I am a lawyer and my field do cross this area which the events have transpired. First, yes, everyone should acknowledge that this matter has been handled poorly by their corporate in-house and external lawyers. These should not have happened. The company should face consequences. I advise my data controller corporate clients to reach out to the reporter/whistleblower immediately and have the IT team collaborate, at t…
Bullshit, NIS 2 article 12 specifically says CSIRTs must coordinate the negotiation of a disclosure timeline between reporter and provider. I'd say offering a 30 day embargo while CC'ing the relevant CSIRT is the start of such negotiation from the reporter.
My biggest doubt about this story, LLM writing aside, is the lack of mention of a CSIRT follow up.