Metaluxo
EMERGENCY RESPONSE

Someone has to take control of the incident

Small companies rarely fail an incident for technical reasons. They fail because nobody is in charge, the notification clock is running unnoticed, and five people are making contradictory decisions at once. We take that role.

Email emergency@metaluxo.com
12 hRESPONSE COMMITMENT
24 hNIS2 EARLY WARNING
72 hGDPR ARTICLE 33
1NAMED PERSON, NOT A TEAM
IF YOU ARE DEALING WITH AN INCIDENT NOW Email emergency@metaluxo.com with INCIDENT in the subject line Tell us what you are seeing, when you noticed it, whether personal data may be involved, and a phone number. We respond within 12 hours, and frequently much faster during business hours in Central European Time. Contracting can be completed the same day where the situation requires it.
BEFORE WE ARRIVE

The first sixty minutes

If you are reading this during an incident, do these six things while you wait for a reply. They cost nothing and they protect every option you have left.

1Put one person in charge. Not a committee. Someone who can authorise taking a system offline and who everyone knows to report to. Most early damage comes from five people acting on different assumptions.
2Isolate, do not wipe. Disconnect affected systems from the network and leave them powered on where you can. Reimaging a machine destroys the evidence that determines what you have to notify, and to whom.
3Preserve the logs now. Cloud and endpoint logs roll off on a retention window measured in days. Export or snapshot them before that window closes; it is the single most common irrecoverable loss.
4Do not reply to the attacker. No negotiation, no payment, no contact — those decisions carry legal and sanctions exposure and belong with your lawyers and your board, once they have the facts.
5Note the time you became aware. Write it down, with who knew what. The notification clocks run from that moment, not from the moment you understand the incident, and you will be asked to evidence it.
6Tell your lawyer, and nobody else yet. Your counsel needs to know immediately. Customers, staff and any public statement come later, once the company has one account of events rather than four.
Nothing on this list requires a specialist, and none of it is legal advice — it is the set of things that are cheap now and impossible to recover later. What happens after that is someone taking command, which is the service on this page.
01

What we do: incident command

We act as incident commander. That means we take responsibility for the response itself rather than for any single technical task:

Establish what is actually happening, separating confirmed facts from assumptions, which is where most early damage is done.
Contain and stabilise, directing your team and your providers towards the decisions that limit further loss.
Run the clock. Every applicable notification deadline is tracked from the moment we start, with the evidence needed to meet it assembled in parallel.
Select and direct specialists. Where forensics, malware analysis or offensive testing is required, we help you choose a firm, brief them properly and hold them to a scope. You engage them directly.
Supply the technical facts to your lawyers, so that notifications and legal positions rest on an accurate account of events.
Manage the communications to your board, your customers and your staff, so that the company speaks with one voice.
Drive recovery, because restoring service safely is usually the decision that matters most to the business.
02

The clocks nobody is watching

The deadlines are short, they run in parallel, and they start before anyone has a complete picture:

GDPR: notification to the supervisory authority without undue delay and, where feasible, within 72 hours of becoming aware (Regulation (EU) 2016/679, Article 33), plus communication to affected individuals where the risk is high.
NIS2: an early warning within 24 hours, an incident notification within 72 hours, and a final report within one month of that notification (Directive (EU) 2022/2555, Article 23).
Beyond the EU: Singapore requires notification to the PDPC no later than three calendar days after determining a breach is notifiable. Australia allows up to 30 calendar days to assess a suspected breach, then requires notification as soon as practicable.

We have handled breach notifications to data protection authorities in Europe and further afield, including Australia and Singapore. Where possible we work through you and your counsel. Where the situation requires it, we can engage with an authority directly, and we can work under external counsel where legal privilege matters to you.

REFERENCE

Breach notification deadlines at a glance

The clocks run in parallel, they start from the moment you become aware rather than the moment you understand, and more than one usually applies at once. This table is a planning aid, not legal advice — the operative text is in the instruments themselves, linked below.

REGIME WHO IT BINDS FIRST CLOCK WHAT FOLLOWS
Any controller processing personal data of people in the EU. 72h
Notification to the supervisory authority without undue delay and, where feasible, within 72 hours of becoming aware. Communication to affected individuals without undue delay where the risk to their rights and freedoms is high (Art. 34).
Essential and important entities in listed sectors — and, in practice, their suppliers. 24h
An early warning to the CSIRT or competent authority within 24 hours of becoming aware of a significant incident. Incident notification within 72 hours, and a final report within one month of that notification.
Financial entities and their critical ICT third-party providers, since 17 January 2025.
No single headline deadline: major ICT-related incidents follow an initial, intermediate and final reporting schedule set out in the regulatory technical standards. Also mandates ICT risk management, resilience testing and third-party oversight year-round.
Singapore PDPA PDPA, Part 6A
Organisations holding personal data of individuals in Singapore. 3 days
Notification to the PDPC no later than three calendar days after determining that a breach is notifiable. Affected individuals notified where the breach is likely to result in significant harm.
Entities covered by the Privacy Act, including many overseas businesses serving Australians. 30 days
Up to 30 calendar days to assess whether a suspected breach is an eligible data breach. Then notify the OAIC and affected individuals as soon as practicable.
The practical problem is not the deadline. It is the assessment. Every one of these clocks starts before anyone has a complete picture, and each requires facts you can defend: what was accessed, whose data, and when. Companies miss deadlines because they are still arguing about what happened, not because they forgot the rule.
03

The version of this service you should actually buy

We are honest about the constraint: we are a small practice, and an incident that arrives with no prior relationship costs you time we could have spent responding. Clients who prepare in advance get materially better outcomes. Preparation is a fixed-scope engagement:

An incident response plan written for your company, your stack and your obligations, not a generic template
A tabletop exercise that puts your leadership team through a realistic scenario and exposes the decisions nobody has made yet
Notification decision trees for every regime that applies to you, with draft content prepared in advance
Named contacts and escalation paths agreed before you need them, including which forensics firm you would call
A pre-agreed response arrangement, which is what makes a contractual response commitment possible, including support for the NIS2 24-hour early warning
Companies with this in place respond in hours rather than days, and they do not spend the first morning of a crisis negotiating a contract.
04

After the incident

Every engagement closes with a written lessons learned analysis and a briefing prepared for your board. Both are written to be read by people who were not in the room during the response.

Most companies discover during an incident that the underlying problem was the absence of anyone accountable for security. If that turns out to be your conclusion, the virtual CISO service is the natural next step, but it is your call and we will not push it.

Emergency engagements carry a premium rate, quoted at the point of engagement, with same-day contracting where the situation demands it. Preparation work is quoted as a fixed-scope project. We work remotely across the EU, in English and Spanish.

WHAT WE DO NOT DO Being told you need someone else is part of what you are paying for
Not a forensics firm We do not image drives, reverse engineer malware or run threat hunts ourselves. We assist those teams and direct their work, and we will tell you when you need them.
We do not negotiate Our position is that you should not pay. Any decision about payment carries legal and sanctions exposure that belongs with your lawyers, not with us.
Not legal advice We produce the technical account of the incident; your counsel decides what is filed and what is said.
FAQ

Questions we get asked

What do we do first after a data breach? Put one person in charge, isolate the affected systems without wiping them, preserve the logs before their retention window closes, and write down the moment you became aware — the notification clocks run from there. Then call your lawyer. The first sixty minutes above sets out the full list.
How do we report a breach, and to whom? Under GDPR, a personal data breach goes to your lead supervisory authority without undue delay and, where feasible, within 72 hours of becoming aware, with affected individuals told separately where the risk to them is high. If NIS2 applies you also owe a CSIRT early warning inside 24 hours. Which authority, and whether the threshold is met at all, depends on where you are established — we supply the technical account and your counsel makes the filing.
Do you take incident calls from companies you have never worked with? Yes. We start with a scoping conversation to establish whether we can genuinely help. If we cannot, we say so immediately.
What is your response time? Within 12 hours, and frequently much faster during business hours in Central European Time. A shorter, contractual response commitment is available to clients with a pre-agreed response arrangement.
Do you do forensics? No. We help you select and direct a forensics firm, and we make sure their findings are used properly.
Will you negotiate with the attackers? No. We advise against paying and we do not take part in negotiations. That decision sits with your lawyers and your board.
Can you talk to the data protection authority for us? Preferably we supply the technical facts and your counsel handles the filing. Where it is genuinely necessary, we have engaged with authorities directly.
Our cyber insurer has a panel of approved providers. Can we use you? Check your policy first. Many policies require you to use a panel provider or lose cover. We do not work through insurer panels, so in that situation you should use their provider, and we would rather tell you that than cost you your claim.
Is a tabletop exercise really worth it? It is the cheapest way to find out that three of your leadership team disagree about who can authorise taking production offline. Better to discover that in a meeting room than at two in the morning.
THE PRESSURE IS REGULATORY, NOT ONLY TECHNICAL

The clocks start before anyone has a complete picture

Small companies often fall outside NIS2 on size grounds and still inherit its requirements through the supply chain, because in-scope customers must manage the security of their suppliers.

01 The notification clocks FROM THE MOMENT YOU BECOME AWARE
0h Awareness The clock is triggered by awareness, not by having answers. Containment and notification run in parallel. GDPR Art. 33
24h NIS2 early warning An early warning to the CSIRT or competent authority, for entities in scope. NIS2 Art. 23
72h Notification Supervisory authority notified of a personal data breach where feasible, and the NIS2 incident notification falls due. GDPR Art. 33 · NIS2 Art. 23
1month Final report The NIS2 final report: what happened, why, and what has changed since. NIS2 Art. 23
02 What it costs when it goes wrong GDPR CEILING · ENISA DATA
4% of worldwide annual turnover, or €20 million, whichever is higher — the GDPR fine ceiling.GDPR Art. 83(5)
60% of observed intrusions began with phishing, across 4,875 incidents analysed in the EU.ENISA Threat Landscape 2025
The first twenty-four hours decide whether the rest of the timeline is manageable. Emergency contact is answered within 12 hours. Emergency response →
03 Regimes already in force NOT PENDING, NOT PROPOSED
DORA SINCE 17 JAN 2025
Financial entities are directly subject to it: ICT risk management, incident reporting, resilience testing and third-party oversight. Regulation (EU) 2022/2554
MiCA SINCE 30 DEC 2024
Applies to crypto-asset service providers. An authorisation application must describe your ICT systems and security arrangements. Regulation (EU) 2023/1114
Health sector ONGOING EXPOSURE
One of Europe’s most targeted sectors: ENISA found ransomware accounted for 54% of analysed incidents in its health threat landscape. ENISA health report
RELATED SERVICES Virtual CISO → Compliance → Blockchain security →

Prepare before you need this

If you are not currently in an incident, this is the right moment to fix that. A free 30-minute consultation will tell you honestly how exposed you are.

emergency@metaluxo.com
FIRST CALL 30 MIN
That did not go through. Please write to emergency@metaluxo.com directly — we will still reply within a working day. Thank you — your message is on its way. Roberto replies within one working day. No slide deck, no discovery call chain — one conversation with Roberto.
Who it is for

Sectors we do this in

FintechPayments and financial data companies under DORA and ICT risk rulesHealthcare & HealthTechSpecial category patient data, NIS2 duties and hospital procurement reviewsStartups & SMEsBlocked enterprise deals, security questionnaires and investor due diligence
Send us a message
Message us Book now