From report to lesson, with the clock that starts where the law says.
One file per incident: report without an account, notification clocks for NIS2, DORA and the GDPR that start at the moment of discovery, one decision per regime and a lesson that is mandatory before the file can close. Built and hosted in the EU.
From now to next
From scattered reports to one accountable file
An incident arrives through the service desk, an email or a phone call. Then the arithmetic starts: which notification duty applies, when did the clock start and who has to do what. That arithmetic does not belong in someone's head or in a spreadsheet.
The clock is running before anyone knows
The NIS2 or DORA deadline starts at discovery or classification, not when the second line receives the report. That difference costs hours.
Clocks on the legal trigger
The reporter gives the moment of discovery. Every clock states what it runs for, when it started and the final time in full, and the next deadline sits at the top.
Reporting is a hurdle
Staff do not know where to report an incident, and a form with twenty fields does not help.
Three questions, no account needed
What happened, when was it discovered, is personal data involved. Through a fixed organisation link or QR code, without logging in, with a report number in return.
The decision is recorded nowhere
Whether an incident was notified, and why not, lives in an email thread. That is hard to explain to a supervisor.
One decision per regime
Notify, do not notify with reasons, or still unclear. The supervisor's reference goes into the file, and a missing reference stays visible as an open item.
Closed, nothing learned
The incident is closed, the cause was never analysed and the control that would have prevented it exists only as an action item.
The lesson as gate
Closing is only possible once the lesson lands: a risk in Risk Heat Map, a control in TRIAS or a deliberate decision to change nothing.
This is what it looks like
A selection from Incident
Click a thumbnail for that screen, or the image itself for the full-size view.
Frequently asked questions
What you want to know about Incident beforehand
What is Incident?
Incident is Audirium's incident register: one file per incident (information security, data breach or other) with reporting without an account, notification clocks for NIS2, DORA and the GDPR, a decision per regime, the supervisor's reference and a lesson that is mandatory before the case can be closed.
Who is Incident for?
For the second line that handles incidents and notification duties (information security, risk, compliance), the data protection officer for data breaches, and every employee who wants to report an incident. Reporters need no account; the second line works in the queue, the file and the cockpit.
What does Incident actually do?
Incident takes in reports through a link, QR code or TOPdesk ticket, calculates the NIS2, DORA and GDPR deadlines from the moment of discovery, records per regime the decision and the supervisor's reference, stores analysis, actions and financial consequences, and only lets the file close once there is a lesson.
How does Incident differ from a ticketing system or spreadsheet?
A ticketing system records, Incident accounts. The clocks start at the legal trigger rather than at receipt, a decision not to notify requires reasons, a missing reference stays visible as an open item and the file cannot close without a lesson. A TOPdesk ticket can still be the source of a report.
Does Incident work with other parts of the suite?
Yes. TRIAS, NIS2, Privorium and TPRM show the incident as a card and write back only their own part, so the file exists in one place. A lesson lands as a risk in Risk Heat Map or as a control in TRIAS. Every link stays within your own organisation.
Where is Incident data stored?
On Hetzner servers in the EU. Each organisation has its own separate database, and the title, description and cause of an incident are stored encrypted. Incident uses no AI, and a reporter's IP address is not kept with the report.
What Incident offers
The whole file, from first report to accountability
Incident is the single file for every reportable incident. TRIAS, NIS2, Privorium and TPRM show a card and write back only their own part, so there is one version of the truth.
Report without an account
A personal one-time report link or the fixed organisation link with QR code and A4 poster. Reporters receive a report number; an abuse brake works without an external CAPTCHA.
Five phases following ISO 27035
Report, classify and decide, handle, account, learn. The phase follows from what is already in the file.
Notification clocks per regime
NIS2, DORA and the GDPR, each with its own trigger. Ticking off a notification step asks for the actual submission time and sets the next clock.
Help with the notification decision
Per regime a short questionnaire with an advice line. The advice helps, a person decides, and anyone who deviates gives a brief reason in the file.
Supervisors and reporting channels
Record per organisation who the supervisor is, which NIS2 entity type applies and whether the data protection officer submits the notification. The step then names the right recipient.
Analysis and consequences
Five-whys analysis, the bowtie barriers that failed, and the financial consequences with gross and net loss in one of the seven Basel event categories.
The lesson as gate for closing
Every lesson lands: as a risk in Risk Heat Map, as a control in TRIAS or as a deliberate no-change with reasons. Without a lesson the file stays open.
TOPdesk tickets as proposals
A ticket in the categories you designate appears as a report in the queue with a clock forecast. An incident is never created automatically; you convert or dismiss.
A cockpit that counts honestly
One score and a traffic light. Exercises do not count, a measure that does not apply to you is not counted as zero, and every gap links through to the incidents behind it.
How it works
From report to closed file in six steps
Receive the report
Through the report link, the organisation link, a TOPdesk ticket or directly in the app. Three questions are enough.
Classify and decide
Decide per regime whether you notify, do not notify or do not know yet, with the help questions and advice alongside.
Follow the clocks
See per regime which deadline is running and when it expires, and tick off each notification step with the actual time and the reference.
Handle
Assign follow-up actions to a person, analyse the cause and record the financial consequences.
Account
Bundle the file with what is still open: a missing reference or a notification step with a legal deadline that was never set.
Learn and close
Let the lesson land in Risk Heat Map or TRIAS, or record why you change nothing. Only then can the file close.
Meet every notification deadline, and be able to show it?
Request a demo or get in touch for more information about Incident for your organisation.