{"id":12596,"date":"2026-04-13T18:53:41","date_gmt":"2026-04-13T18:53:41","guid":{"rendered":"https:\/\/www.securitytoday.de\/2026\/04\/22\/nis2-crisis-2026-three-reporting-channels-companies-need-in\/"},"modified":"2026-06-10T11:20:22","modified_gmt":"2026-06-10T11:20:22","slug":"nis2-crisis-2026-three-reporting-channels-companies-need-in","status":"publish","type":"post","link":"https:\/\/www.securitytoday.de\/en\/2026\/04\/13\/nis2-crisis-2026-three-reporting-channels-companies-need-in\/","title":{"rendered":"NIS2 Crisis 2026: 3 Reporting Channels for First-Hour Incidents"},"content":{"rendered":"<p style=\"display:inline-block;background:#69d8ed;color:#fff;padding:4px 14px;border-radius:20px;font-size:0.85em;margin-bottom:18px;\">6 Min. Reading time<\/p>\n<p><strong>The moment security teams realize that something is seriously wrong is not the time to leaf through the legal text. Anyone who, at T+0, still has to figure out which authority expects what, has three clocks ticking against them simultaneously: BSI, data protection, and customer\u2011 and insurer contracts. This article shows which reporting channels must be handled in parallel in 2026, what the forms and platforms actually ask for, and where the first documented cases have stumbled.<\/strong><\/p>\n<div style=\"background:#003340;color:#fff;padding:28px 32px;margin:32px 0;border-radius:8px;\">\n<p style=\"margin:0 0 14px 0;font-size:0.78em;font-weight:700;text-transform:uppercase;letter-spacing:0.18em;color:#69d8ed;\">Key points in brief<\/p>\n<ul style=\"margin:0;padding-left:22px;color:rgba(255,255,255,0.92);line-height:1.55;\">\n<li style=\"margin-bottom:8px;\"><strong style=\"color:#69d8ed;\">Three reporting paths in parallel:<\/strong> BSI (NIS2\/BSIG), data\u2011protection supervisory authority (Art. 33 GDPR) and contractual reporting chains (customers, insurers). They operate independently and have different deadlines.<\/li>\n<li style=\"margin-bottom:8px;\"><strong style=\"color:#69d8ed;\">NIS2 cascade:<\/strong> 24\u202fhours initial notice (Early Warning), 72\u202fhours incident notification, one\u202fmonth final report. Basis: Art. 23 of the NIS2 Directive (EUR\u2011Lex, 2022).<\/li>\n<li style=\"margin-bottom:8px;\"><strong style=\"color:#69d8ed;\">GDPR reporting:<\/strong> 72\u202fhours to the competent supervisory authority as soon as personal data are affected (Art. 33 GDPR). Runs in parallel with the BSI report, not afterwards.<\/li>\n<li style=\"margin-bottom:8px;\"><strong style=\"color:#69d8ed;\">Insurers and large customers:<\/strong> reporting deadlines set by the contract, often 24 to 48\u202fhours, sometimes before the authority report. Missing them risks a denial of coverage.<\/li>\n<li style=\"\"><strong style=\"color:#69d8ed;\">Pitfall #1:<\/strong> The initial notice is not a case description but a structured signal. Treating it like an incident report wastes time.<\/li>\n<\/ul>\n<\/div>\n<p style=\"font-size:0.88em;color:#666;margin:20px 0 32px 0;border-top:1px solid #e5e5e5;border-bottom:1px solid #e5e5e5;padding:10px 0;\"><span style=\"color:#004a59;font-weight:700;text-transform:uppercase;font-size:0.72em;letter-spacing:0.14em;margin-right:14px;\">Related<\/span><a href=\"https:\/\/www.securitytoday.de\/en\/2024\/02\/14\/nis2-implementation-a-practical-guide-for-german-smes\/\" style=\"color:#333;text-decoration:underline;\">NIS2 Governance in SMEs<\/a> &nbsp;&nbsp;<span style=\"color:#ccc;\">\/<\/span>&nbsp;&nbsp;<a href=\"https:\/\/www.securitytoday.de\/en\/2026\/04\/06\/ransomware-2026-companies-pay-ransom-payment\/\" style=\"color:#333;text-decoration:underline;\">Ransomware 2026: What Happens When Companies Pay<\/a><\/p>\n<p>The confusion is common: people refer to the NIS2 report as if it were a single act. In practice there are at least three parallel channels with different deadlines and recipients. Serving any of them too late creates a consequential\u2011damage risk that is often larger than the incident itself. No paragraph\u2011by\u2011paragraph legal exegesis follows, just an operational framing for the first hour window.<\/p>\n<h2 style=\"margin-top:64px;margin-bottom:20px;padding-top:16px;\">Who is actually affected<\/h2>\n<p>The NIS2 Directive (<a href=\"https:\/\/eur-lex.europa.eu\/eli\/dir\/2022\/2555\/oj\">EUR\u2011Lex 2022\/2555<\/a>) covers far more companies than the previous version. It includes essential and important entities from 18 sectors, including energy, transport, health, digital infrastructure, as well as food, postal services and chemicals. The threshold is typically 50 employees or \u20ac10\u202fmillion annual turnover, with upward exceptions for critical sectors.<\/p>\n<p>Germany\u2019s transposition via the NIS2 Implementation and Cyber\u2011Security Strengthening Act (NIS2UmsuCG) has been postponed several times in parliament. Regardless of the implementation status, the directive is binding. The reporting deadlines from Art.\u202f23 have been carried over virtually unchanged in the drafts known so far.<\/p>\n<p>A second point that often gets overlooked: GDPR and NIS2 do not exclude each other. A ransomware incident with exfiltrated customer data triggers both regimes. Three pathways, one set of facts, different forms.<\/p>\n<div class=\"evm-stat evm-stat-highlight\" style=\"text-align:center;background:#f0f9fa;border-radius:12px;padding:32px 24px;margin:32px 0;\">\n<div style=\"font-size:48px;font-weight:700;color:#004a59;letter-spacing:-0.03em;\">24\u202fh \/ 72\u202fh \/ 1\u202fmonth<\/div>\n<div style=\"font-size:15px;color:#444;margin-top:8px;\">NIS2 reporting cascade: Early Warning, Incident Notification, Final Report<\/div>\n<div style=\"font-size:12px;color:#888;margin-top:8px;\">Source: Art.\u202f23 Directive (EU) 2022\/2555<\/div>\n<\/div>\n<h2 style=\"margin-top:64px;margin-bottom:20px;padding-top:16px;\">Reporting Channel 1: BSI and the 24-Hour Initial Report<\/h2>\n<p><strong>What is the NIS2 initial report?<\/strong> The NIS2 initial report (Early Warning) is a structured brief message to the competent national authority, which must be submitted within 24 hours of becoming aware of a significant security incident. It contains minimal mandatory details and serves as an early warning\u2014not a case analysis.<\/p>\n<p>The 24-hour NIS2 initial report isn\u2019t an incident report. It\u2019s a structured early-warning signal to the relevant authority. The goal? Simply to loop them in so they can issue alerts to other sectors if needed. Anyone who doesn\u2019t grasp this will spend hour one drafting a root-cause analysis that won\u2019t be finished by hour 12.<\/p>\n<p>Realistically, an initial report must include just four key data points: suspicion of malicious activity (yes or no), a rough classification of the incident (ransomware, DDoS, access compromise, supply chain), an initial assessment of cross-border impact, and a contact for follow-up questions. Twenty-four hours after detection, that\u2019s about all you can reliably determine.<\/p>\n<p>In Germany, reports are submitted via the BSI\u2019s reporting portal. The exact platform varies by sector and current implementation\u2014KRITIS operators already know the process from existing reporting obligations, while newly designated essential entities should head to the BSI\u2019s security incident form first. Anyone logging in for the first time during an actual incident is already in trouble. Access must be set up *before* an incident, not during.<\/p>\n<p>The 72-hour follow-up report is far more demanding in terms of content. It requires an initial assessment of severity, impact, and indicators of compromise. If you don\u2019t have a clear picture of the attack vector by then, say so\u2014<a href=\"https:\/\/www.securitytoday.de\/en\/2026\/04\/09\/cyber-resilience-act-from-september-11-2026-the-24-hour-reporting-obligation-that-it-security-teams-must-now-establish-processes-for\/\">the CRA reporting chain<\/a> follows the same logic: documenting clear uncertainty is better than having to retract a seemingly confident finding later.<\/p>\n<h2 style=\"margin-top:64px;margin-bottom:20px;padding-top:16px;\">Reporting Channel 2: Data Protection \u2013 72 Hours, but a Different Clock<\/h2>\n<p>If personal data is affected, Article 33 of the GDPR kicks in simultaneously. You have 72 hours from awareness to notify the competent supervisory authority, including mandatory details: type of breach, affected data categories and approximate number of individuals, contact point, likely consequences, and measures taken.<\/p>\n<p>The critical nuance? The 72-hour countdown starts when the company becomes aware\u2014not when the board is informed. If this distinction isn\u2019t clearly defined in your internal escalation process, expect uncomfortable questions from the authority later.<\/p>\n<p>In Germany, the responsible authority is the supervisory body of the federal state where your main establishment is located. For cross-border data processing, the One-Stop-Shop principle applies, with a lead authority. In practice, however, large incidents often require separate submissions to multiple authorities, each demanding their own level of detail.<\/p>\n<p>A common pitfall: submitting the GDPR report before forensic findings are clear, using estimated numbers of affected individuals. This is permissible and even expected (<a href=\"https:\/\/eur-lex.europa.eu\/eli\/reg\/2016\/679\/oj\">Article 33(4) GDPR<\/a> allows follow-ups). The problem arises when those estimates remain unchanged weeks later. To authorities, that reads as indifference\u2014not diligence.<\/p>\n<h2 style=\"margin-top:64px;margin-bottom:20px;padding-top:16px;\">Reporting Path 3: Customers, Key Accounts, and Insurers<\/h2>\n<p>The third reporting path is often underestimated, even though it can come with the tightest deadlines. Major clients\u2014especially in finance, pharma, and public sectors\u2014frequently include reporting clauses in their contracts requiring notification within 24 or even 12 hours. Cyber insurance policies typically demand &#8220;immediate&#8221; reporting, a term courts have already interpreted in some cases as meaning &#8220;within 24 hours.&#8221;<\/p>\n<p>If you meet contractual reporting deadlines later than regulatory ones, you risk two distinct but equally unpleasant consequences: customers may enforce contractual penalties or special termination rights, while insurers may deny coverage for failing to meet the &#8220;immediate notification&#8221; obligation. In one anonymised pattern from the financial sector\u2014repeatedly described in post-mortem sessions\u2014an insurer reduced the claims payout across the board because the initial report was only submitted after forensic analysis had concluded.<\/p>\n<p>Operational takeaway: contractual reporting chains belong in the same runbook as regulatory ones. If you only start compiling your customer list, SLA matrix, and insurer contacts during an incident, you\u2019ll waste precious hours. And the 24-hour clock is ticking for all three paths simultaneously.<\/p>\n<p>A third underestimated component: press and data subject communications. Article 34 of the GDPR requires notifying affected individuals if the breach poses a high risk to their rights. For this, a pre-approved template should be ready\u2014legally sound and communication-ready. If you wait to draft data subject emails until after the regulatory report is submitted, you risk seeing the story break in the media before your customers hear your side.<\/p>\n<blockquote style=\"border-left:4px solid #69d8ed;margin:32px 0;padding:20px 24px;background:#fafafa;border-radius:0 8px 8px 0;font-size:1.1em;line-height:1.6;color:#333;\"><p>\n&#8220;The initial report isn\u2019t documentation\u2014it\u2019s a placeholder. If you treat it like a full incident report, you\u2019ll burn the time you need for actual incident response.&#8221;<br \/>\n<cite style=\"display:block;margin-top:12px;font-size:0.8em;color:#888;font-style:normal;\">Paraphrased from multiple documented NIS2-adjacent reporting cases, 2025\/2026<\/cite>\n<\/p><\/blockquote>\n<h2 style=\"margin-top:64px;margin-bottom:20px;padding-top:16px;\">Auto-Notification vs. Manual Control Call<\/h2>\n<p>Every security team should ask itself this question before the first report is due: How much of the initial notification can be automated, and where is a manual control call non-negotiable? Both approaches have trade-offs.<\/p>\n<p><strong>Auto-notification via predefined templates and API interfaces:<\/strong><\/p>\n<p style=\"margin-left:16px;\"><em>Pros:<\/em> Fast, consistent, and independent of staff availability\u2014especially overnight. Ideal for clear-cut cases like confirmed ransomware signatures or detected data exfiltration.<\/p>\n<p style=\"margin-left:16px;\"><em>Cons:<\/em> Blind to nuances. Often reports too much or too soon, creating follow-up work for corrections. Authorities tend to react poorly to serial notifications.<\/p>\n<p><strong>Manual control call before written notification:<\/strong><\/p>\n<p style=\"margin-left:16px;\"><em>Pros:<\/em> Clarifies context, answers questions, and confirms reporting paths. Builds trust in critical incidents, which later translates into less aggressive follow-up inquiries.<\/p>\n<p style=\"margin-left:16px;\"><em>Cons:<\/em> Doesn\u2019t scale in multi-factor incidents affecting parallel sectors. Requires trained communication skills\u2014a capability rarely practiced in incident drills.<\/p>\n<p>The pragmatic solution lies in combining both: auto-notification for the 24-hour initial report in clear-cut cases, and a manual call for the 72-hour follow-up or grey-area scenarios. The key is ensuring the process is in place before an incident strikes\u2014not developed mid-crisis.<\/p>\n<h2 style=\"margin-top:64px;margin-bottom:20px;padding-top:16px;\">Pitfalls from the first reporting cases<\/h2>\n<p>The following patterns come from anonymised case studies and post-mortem sessions in 2025\/26. Recurring, not unique:<\/p>\n<p><strong>The contact person trap.<\/strong> The initial report names a person who neither has the necessary information nor can answer follow-up questions immediately. Fix: a 24\/7 availability matrix with a backup protocol\u2014not just an IT management phone number.<\/p>\n<p><strong>Parallel or sequential?<\/strong> Teams first notify the BSI, then data protection, then customers\u2014to build a consistent narrative. Result: deadlines are missed across all three channels. Fix: report in parallel; different levels of detail per recipient are expected.<\/p>\n<p><strong>The log gap.<\/strong> Without complete, accessible logs, the 72-hour follow-up report on the attack vector remains vague. See <a href=\"https:\/\/www.securitytoday.de\/en\/2026\/04\/11\/infostealer-2026-how-stolen-session-cookies-bypass-mfa\/\">infostealer attacks using session cookies<\/a>, where precisely these gaps make the difference between resolution and an open question. Fix: log retention is part of preparedness.<\/p>\n<p><strong>Insurers as an afterthought.<\/strong> The cyber policy sits in the legal department, but no one on the security team knows the reporting deadlines. Fix: include the policy in the incident playbook and review deadlines in advance.<\/p>\n<p><strong>Communication hygiene.<\/strong> What\u2019s written in the report form can be used in civil lawsuits. Phrases like &#8220;known issue that was ignored&#8221; are honest but legally risky. Fix: security, legal, and communications teams must approve content together\u2014not the CISO alone under time pressure.<\/p>\n<h2 style=\"margin-top:64px;margin-bottom:20px;padding-top:16px;\">Conclusion<\/h2>\n<p>The three reporting channels\u2014BSI, data protection, and customers\/insurers\u2014aren\u2019t an optional drill but parallel traffic. Those navigating them for the first time in a crisis will lose time they don\u2019t have. The real work happens *before* the incident: setting up access, drafting templates, maintaining contact matrices, and reviewing insurance policies. An IR playbook that doesn\u2019t cover all three channels is incomplete in 2026.<\/p>\n<p>A concrete suggestion for the next quarterly review: test your playbook against the three reporting channels. If you can\u2019t say within an hour which templates are ready for which channel\u2014and who steps in if the primary contact is on vacation\u2014there\u2019s work to do. A helpful resource: <a href=\"https:\/\/mybusinessfuture.com\/daten-governance-mittelstand-praxischeck-dgg\/\">Data governance for SMEs<\/a> shows the foundations needed for serious reporting capability.<\/p>\n<p>One final point, rarely on the slides: tabletop exercises with external observers. If you only run your playbook internally, you develop blind spots in external communication. An experienced legal advisor and crisis PR contact in the exercise loop will uncover gaps that could prove costly in a real incident. Once a year, with a realistic scenario and a stopped clock. That\u2019s the cheapest insurance against reporting errors.<\/p>\n<h2 style=\"margin-top:64px;margin-bottom:20px;padding-top:16px;\">Frequently Asked Questions<\/h2>\n<h3>Does the NIS2 reporting obligation apply in Germany as early as 2026?<\/h3>\n<p>The NIS2 Directive has been in force at EU level since 17 January 2023, with a transposition deadline of 17 October 2024. Germany\u2019s implementation via the NIS2UmsuCG has been delayed multiple times. Regardless of the national transposition status, the directive\u2019s requirements and existing BSIG reporting obligations for critical infrastructure operators remain in effect. Those likely to fall under NIS2 should not wait for the final signature.<\/p>\n<h3>Do I need to report a ransomware incident to both the BSI and data protection authorities?<\/h3>\n<p>Yes, as soon as personal data is\u2014or could be\u2014affected. The two reporting obligations operate under separate regimes with distinct deadlines. NIS2 focuses on supply chain security, while the GDPR protects data subject rights. One report does not replace the other.<\/p>\n<h3>What\u2019s the difference between the initial report and the incident notification under NIS2?<\/h3>\n<p>The initial report (Early Warning, 24 hours) is a structured signal with minimal details. The Incident Notification (72 hours) provides a first substantive assessment, including the attack vector, severity, and impact\u2014where known. The final report, due within one month, delivers the complete evaluation.<\/p>\n<h3>Which authority in Germany is responsible for GDPR reports?<\/h3>\n<p>This depends on the location of your main establishment. Companies in Bavaria typically report to the Bavarian State Office for Data Protection Supervision (BayLDA) for the private sector, while those in North Rhine-Westphalia submit to the State Commissioner for Data Protection and Freedom of Information NRW, and so on. For cross-border processing, the One-Stop-Shop principle applies, designating a lead authority.<\/p>\n<h3>What happens if the report to the cyber insurer is delayed?<\/h3>\n<p>In the worst case, this could lead to reduced coverage or even a complete exclusion of coverage. Cyber policies usually require &#8220;immediate&#8221; notification, a term strictly interpreted in the event of a claim. The contractual reporting obligation should be your first priority\u2014often within 24 hours of becoming aware of the incident.<\/p>\n<h2 style=\"margin-top:64px;margin-bottom:20px;padding-top:16px;\">Further Reading<\/h2>\n<p>&rarr; <a href=\"https:\/\/www.securitytoday.de\/en\/2026\/04\/11\/infostealer-2026-how-stolen-session-cookies-bypass-mfa\/\">Infostealer 2026: Why stolen session cookies bypass MFA<\/a><\/p>\n<p>&rarr; <a href=\"https:\/\/www.securitytoday.de\/en\/2026\/04\/09\/cyber-resilience-act-from-september-11-2026-the-24-hour-reporting-obligation-that-it-security-teams-must-now-establish-processes-for\/\">Cyber Resilience Act from 11 September 2026: The 24-hour reporting obligation<\/a><\/p>\n<p>&rarr; <a href=\"https:\/\/mybusinessfuture.com\/daten-governance-mittelstand-praxischeck-dgg\/\">Data governance for SMEs: A practical check on the new DGG<\/a><\/p>\n<div style=\"margin:40px 0 24px 0;\">\n<p style=\"margin:0 0 12px 0;font-size:0.78em;font-weight:700;text-transform:uppercase;letter-spacing:0.18em;color:#666;\">More from the MBF Media Network<\/p>\n<div style=\"padding:14px 18px;border-left:3px solid #0bb7fd;background:#fafafa;margin-bottom:6px;\">\n<div style=\"font-size:0.7em;font-weight:700;color:#0bb7fd;text-transform:uppercase;letter-spacing:0.12em;margin-bottom:4px;\">cloudmagazin<\/div>\n<p><a href=\"https:\/\/www.cloudmagazin.com\/2026\/04\/11\/platform-engineering-2026-internal-developer-platforms\/\" style=\"font-weight:600;line-height:1.4;color:#1a1a1a;text-decoration:none;\">Platform Engineering 2026: Internal Developer Platforms as the foundation<\/a>\n<\/div>\n<div style=\"padding:14px 18px;border-left:3px solid #202528;background:#fafafa;margin-bottom:6px;\">\n<div style=\"font-size:0.7em;font-weight:700;color:#202528;text-transform:uppercase;letter-spacing:0.12em;margin-bottom:4px;\">mybusinessfuture<\/div>\n<p><a href=\"https:\/\/mybusinessfuture.com\/e-rechnung-2026-pflichtstart-mittelstand-praxis\/\" style=\"font-weight:600;line-height:1.4;color:#1a1a1a;text-decoration:none;\">E-invoicing 2026 for SMEs: 15 months after the mandatory rollout<\/a>\n<\/div>\n<div style=\"padding:14px 18px;border-left:3px solid #666;background:#fafafa;\">\n<div style=\"font-size:0.7em;font-weight:700;color:#666;text-transform:uppercase;letter-spacing:0.12em;margin-bottom:4px;\">digital-chiefs<\/div>\n<p><a href=\"https:\/\/www.digital-chiefs.de\/cloud-repatriation-2026-statistische-illusion-hybrid-architektur-cio\/\" style=\"font-weight:600;line-height:1.4;color:#1a1a1a;text-decoration:none;\">Cloud Repatriation 2026: Hybrid architecture in the CIO spotlight<\/a>\n<\/div>\n<\/div>\n<p style=\"color:#888;font-size:0.85em;margin-top:32px;\"><em>Status: April 2026. Legal assessment provided without warranty; regulations continue to evolve.<\/em><\/p>\n<p style=\"text-align:right;font-style:italic;color:#888;font-size:0.85em;\">Source header image: Pexels \/ Sergey Sergeev (px:32845695)<\/p>\n","protected":false},"excerpt":{"rendered":"BSI, data protection authorities, and insurers expect parallel reports with individual deadlines in 2026. What the NIS2 initial report requires\u2014and where reporting runs into problems.","protected":false},"author":10,"featured_media":12309,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"_yoast_wpseo_focuskw":"NIS2 Meldewege","_yoast_wpseo_title":"NIS2 Crisis 2026: Three Reporting Channels Companies Need in the First Hour of a","_yoast_wpseo_metadesc":"BSI, authorities, insurers: Know reporting duties in the first hour & how NIS2 impacts you by 2026. Act now!","_yoast_wpseo_meta-robots-noindex":"","_yoast_wpseo_meta-robots-nofollow":"","_yoast_wpseo_meta-robots-adv":"","_yoast_wpseo_canonical":"","_yoast_wpseo_opengraph-title":"","_yoast_wpseo_opengraph-description":"","_yoast_wpseo_opengraph-image":"","_yoast_wpseo_opengraph-image-id":0,"_yoast_wpseo_twitter-title":"","_yoast_wpseo_twitter-description":"","_yoast_wpseo_twitter-image":"","_yoast_wpseo_twitter-image-id":0,"_evm_translation_lang":"","featured_post":0,"featured_post_sortierung":0,"_wp_old_slug":[],"footnotes":""},"categories":[215],"tags":[],"class_list":["post-12596","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-case-studies"],"evm_reading_time_minutes":13,"wpml_language":"en","wpml_translation_of":12310,"_links":{"self":[{"href":"https:\/\/www.securitytoday.de\/en\/wp-json\/wp\/v2\/posts\/12596","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.securitytoday.de\/en\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.securitytoday.de\/en\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.securitytoday.de\/en\/wp-json\/wp\/v2\/users\/10"}],"replies":[{"embeddable":true,"href":"https:\/\/www.securitytoday.de\/en\/wp-json\/wp\/v2\/comments?post=12596"}],"version-history":[{"count":3,"href":"https:\/\/www.securitytoday.de\/en\/wp-json\/wp\/v2\/posts\/12596\/revisions"}],"predecessor-version":[{"id":15916,"href":"https:\/\/www.securitytoday.de\/en\/wp-json\/wp\/v2\/posts\/12596\/revisions\/15916"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.securitytoday.de\/en\/wp-json\/wp\/v2\/media\/12309"}],"wp:attachment":[{"href":"https:\/\/www.securitytoday.de\/en\/wp-json\/wp\/v2\/media?parent=12596"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.securitytoday.de\/en\/wp-json\/wp\/v2\/categories?post=12596"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.securitytoday.de\/en\/wp-json\/wp\/v2\/tags?post=12596"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}