NIS2Compass — NIS2-Compliance-Plattform
Use CasesPricing
Go to platform

Explore

  • Blog
  • FAQ
  • Glossary
  • Use Cases
  • Sectors
  • Pricing

Official Sources

  • BSI – Bundesamt für Sicherheit in der Informationstechnik
  • NIS2-Richtlinie (EUR-Lex)
  • NIS2UmsuCG (Bundesgesetzblatt)
NIS2Compass — NIS2-Compliance-Plattform

Your Navigator Through NIS2 Compliance

Legal

  • Privacy Policy
  • Terms of Service
  • Cookie Policy
  • Imprint

Resources

  • Blog
  • Use Cases
  • Industries
  • Pricing
  • FAQ
  • Glossary

Connect

Contact

kontakt@nis2compass.de

NIS2Compass bietet Informationen und Orientierungshilfen zur NIS2-Compliance. Die Inhalte stellen keine Rechtsberatung im Sinne des Rechtsdienstleistungsgesetzes (RDG) dar und ersetzen keine individuelle rechtliche oder fachliche Beratung.

© Copyright 2026 NIS2Compass. All Rights Reserved.

Made in GermanyAllianz für Cyber-Sicherheit — Teilnehmer
Home/Blog/NIS2 Crisis Communication: What Role Does Telfo Play?
  1. What Does NIS2 Require for Crisis Communication Under §30 BSIG?
  2. Who Decides in an Emergency? How Do You Build an Escalation Matrix?
  3. How Should the Internal Escalation Chain Be Structured?
  4. Who Belongs on the Crisis Team?
  5. What Gets Overlooked in the Escalation Matrix?
  6. How Do Internal and External Communication Differ?
  7. Which Communication Channels Need Redundancy?
  8. What Role Does Phone Availability Play in a Crisis?
  9. What Is Telfo, and Where Does It Fit In?
  10. How Does a Hospital Group Build Its Crisis Communication? (Case Study)
  11. How Do You Get Started with Crisis Communication Planning? (Practical Checklist)
  12. Frequently Asked Questions
  13. Is Crisis Communication Mandatory for All Companies Under NIS2?
  14. What Belongs in a Crisis Communication Plan?
  15. Is a Phone Fallback Enough as Emergency Communication?
  16. Does an AI Phone Assistant Like Telfo Make a Company NIS2-Compliant?
  17. How Often Does Crisis Communication Need to Be Tested?
Guide

NIS2 Crisis Communication: What Role Does Telfo Play?

Authored by NIS2Compass Redaktion, NIS2 Compliance Expert
Last updated:September 8, 202610 min read
Share
Abstract network of people icons connected by phone, with one central connection broken and a redundant connection highlighted

NIS2 requires crisis management and secure emergency communication under §30 BSIG: escalation matrix, redundant channels, crisis communication plan — plus where Telfo fits in.

Written by the NIS2Compass editorial team | Last updated: September 2026

Under §30 (2) No. 3 and No. 10 BSIG, companies subject to NIS2 must demonstrate crisis management and secure emergency communication. According to Bitkom, only 28 percent of German companies currently have established crisis or emergency management. NIS2Compass guides you step by step through the escalation matrix, communication channels, and crisis communication plan in Guide Chapter 7. Phone availability, for example via Telfo, is just one building block among several.

What Does NIS2 Require for Crisis Communication Under §30 BSIG?

NIS2 applies on a risk basis: only entities above a certain size in 18 defined sectors are affected, not every company. For them, crisis communication is one of the ten mandatory areas under §30 (2) BSIG — specifically No. 3 (business continuity and crisis management) and No. 10 (secure communication, including emergency communication systems where applicable). NIS2Compass places these obligations within a structured implementation path.

The law spells out both requirements specifically. No. 3 requires the "maintenance of operations, such as backup management and disaster recovery, and crisis management." No. 10 requires, among other things, "secure voice, video, and text communication, as well as secure emergency communication systems where applicable."

This business continuity obligation stands independently alongside the reporting obligations. Which incidents must be reported to the BSI, and when, is covered in a separate guide; this article is about how a company stays able to act and communicate in an actual emergency.

The BSI Standard 200-4 on business continuity management provides an operational framework for this. It fleshes out §30 BSIG with specifics on alerting, crisis team operations, and crisis communication. A recent survey shows just how big the gap is in practice: on average, German companies can only keep operating for around 20 hours during an internet outage, and 21 percent cannot continue working at all (Bitkom, February 11, 2026). NIS2Compass walks through the practical implementation of these obligations in Guide Chapter 7, "Business Continuity and Crisis Management."

Who Decides in an Emergency? How Do You Build an Escalation Matrix?

An escalation matrix defines who is informed and involved at which severity level of an incident, and is a core component of the incident response plan under §30 (2) No. 2 BSIG. Currently, however, only 28 percent of German companies have established crisis or emergency management, with another 25 percent planning to introduce it, according to a Bitkom survey. NIS2Compass structures roles and escalation levels in Guide Chapter 4.

How Should the Internal Escalation Chain Be Structured?

The escalation chain must function around the clock, because security incidents don't respect office hours (Guide Chapter 4.1.2). Who is reached at which level depends on the severity of the incident. That threshold is based on what counts as a "significant security incident" under NIS2.

Who Belongs on the Crisis Team?

Under §38 BSIG, executive management is responsible for implementing and overseeing the §30 measures and must approve the incident response plan (Guide Chapter 4.1.4) — this approval is itself a documentation requirement. The information security officer or crisis team lead handles operational management, and the data protection officer is brought in whenever personal data is involved, in parallel with the GDPR reporting obligation. External forensics providers are an escalation option, not a standard part of the team.

A functioning escalation chain is also a prerequisite for meeting the 24-hour early warning deadline in the first place.

What Gets Overlooked in the Escalation Matrix?

The matrix also has to work when individual roles are unavailable. Backup arrangements for vacation and illness are often forgotten in practice, even though they can determine how well a real emergency is handled.

How Do Internal and External Communication Differ?

Internal and external communication belong in separate plans (Guide Chapter 4.1.3). Internally, the communication plan clarifies who alerts whom and what information the crisis team needs for its decisions. Externally, it defines what customers, suppliers, and the public are told, and who signs off on that.

Which Communication Channels Need Redundancy?

If a cyberattack takes down email, your collaboration tool, or the customer portal, at least one independent channel needs to keep working. §30 (2) No. 10 BSIG requires secure communication and, where applicable, dedicated emergency communication systems. Currently, however, only 58 percent of German companies have alternative communication tools for a crisis, according to Bitkom.

This redundancy has to be planned and tested before an emergency happens, not improvised during one. That calls for out-of-band emergency communication — channels that run physically and technically separate from your standard IT. Concrete failure scenarios help with planning: What still works if the email server is encrypted? If Teams or Slack are unreachable? If the customer portal is down?

The answer usually lies in personal mobile phones, an alternative domain or a separate cloud mailbox, and traditional telephony — documented in advance and ready to use the moment an emergency hits. One often-overlooked point: check for dependencies that can knock out several channels at once. A shared internet connection, the same identity provider for single sign-on, or a central phone system can render seemingly separate channels equally useless in an emergency.

So these considerations don't just end up in a drawer, they belong in a standalone crisis communication plan — separate from, but embedded within, the larger framework of the business continuity plan and IT emergency handbook. The NIS2 Guide walks through this framework in Chapter 7, "Business Continuity and Crisis Management"; Chapter 7.2.3 shows specifically how to build a crisis communication plan. The matching Excel template for the crisis communication plan from the Template Library provides the structure ready to use, including internal and external communication channels per Chapter 4.1.3 and the out-of-band procedures from Chapter 4.1.5.

What Role Does Phone Availability Play in a Crisis?

In a crisis, telephony serves as an additional communication channel when email, collaboration tools, or the customer portal fail or can no longer be trusted. This channel only becomes reliable, though, once the phone number, call handling, prioritization, and escalation are defined in advance. §30 (2) No. 10 BSIG requires "secure voice, video, and text communication, as well as secure emergency communication systems where applicable" as a mandatory topic.

A dedicated, reliable statistic on phone availability during a crisis does not exist, however.

A phone-based fallback needs to define several points in advance:

  • Reachable phone number: Which number applies in a crisis, and how is it communicated?
  • Minimum information on pickup: What details does the person or system answering the call capture immediately?
  • Urgency criteria: How is a critical call distinguished from a non-critical one?
  • Escalation path: Who is alerted at which severity level?
  • Handback: How do open cases return to regular processing once the main systems are restored?

Who answers calls when staff are tied up on the crisis team? Traditional call forwarding to backups, an external answering service, and AI-supported call handling are all equally valid options. Neither the NIS2 Directive nor the NIS2UmsuCG mandates any one of them. What matters is that the chosen solution is tested and documented in advance.

For a deeper look at emergency communication and phone availability, see Telfo's own article on the topic.

What Is Telfo, and Where Does It Fit In?

Telfo is an AI phone assistant service developed in Mannheim. According to the Telfo website (as of September 2026), the service automatically answers incoming calls, captures requests in a structured way, and, depending on configuration, passes callback requests, priorities, or status information on to the company. Telfo describes its offering as an AI phone assistant developed and hosted in Germany.

Within the scope of a company's own business continuity concept, such an assistant can support an additional phone-based process — for example, relaying approved status information or collecting callback requests in a structured way. That requires risks, dependencies, data protection, escalation paths, and a manual fallback to be clarified in advance.

There is no official partnership and no technical integration between NIS2Compass and Telfo. An AI phone assistant also does not make a company NIS2-compliant and does not replace business continuity planning. NIS2 compliance results from the entire risk management process under §30 BSIG, not from a single tool.

Shared dependencies still need attention: if the automated phone channel runs over the same internet connection or the same provider as the rest of your IT, it may go down at the same time during an outage. An independent, manually staffed fallback therefore remains necessary.

How Does a Hospital Group Build Its Crisis Communication? (Case Study)

A mid-sized hospital group with around 180 employees qualifies as an important entity in the healthcare sector under BSIG Annex 1. A ransomware incident there knocks out the patient portal and internal email at the same time, while patients and suppliers still need to be reachable. A prepared escalation matrix and a tested phone-based fallback channel keep patient communication and crisis team work running.

The following scenario is constructed and anonymized, but reflects typical processes in the healthcare sector. Ransomware encrypts parts of the internal network, the patient portal becomes unreachable, and the email system fails completely. The crisis team is alerted via a documented escalation chain (§30 (2) No. 2/3 BSIG), and external forensics are brought in based on criteria defined in advance.

Because email and internal systems are down, the communication plan activates an out-of-band channel for coordination within the crisis team — for example, phone or a separate messaging channel outside the affected network. For patients and suppliers, a prepared phone-based fallback channel kicks in: a predefined phone number with clearly defined minimum information about who receives what information and when. This keeps appointment requests and urgent questions answerable even without the portal.

Because patient data is affected, a reporting obligation under Art. 33/34 GDPR may run in parallel to the NIS2 report. Both processes need to be coordinated so that deadlines and responsibilities don't diverge. The 24-hour early warning to the joint reporting office of BSI and BBK is met because the escalation chain was already in place.

After the acute phase, the incident feeds into a post-incident review that updates the crisis communication plan. What typically happens during this follow-up is covered in the article What Happens After Reporting to BSI?

According to ENISA's 2026 NIS360 report, the healthcare sector is one of seven sectors in the risk zone, where comparatively low cybersecurity maturity meets high criticality. In this example, it wasn't any single piece of technology that determined response speed, but the preparation: an escalation matrix, redundant channels, and a tested phone-based fallback.

How Do You Get Started with Crisis Communication Planning? (Practical Checklist)

Getting started means having a documented escalation matrix, at least one redundant communication channel, and a tested crisis communication plan that still works even when individual people responsible are unavailable. Currently, only 10 percent of companies run regular crisis exercises, with another 26 percent planning to, according to Bitkom. NIS2Compass bundles the necessary templates and checklists in Guide Chapters 4 and 7.

Companies should have checked off the following points before an emergency happens:

  • Escalation chain documented: backup arrangements defined and known to everyone involved (Guide 4.1.2).
  • Communication plan set down in writing: internal and external communication channels clearly defined (Guide 4.1.3).
  • Out-of-band channel established: at least one channel that works independently of the main network (Guide 4.1.5).
  • Crisis communication plan as a standalone document: clear responsibilities instead of improvisation in an emergency (Guide 7.2.3, template).
  • Phone-based fallback defined: phone number, minimum information, and escalation criteria established, whether manually staffed or supported by an AI phone assistant like Telfo that stays reachable even when staff are unavailable.
  • Shared dependencies identified: internet connection, identity provider, and phone system checked for failure scenarios.
  • IR plan and BCP approved: signed off by executive management under §38 BSIG (Guide 4.1.4, 7.2.4).
  • Crisis exercise at least annually: conducted and documented (Guide 4.3, 7.4).
  • Lessons learned incorporated: applied to existing plans after every real incident or exercise (Guide 4.4.3, 7.4.3).

If you're not yet familiar with the reporting obligations in an emergency, you'll find the details in the article NIS2 Incident Reporting: When, What, and to Whom to Report?

Frequently Asked Questions

Is Crisis Communication Mandatory for All Companies Under NIS2?

No. Crisis communication is only mandatory for companies that fall within the scope of the BSIG: sector, company size, and special legal cases determine whether a company is affected. Affected entities must implement crisis management and business continuity under §30 (2) No. 3 BSIG as one of ten mandatory topics, regardless of their industry.

What Belongs in a Crisis Communication Plan?

A crisis communication plan includes, at a minimum, responsibilities and backup arrangements, internal and external communication channels, pre-drafted key messages for different scenarios, at least one redundant channel, and clear approval processes for external statements. NIS2Compass provides a crisis communication plan template for this in Guide Chapter 7.2.3, which can be adapted to your own processes and responsibilities.

Is a Phone Fallback Enough as Emergency Communication?

No. Phone availability is a useful additional channel, but it doesn't replace complete crisis communication planning. §30 (2) No. 10 BSIG requires secure communication overall, not just a single channel, and the law does not mandate any particular technology or provider for it.

Does an AI Phone Assistant Like Telfo Make a Company NIS2-Compliant?

No. NIS2 compliance results from the entire risk management process under §30 BSIG. An AI phone assistant like Telfo can support an additional phone-based process as part of business continuity planning, but it does not replace an escalation matrix, a communication plan, or any of the other nine mandatory measures. There is also no official partnership between NIS2Compass and Telfo.

How Often Does Crisis Communication Need to Be Tested?

The BSIG doesn't mandate a fixed testing interval, but it does require effective and up-to-date measures. In practice, at least one crisis exercise per year is recommended, as outlined in NIS2Compass Guide Chapters 4.3 and 7.4. Currently, according to Bitkom, only 10 percent of companies conduct regular exercises.

Implement NIS2 step by step

NIS2Compass guides you step by step through implementation – with an Implementation Guide, templates and Knowledge Hub.

Get started

Related Articles

news

Rhysida Berlin Leak: Is Redistributing the Data a Crime?

Rhysida published Berlin government data after the city refused a ransom. Redistributing it is a crime under §202d StGB and §42 BDSG — the legal analysis, plus NIS2 lessons.

4 min read

case-study

Blossom Health cyberattack: the extortion note landed in patients' inboxes

An extortionist sent his demand directly through Blossom Health's patient messaging. What is reported, what remains open, and which obligations would apply in Germany.

12 min read

guide

Security Incident at a Service Provider: Who Reports to the BSI?

Why every affected NIS2 entity reports a cloud or MSP incident itself, when its own 24-hour deadline starts, and how providers can inform customers in time.

9 min read

Back to Blog