Run one discovery into two notifications — the UK three-hour Ofcom expectation and the EU twenty-four-hour early warning — and leave every notification to a named person.
A compromise is discovered, and one moment of awareness starts both clocks, in the UK and in the EU.
02
An effect is weighed against the s.105K(2) matters: period, persons, geography, extent of activities.
Reason
03
An urgent UK case runs on Ofcom policy of 15 September 2023: initial notification usually within 3 hours.
04
An EU incident crosses the significance line, and Article 23(4) opens at 24 hours and closes at 72.
05
A final EU report falls one month after the notification is submitted, not one month after awareness.
Decide
06
A review falls due, and UK regulation 11 wants a written assessment of the next 12 months of risk.
07
A supplier contract is in force, and the UK Code reaches all contracts by 31 March 2027.
Out
08
A Member State has not transposed, and the old EECC security articles went on 18 October 2024.
09
Execute write actions only inside the approval boundaries agreed during implementation.
→Product statement
The agent drafts and keeps the record; a board-level person or committee holds the responsibility, a named person notifies, and the provider answers for it.
Example workflow
One compromise, discovery to notification
AgentHuman
1Compromise discoveredMonitoring tools, incident tickets, supplier advisories or a CSIRT contact
2Effect assessed against the limbsPeriod, persons, geographical area and extent of activities, and the near-miss limb with them
3Notifications draftedThe UK notification and the EU early warning, drafted from one set of facts
4Controls appliedClock checks, jurisdiction checks, evidence-sufficiency checks and completeness confidence
No human action required
Stages 1 to 4 run unaided, and nothing is notified at any of them — the agent is drafting, and the security lane opens at the completeness gate.
5DecisionBranches at the completeness gate
Evidence sufficient
Goes to the named notifier to send.
Anything thin
Adds a regulatory counsel read first.
Security review
The draft is held with its clocks, its evidence and the jurisdiction each one belongs to.
Notify the regulator · Append evidence · Send to counsel
Notified — by a named person▼
6Incident and assessment records updatedOnly where write access and security policy allow it
7Outcome evaluatedClock margin, effect evidence, counsel corrections and what the post-incident review found
Corrections
Each counsel correction is counted in the evaluation.
What should not run autonomously
Human approval stays in control
Outside the boundary — human approval required8 items
Deciding the UK significance test is not met.
Notifying Ofcom or any EU national authority.
Sending an EU early warning under Art. 23(4).
Approving EU risk-management measures under Art. 20.
Automation boundaryAgent acts unaided
✓Start both clocks from the one moment the provider became aware.
✓Weigh the effect against each s.105K(2) matter and record the answer.
✓Draft the UK and EU notifications from one assembled set of facts.
✓Hold the twelve-month written assessment current against what changed.
Nothing reaches a regulator except by a named person, inside the agreed boundaries.
Judging that the near-miss limb has not been reached.
Telling a customer their service went unaffected.
Concluding the overall forward risk is low.
Changes to clocks, significance rules or templates.
Example output
One compromise, annotated
Our NOC copilot declares the cause; this record is what two regulators are notified from.
Notification draft · single compromiseIllustrative example
Compromise
Drafted as
Clock
Evidence of record
Confidence
Held for
Core signalling node failure
UK initial notification, urgent, effect assessed
Hour 2 · UK 3-hour clock
Monitoring and incident record, 12 August 2026
Held unsent
The named notifier, in person
As receivedTaken from the monitoring tools and the incident record — it reaches as far as the logging does.
What the record holdsAwareness time-stampEffect-limb evidenceAssessment extract
Why no significance call hereSignificance is the s.105K test for a person, not a model output.
ActionNotify the regulatorAppend evidenceSend to counsel
What the score decidesBelow the configured threshold the draft picks up a counsel read before it moves.
Value
Where AI adds value
The same four claims, placed at the point in the workflow where each one applies.
Where the value landsValue 01 – 04
Every compromiseFrom the monitoring tools that saw it
03Evidence
Where the notification goes
Our outage and disaster reporting agent files the US reports from this same discovery — three regulators there, three clocks, another signer. Financial-sector resilience sits under DORA, a separate regime with its own register and its own clocks.
01Approved path
Three hours is not twenty-four
Ofcom policy of 15 September 2023 expects an urgent UK initial notification usually within 3 hours; EU Article 23(4) allows 24 hours for the early warning.
02Human review
What was checked, and what was not
No Ofcom penalty specifically for the s.105K or s.105N reporting duties was found, and no tier-by-tier compliance assessment is published.
04Build an evidence trail
The compromise, the effect assessed against it and the person who notified stay on the record.
Integrations
Typical integrations
Five system groups connect to the same agent. Which of them are in scope is decided in discovery.
Notification channelsOfcom incident reporting National CSIRT contacts
Security monitoringSIEM · network monitoring Vulnerability and patch records
Governance recordsPolicy · board oversight Supplier and contract register
Agent
Security duty evidence
Reads the compromise Drafts both notifications Holds for the notifier
Incident and case systemsServiceNow · Jira Post-incident review files
A jurisdiction-level assessment-currency figure can read clean while one jurisdiction carries most of the corrections. Nestack reports the counsel-correction rate by jurisdiction, not only in total.
Slice performance — reported separately, not only in aggregateIllustrative example
Slice
Failure rate
Lift
Lift vs. threshold
Status
UK urgent compromises
6.7%
3.6×
Review
EU states not yet transposed
4.8%
2.6×
Review
EU states with NIS2 transposed
3.0%
1.6×
Watch
UK non-urgent compromises
1.5%
0.8×
Normal
Bar: counsel-correction-rate lift vs. UK non-urgent baseline · scale 0–4.0× · tick marks the 2.0× review threshold2 of 4 slices over threshold
Evidence-linked improvement
What a missed clock costs
A cycle ends when the missed reporting clock is a standing case. That suite is what the next assessment written is measured against.
Improvement cycle · five stagesSwitchback — the path turns at Improve and returns at Learn
01Detect
Counsel-correction rate rises in one jurisdiction.
02Diagnose
The three-hour expectation that lives nowhere in the Act somebody read is traced back until one cause remains.
03Improve
Every change leaves numbered, with the measures that caused it filed beneath.
04Verify
A single red measure case is enough to keep the release back.
05Learn
The case is permanent, and the reporting rules are rewritten with it.
Learn → DetectThe return edge. The next assessment is measured against a suite one case longer.
Typical build scope
Twelve workstreams across six weeks
The build scope read against the delivery timeline. Week structure follows the six-week plan — discovery, sources, notification assembly, evaluation, integration, then production validation and handover.
WorkstreamWeek 1Week 2Week 3Week 4Week 5Week 6
01Security-duty discovery and boundary definition.
02Monitoring and governance sources.
03Significance-limb and reporting-clock mapping work.
04Compromise evidence ingestion.
05Jurisdiction, clock and record binding.
06Completeness scoring and counsel routing.
07Named-notifier release workflow.
08Incident and case-system integration.
09Significance and clock cases.
10Guardrails and board-oversight controls.
11Compromise-trail instrumentation.
12Deployment, documentation and Agent Care handover.
12 workstreams · 6 weeks · bar shows the weeks a workstream is active — several run in parallelFinal scope and sequence confirmed in discovery
Engagement tiers
What each tier includes
Rows are the capabilities named in each tier's scope. Higher tiers include everything below them.
Capability✓ in scope · — not at this tierPilotOne jurisdiction, one dutyProductionProduction notification workflowAdvancedMultiple jurisdictions / entities
Introduced at Pilot
Notification drafting to your rules✓✓✓
Named-person notification✓✓✓
Risk-assessment baseline✓✓✓
Introduced at Production
Reporting by jurisdiction—✓✓
Release workflow in your systems—✓✓
Approved write-back—✓✓
Security-monitoring integration—✓✓
Introduced at Advanced
Multi-jurisdiction security duties——✓
Cross-border evidence packs——✓
High incident volume——✓
Multi-regulator notification controls——✓
Build priceFrom $5,000From $8,000Custom quote
Final build priceConfirmed after discovery based on integrations, workflow complexity, transaction volume, approval controls and deployment requirements.
Separate from buildBuild pricing is separate from recurring Agent Care, which covers managed monitoring, evaluations, incidents and verified improvements after launch.
What we need from you
What you bring, and what we build with it
Each input maps to a piece of build scope and a week in the delivery timeline.
You bringWe build with it
01Your security measures as implemented→Measure-to-regulation binding and evidence captureWeek 1
02Representative compromises and incident records→Effect-limb scoring, clock binding and the draft baselineWeek 2
03Your jurisdictions and notification channels→Duty mapping, jurisdiction binding and the automation boundaryWeek 1
04Access to relevant APIs, feeds or exports→Monitoring, governance and incident-source assessment, then integration setupWeek 2
05Assessments you would not want relied on→Significance cases and the evaluation suiteWeek 4
06What no security assessment may conclude→Completeness scoring, counsel routing, guardrails and release controlsWeek 3
07A named person to notify, and the board-level owner→Named-notifier release workflow, then pilot and production validationWeeks 5–6
Nothing else is requiredDeployment, documentation and Agent Care handover are ours.
Delivery timeline
Four phases across six weeks
The widths here are the weeks the work actually takes, and the fifth week is shared for that reason.
PhaseW1W2W3W4W5W6
DiscoveryW1
BuildW2 – W3
EvaluateW4 – W5
Pilot & LaunchW5 – W6
Week focusW1Security-duty discovery, jurisdiction mapping and the automation boundaryW2Source integration and the risk-assessment baselineW3Notification assembly, clock logic and release controlsW4Evaluation suite, significance cases and failure-mode testingW5Record integration, pilot compromises and targeted correctionsW6One assessment year run under the responsible board member, then Agent Care handover
Reading the bandA band spans only the weeks its own work is named for. The fifth week doubles because two phases run inside it.
At the end of W6When the assessment record validates, Agent Care takes the agent on.
DurationSix-week plan shown · typical delivery 4–6 weeks depending on scope confirmed in discovery.
Next step · Telecom AI agent
Build a security-duty agent around two clocks that start from one discovery.
Show us how a compromise reaches you today and who notifies. Bring one recent case and we will run it through both clocks with you — the UK 3-hour Ofcom expectation of 15 September 2023 and the EU 24-hour early warning under Article 23(4) — from one moment of awareness.