
22.09.2026 nis2ransomwareincident responseregulatorische meldepflicht
On 20 January 2026, the European Commission published a proposal that tightens NIS2 in a corner most security teams have not yet mapped: the documentation trail around ransomware payments. The changes cover information about whether a ransom demand was made and by whom, whether a ransom was paid, the amount, the payment method, the recipient, and, where relevant, any crypto-assets or crypto-asset service providers involved. National authorities would gain the explicit right to demand this information after a significant incident has been reported.
Until now, “pay or don’t pay” was primarily a governance and legal call, made between executives, the cyber insurer, and outside counsel. The amendment turns it into an operational documentation problem for the IR team as well. Anyone who later has to reconstruct payment method, recipient, and involved crypto brokers with confidence cannot rely on memory or scattered email threads. The proposal introduces a harmonized framework for collecting ransomware-related data under Article 23, requiring entities to provide information on attack vectors, mitigation measures, and, on request, ransom demands and payments.
In practice, this means negotiation transcripts with the threat actor, the payment approval chain, wallet addresses, and the KYC records of any crypto broker involved shift from “nice to have for the insurer” to a regulator-demandable artifact. IR teams that have historically treated ransomware cases as a purely technical problem — containment, eradication, recovery — now need a parallel documentation track that runs unbroken from first attacker contact to the final transaction.
Three things IR leaders should tackle now, regardless of where the Brussels negotiations land:
First, clear role separation and handoff protocols between the technical IR team, the ransomware negotiator, the cyber insurer, and legal counsel. Every information handoff needs a timestamped, attributable log entry.
Second, a standardized “ransom disclosure dossier” template maintained alongside the main incident timeline — with fields for demand amount, deadlines, negotiation history, final payment sum, payment method, exchanges or brokers involved, and recipient address.
Third, contractual groundwork with external providers. Identifying who holds payment authority, pre-negotiating engagement terms with a ransomware response firm, and confirming that the cyber insurance policy covers ransom payments, including any sub-limits or exclusions, are essential steps that buy critical time once a demand actually lands.
Context matters here. The proposals are expected to be adopted no earlier than late 2026 or early 2027, followed by a national transposition period. At the same time, the drafters are careful to note that reporting ransomware-related information should not trigger additional obligations or increased liability — an important political clarification, though it doesn’t excuse IR teams from preparing operationally now.
The message for SOC and IR leadership is clear: ransomware reporting is moving from a technical notification to a governance matter with a forensic evidentiary burden. This reflects the growing regulatory view that ransomware is not merely a technical incident but a governance and disclosure issue. Building the documentation chain now means not having to reconstruct it under deadline pressure later.
← Back to overview