The organization must ensure its incident response process is prepared to handle vulnerability reports that are forwarded by a national cybersecurity incident response team (CSIRT).
This situation will arise if a third party reports a severe incident or an actively exploited vulnerability in one of the organization’s products directly to the authorities. The CSIRT is then obligated to inform the organization without undue delay.
The organization's internal process must be able to efficiently receive, validate, and initiate a response to these high-priority notifications.