Incident

From report to lesson, with the clock that starts where the law says.

One file per incident: report without an account, notification clocks for NIS2, DORA and the GDPR that start at the moment of discovery, one decision per regime and a lesson that is mandatory before the file can close. Built and hosted in the EU.

From scattered reports to one accountable file

An incident arrives through the service desk, an email or a phone call. Then the arithmetic starts: which notification duty applies, when did the clock start and who has to do what. That arithmetic does not belong in someone's head or in a spreadsheet.

Now

The clock is running before anyone knows

The NIS2 or DORA deadline starts at discovery or classification, not when the second line receives the report. That difference costs hours.

With Incident

Clocks on the legal trigger

The reporter gives the moment of discovery. Every clock states what it runs for, when it started and the final time in full, and the next deadline sits at the top.

Now

Reporting is a hurdle

Staff do not know where to report an incident, and a form with twenty fields does not help.

With Incident

Three questions, no account needed

What happened, when was it discovered, is personal data involved. Through a fixed organisation link or QR code, without logging in, with a report number in return.

Now

The decision is recorded nowhere

Whether an incident was notified, and why not, lives in an email thread. That is hard to explain to a supervisor.

With Incident

One decision per regime

Notify, do not notify with reasons, or still unclear. The supervisor's reference goes into the file, and a missing reference stays visible as an open item.

Now

Closed, nothing learned

The incident is closed, the cause was never analysed and the control that would have prevented it exists only as an action item.

With Incident

The lesson as gate

Closing is only possible once the lesson lands: a risk in Risk Heat Map, a control in TRIAS or a deliberate decision to change nothing.

A selection from Incident

Click a thumbnail for that screen, or the image itself for the full-size view.

Nl ex dossier en1 / 5 shown

What you want to know about Incident beforehand

What is Incident?

Incident is Audirium's incident register: one file per incident (information security, data breach or other) with reporting without an account, notification clocks for NIS2, DORA and the GDPR, a decision per regime, the supervisor's reference and a lesson that is mandatory before the case can be closed.

Who is Incident for?

For the second line that handles incidents and notification duties (information security, risk, compliance), the data protection officer for data breaches, and every employee who wants to report an incident. Reporters need no account; the second line works in the queue, the file and the cockpit.

What does Incident actually do?

Incident takes in reports through a link, QR code or TOPdesk ticket, calculates the NIS2, DORA and GDPR deadlines from the moment of discovery, records per regime the decision and the supervisor's reference, stores analysis, actions and financial consequences, and only lets the file close once there is a lesson.

How does Incident differ from a ticketing system or spreadsheet?

A ticketing system records, Incident accounts. The clocks start at the legal trigger rather than at receipt, a decision not to notify requires reasons, a missing reference stays visible as an open item and the file cannot close without a lesson. A TOPdesk ticket can still be the source of a report.

Does Incident work with other parts of the suite?

Yes. TRIAS, NIS2, Privorium and TPRM show the incident as a card and write back only their own part, so the file exists in one place. A lesson lands as a risk in Risk Heat Map or as a control in TRIAS. Every link stays within your own organisation.

Where is Incident data stored?

On Hetzner servers in the EU. Each organisation has its own separate database, and the title, description and cause of an incident are stored encrypted. Incident uses no AI, and a reporter's IP address is not kept with the report.

The whole file, from first report to accountability

Incident is the single file for every reportable incident. TRIAS, NIS2, Privorium and TPRM show a card and write back only their own part, so there is one version of the truth.

Report without an account

A personal one-time report link or the fixed organisation link with QR code and A4 poster. Reporters receive a report number; an abuse brake works without an external CAPTCHA.

Five phases following ISO 27035

Report, classify and decide, handle, account, learn. The phase follows from what is already in the file.

Notification clocks per regime

NIS2, DORA and the GDPR, each with its own trigger. Ticking off a notification step asks for the actual submission time and sets the next clock.

Help with the notification decision

Per regime a short questionnaire with an advice line. The advice helps, a person decides, and anyone who deviates gives a brief reason in the file.

Supervisors and reporting channels

Record per organisation who the supervisor is, which NIS2 entity type applies and whether the data protection officer submits the notification. The step then names the right recipient.

Analysis and consequences

Five-whys analysis, the bowtie barriers that failed, and the financial consequences with gross and net loss in one of the seven Basel event categories.

The lesson as gate for closing

Every lesson lands: as a risk in Risk Heat Map, as a control in TRIAS or as a deliberate no-change with reasons. Without a lesson the file stays open.

TOPdesk tickets as proposals

A ticket in the categories you designate appears as a report in the queue with a clock forecast. An incident is never created automatically; you convert or dismiss.

A cockpit that counts honestly

One score and a traffic light. Exercises do not count, a measure that does not apply to you is not counted as zero, and every gap links through to the incidents behind it.

From report to closed file in six steps

1

Receive the report

Through the report link, the organisation link, a TOPdesk ticket or directly in the app. Three questions are enough.

2

Classify and decide

Decide per regime whether you notify, do not notify or do not know yet, with the help questions and advice alongside.

3

Follow the clocks

See per regime which deadline is running and when it expires, and tick off each notification step with the actual time and the reference.

4

Handle

Assign follow-up actions to a person, analyse the cause and record the financial consequences.

5

Account

Bundle the file with what is still open: a missing reference or a notification step with a legal deadline that was never set.

6

Learn and close

Let the lesson land in Risk Heat Map or TRIAS, or record why you change nothing. Only then can the file close.

Meet every notification deadline, and be able to show it?

Request a demo or get in touch for more information about Incident for your organisation.