The guidelines aim to harmonize the estimation by financial entities of aggregated annual costs and losses caused by major information and communication technology (ICT) incidents. They are part of the DORA regulation and seek to ensure consistency across various reporting requirements related to ICT incidents. Financial entities must apply a uniform approach to assess costs and losses, considering only classified…
This document is a final guide published in 2024 by the Joint Committee of the European Supervisory Authorities (ESAs), comprising the European Banking Authority (EBA), the European Insurance and Occupational Pensions Authority (EIOPA), and the European Securities and Markets Authority (ESMA). It concerns common guidelines for estimating aggregated annual costs and losses caused by major incidents related to information and communication technologies (ICT) in the financial sector, pursuant to Regulation (EU) 2022/2554 on digital operational resilience (DORA). The scope covers financial entities other than microenterprises, for ICT incidents classified as major, over annual fiscal or calendar periods, from the planned application date of 19 May 2025 (p. 1-2, 5, 8-11).
The guide responds to Article 11(11) of the DORA Regulation which mandates the ESAs to harmonize the estimation of aggregated annual costs and losses related to major ICT incidents in financial entities. This topic is crucial to improve the consistency, comparability, and relevance of data reported to competent authorities, while limiting the reporting burden for entities. The main findings are:
- The estimation must cover only incidents classified as major and for which a final report has been submitted, including financial impacts in the reference year even if the incident occurred earlier.
- Entities may choose to base their estimation on the calendar year or fiscal year but must maintain this choice for future reports, with the possibility of change subject to competent authority approval.
- Only gross costs and financial recoveries must be reported; net costs may be calculated by authorities.
- The report must provide detail per incident to justify aggregates.
- These guidelines align with other DORA obligations on incident classification and reporting.
The recommendations aim to ensure a harmonized, reliable, and proportionate estimation of costs and losses, facilitating supervision and ICT risk management in the financial sector (p. 3-4).
The document was developed to address the need to harmonize the estimation of aggregated annual costs and losses related to major ICT incidents, pursuant to Article 11(11) of the DORA regulation. Before these guidelines, estimation methods varied by entity and sector, limiting comparability and usefulness of data for competent authorities. The main objective is to provide a common framework for financial entities, excluding microenterprises, to report consistent and comparable estimates upon request by authorities, to improve the assessment of ICT risk management effectiveness. The scope excludes non-major incidents and focuses on costs and losses related to major incidents classified according to the RTS on incident classification. The document also specifies the modalities for choosing the reference period and data to use, while considering feedback from a public consultation that allowed adjustment of some provisions to reduce reporting burden (p. 5-7, 13-16).
Estimation of costs and losses: Entities must estimate aggregated annual costs and losses by aggregating costs and losses from major ICT incidents over the chosen reference period (calendar or fiscal year). The estimation covers gross costs paid or accounted for, as well as financial recoveries, but not net costs, which will be calculated by authorities (p. 10-11, 17-18).
Choice of reference period: Entities may choose to base their estimation on the calendar year or finalized fiscal year. This choice must be maintained for future reports, except upon notification and approval by the competent authority. This flexibility aims to reduce reporting burden, especially for entities already having an operational risk management framework based on the calendar year (p. 5-7, 20-22).
Inclusion of incidents: Only incidents classified as major according to the RTS on incident classification and for which a final report has been submitted must be included. Prior incidents having a financial impact on the reference year must also be taken into account. This approach ensures consistency with other DORA obligations (p. 10, 21-22).
Granularity and reporting: The report must provide detail of gross costs and recoveries per incident to enable authorities to understand cost distribution and evolution over time. Reporting is done at the financial entity level, in local currency, with accuracy in thousands of units. A template model is annexed (p. 12, 14-15, 17-19, 23-25).
Reporting burden and proportionality: The guidelines aim to limit reporting burden by removing the obligation to report net costs, allowing choice of reference period, and relying on existing data (financial statements, prudential reporting). Proportionality is integrated via the classification of major incidents, which is less frequent for smaller entities, and the exemption of microenterprises (p. 3-4, 5-7, 25).
Public consultation and adjustments: Following 70 responses, the ESAs adjusted the choice of reference period, removed the obligation to report net costs, clarified modalities for adjusting annual reports, and specified granularity and data accuracy requirements. Some proposals, such as time limitation on adjustments or group-level reporting, were rejected to preserve data consistency and usefulness (p. 5-7, 16-26).
Findings:
- The DORA regulatory framework requires the ESAs to define common guidelines for estimating aggregated annual costs and losses related to major ICT incidents (p. 3, 5).
- Financial entities must report upon request by competent authorities, based on incidents classified as major according to a specific RTS (p. 6, 10).
- The reference period can be calendar or fiscal year, at the entity's choice, with obligation of consistency over time (p. 5-7, 20-22).
- Gross costs and financial recoveries must be reported; net costs may be calculated by authorities (p. 3, 6-7, 17).
- Reporting must be detailed per incident to allow fine analysis (p. 12, 14-15).
Assumptions:
- Estimation may rely on validated financial statements or prudential reporting data when available (p. 8, 21-22).
- Adjustments to previous estimates must be included in the report of the year they are made (p. 9, 18).
Interpretations:
- Flexibility on the reference period aims to reduce administrative burden and adapt to existing entity practices (p. 6).
- Removing the obligation to report net costs simplifies reporting without loss of information for authorities (p. 7, 17).
Uncertainties:
- Estimation accuracy may vary depending on entity size and capabilities, but proportionality is ensured by classification of major incidents (p. 25).
- The actual impact of the guidelines on administrative burden remains to be observed after implementation (p. 13-16).
The ESAs conclude that these guidelines effectively harmonize the estimation of aggregated annual costs and losses related to major ICT incidents, ensuring consistency, comparability, and proportionality. They recommend that financial entities:
- Choose and maintain a clear reference period (calendar or fiscal year) for their estimations, with the possibility of change subject to competent authority approval (p. 5-7, 20-22).
- Include in their estimations all major incidents for which a final report has been submitted, as well as financial impacts on the reference period, even if the incident is prior (p. 10, 21-22).
- Report only gross costs and financial recoveries per incident, using the provided template, to facilitate analysis by authorities (p. 12, 17-18).
- Incorporate adjustments to previous estimates in the reports of the year in which they are made (p. 9, 18).
The guide will be applicable from 19 May 2025, with an obligation for competent authorities to notify their compliance within two months following the publication of official translations (p. 4, 8).
Synthesis note written from the full document by DataSAI Academy. This note comes from the scientific library of the DataSAI Academy, open to all.