Companies and authorities

A data leak – what next?
Generally, when a data leak occurs, the aim is to limit the damage, find the vulnerability and remove it, and prevent further data leaks.

Cyberattack – how to communicate?
Good crisis communication helps the company/organisation/authority to position themselves as a central and trustworthy source of information and prevent speculation, indiscretions and false reporting. Cyberattacks therefore require prompt, coordinated and well-thought-out crisis communication in order to reassure and regain the trust of stakeholders.

DDoS attack – what next?
When facing a DDoS attack, the main aim is to show the attackers that they have not achieved their objective. If you withstand the attempt long enough, the attackers will typically turn their attention to someone else.

Hacked website – what next?
There are two common points of entry which hackers and cybercriminals use to gain access to a website: Stolen credentials and Outdated CMS. The NCSC instructions provide a brief overview of how you can to clean up and secure your website.

Ransomware – What next?
Encryption Trojans (ransomware) can cause considerable damage, especially if your data backups are also affected. In the event of such an incident, remain calm and act with caution.
Report to NCSC
The NCSC receives voluntary reports of cyberincidents from the public, companies and the authorities, and assists them in taking the necessary steps. The NCSC is also responsible for collecting reports of cyberincidents from operators of critical infrastructure, who have been subject to a reporting obligation since 1 April 2025. The NCSC also receives reports of vulnerabilities and assigns them a unique identification number in accordance with the international reference system.