoFirm ensures the evidence of that preparation is immutable, complete, and available the moment it’s needed.
GoFirm is The Authority Platform. Stop unauthorised action. Every time.
In association with Osinto.ai, the collective intelligence platform for Security, Resilience & Defence. Osinto’s AI-enabled open-source network and governed collaborative operational environment help mitigate the growing security, resilience and governance obligation in minutes, not months.
References
1. European Parliament, Directive (EU) 2022/2555 (NIS2), Article 23, October 2022
