Deadlines for an incident
najjab_deadlinesCompute Gulf cyber incident notification deadlines by country, authority, and severity from discovery time, including follow-ups, closure reports, and severity-change notes.
Instructions
Every notification duty an incident triggers across the given countries, soonest first, with the due time computed from the discovery time, follow up updates and closure reports, and notes when the severity grade changes the answer.
Input Schema
| Name | Required | Description | Default |
|---|---|---|---|
| lang | No | Language for the answer: en or ar. | en |
| zones | No | Financial free zones the organization also operates in: difc and adgm (UAE), qfc (Qatar). Their data protection duties are added; federal duties still apply outside the zone. | |
| sector | No | general, banking, insurance, payments, telecom, government or critical (critical infrastructure). | general |
| severity | No | The grade your own classification gives: critical, high, medium or low. | high |
| countries | Yes | Every country the organization operates in, for example ["KW", "SA"]. | |
| discovered_at | Yes | When the incident was discovered, ISO 8601 with offset, for example "2026-10-04T08:00:00+03:00". | |
| incident_type | Yes | ransomware, bec (business email compromise), data-breach or cloud-key (exposed cloud access keys). | |
| personal_data | No | True when personal data was affected. A data-breach always counts as personal data. | |
| response_format | No | markdown for reading, json for further processing. | markdown |