← Netlock cases
Bugzilla #2007948
CCADB Compliance
NETLOCK: Full Incident Report was not published within 14 days of notification
RESOLVED
FIXED
Netlock
AI Summary
NETLOCK failed to publish a Full Incident Report within the required 14-day timeframe after receiving notification of an incident on December 27, 2025. This delay was due to a lack of enforced internal controls for tracking reporting deadlines. Although no security breaches occurred, the incident highlighted significant gaps in compliance processes. NETLOCK has since implemented a new tracking system to ensure adherence to reporting timelines and has committed to ongoing monitoring and improvements.
Chronology
- Notification received regarding the underlying incident.
- Deadline to publish the Full Incident Report.
- Full Incident Report published.
- Closure report prepared and submitted.
Participants
Roland Kaluha
R. Daurne
Nikolett Nagy
External References
Similar Local Cases
Netlock: Failure to Provide Weekly Updates
NETLOCK: Intermediate CA Certificate not disclosed to CCADB
NetLock: Failure to provide regular and timely incident updates
e-commerce monitoring gmbh: failure to follow incident report requirements
Netlock: Delayed reply from CPR sent to contact listed in section 1.5.2 of CP/S
Firmaprofesional: Delayed initial incident reporting for Bug 2016475 (72-hour preliminary and 14-day full report timing)
SwissSign: recommendation on log review process
Microsoft PKI Services: Failure to report Bugzilla 2026452 within 72 hrs