======================================================================== PXS-LU-CSIRT - Incident Notification Form Version 4.0 | 21/07/26 | Sensitivity: Public | TLP: CLEAR ======================================================================== Proximus Luxembourg Cybersecurity Incident Response Team Proximus Luxembourg S.A. - Commercial brand: ProximusNXT ASN: AS56665 Submit to: csirt (at) proximus (dot) lu PGP KeyID: 6E2EA9F8 Encrypt: PGP/GPG encryption strongly recommended RFC 2350: https://www.proximusnxt.lu/en/csirt Hours: 09h00-17h00 CET, Monday-Friday (excl. LU public holidays) Emergency: telecomsd (at) proximus (dot) lu ------------------------------------------------------------------------ INSTRUCTIONS ------------------------------------------------------------------------ - Fill in all applicable fields below as thoroughly as possible - Attach logs, screenshots, PCAPs, malware samples, or email headers separately and list them in SECTION 8 - PGP-encrypt this form before sending - If personal data was compromised, notify the CNPD within 72 hours - If the affected entity falls under DORA, assess whether this qualifies as a major ICT-related incident requiring notification - File a complaint with legal authorities (Police Grand-ducale, Parquet du Luxembourg) if applicable ======================================================================== SECTION 1 - ABOUT THE REPORTER ======================================================================== Organization / Company : Contact Name : Job Title / Role : Phone Number : Email Address : ======================================================================== SECTION 2 - INCIDENT CLASSIFICATION ======================================================================== Date Detected : Time Detected : Date Reported : Type of Incident (mark with [X], select all that apply): [ ] Unauthorized Access [ ] Denial of Service [ ] Vulnerability Exploitation [ ] Data Breach / Disclosure [ ] Malicious Code / Malware [ ] Ransomware [ ] Phishing / Spam [ ] Social Engineering [ ] Brand / Identity Abuse [ ] Policy Violation [ ] Insider Threat [ ] Supply Chain Compromise [ ] Other (specify): Severity Level: [ ] Critical [ ] High [ ] Medium [ ] Low [ ] Unknown Current Status: [ ] Occurring [ ] Contained [ ] Occurred [ ] Unknown ======================================================================== SECTION 3 - AFFECTED SYSTEMS & INFRASTRUCTURE ======================================================================== Impacted System(s) / Hostname(s): IP Address(es) / Range(s) : Operating System(s) : Affected Services / Applications: Network Segment / VLAN (if known): ======================================================================== SECTION 4 - INDICATORS OF COMPROMISE (IoC) ======================================================================== Suspicious IP Addresses / Domains / URLs: File Hashes (MD5 / SHA-1 / SHA-256): Malware Samples / Names (if identified): Suspicious Email Addresses / Subjects: ======================================================================== SECTION 5 - IMPACT ASSESSMENT ======================================================================== Data Affected (mark with [X]): [ ] Personal Data (GDPR) [ ] Financial Data [ ] Intellectual Property [ ] Credentials / Secrets [ ] None / Unknown Estimated No. of Affected Users / Records: Business Impact : Has the CNPD been notified? [ ] Yes [ ] No [ ] Not applicable Does this incident require DORA major-incident notification? (Applicable if the affected entity or service is in scope of Regulation (EU) 2022/2554.) [ ] Yes [ ] No [ ] Not applicable / Unknown ======================================================================== SECTION 6 - INCIDENT DESCRIPTION ======================================================================== DETAILED CHRONOLOGICAL ACCOUNT: Describe what happened, when, how it was detected, and what is currently known. ======================================================================== SECTION 7 - ACTIONS ALREADY TAKEN ======================================================================== CONTAINMENT, ERADICATION & MITIGATION STEPS: Describe containment, eradication, or mitigation steps already performed. ======================================================================== SECTION 8 - SUPPORTING EVIDENCE & ATTACHMENTS ======================================================================== Attached Materials (mark with [X]): [ ] Log files [ ] Screenshots [ ] Network captures (PCAP) [ ] Malware samples [ ] Email headers [ ] Other (specify): List of attached files (filename + short description for each): ======================================================================== SUBMISSION ======================================================================== Please PGP-encrypt this completed form and send it, along with any attached evidence, to: csirt (at) proximus (dot) lu PGP KeyID: 6E2EA9F8 The PXS-LU-CSIRT will: - Acknowledge receipt within 2 business days - Validate the incident and assess severity - Coordinate containment and remediation actions as needed - Advise on regulatory notification obligations (GDPR/CNPD, DORA) where applicable ------------------------------------------------------------------------ CONFIDENTIALITY NOTICE ------------------------------------------------------------------------ All reported information will be treated confidentially in accordance with PXS-LU-CSIRT policies (RFC 2350). See https://www.proximusnxt.lu/en/csirt ======================================================================== Proximus Luxembourg S.A. | 18, rue du Puits Romain – Z.A Bourmicht | L-8070 Bertrange – Luxembourg | T +352 45 09 15 – 1 | F +352 45 09 11 www.proximusnxt.lu VAT LU 15605033 | RCS Luxembourg B 19.669 | Autorisation d’établissement N°00116315 / 3 | ISO 27001 (Cybersecurity, Housing & Hosting, Managed and Outsourcing Services) & ISO 9001 certifications | Sensitivity: Public / TLP: CLEAR ========================================================================