Home › Academy › Library › Joint Technical Standards on major incident…
Synthesis note · Standard

Joint Technical Standards on major incident reporting

European Banking Authority (EBA) · 2024 · Standard · 128 pages · Intermediate

This final report presents the regulatory and implementing technical standards regarding the reporting of major incidents and significant cyber threats under the DORA regulation. It aims to harmonize the incident reporting regime related to ICT for financial entities in the European Union. The standards establish the content of reports, notification deadlines, and simplify the reporting process to allow financial…

General Information

The document, published in July 2024 by the European Banking Authority (EBA), presents the joint technical standards (RTS and ITS) relating to the content, format, deadlines and procedures for notification and reporting of major incidents and significant cyber threats in the European financial sector. It falls within the scope of Regulation (EU) 2022/2554 on digital operational resilience (DORA) and covers financial entities (banks, insurance, asset managers, etc.) operating in the European Union. The scope includes management, classification and notification of incidents related to information and communication technologies (ICT) over a recent period, with a focus on consistency with the NIS2 directive.

Executive Summary

The document addresses the harmonization and simplification of the notification regime for major ICT incidents and significant cyber threats for financial entities in the EU, in accordance with DORA. The objective is to ensure that competent authorities receive standardized, complete and timely information to act effectively. The main findings are:

- Notification deadlines have been adjusted after public consultation: the initial 4-hour notice for initial notification is maintained but with flexibility up to 24 hours from awareness of the incident; intermediate and final reports benefit from extended deadlines (72 hours and one month respectively) calculated from the previous submission.

- The scope of notifications during weekends and public holidays has been restricted to systemic and critical entities, with a submission deadline postponed to noon of the next working day.

- The content of reports has been simplified: the number of fields in the initial notification form is reduced from 17 to 10, including 7 mandatory, to lighten the burden during incident management.

- A possibility of aggregation of reports at the national level is introduced for entities supervised by the same authority, notably when the incident originates from a common third-party provider.

- Requirements are aligned and at least equivalent to those of the NIS2 directive, ensuring regulatory consistency.

Recommendations concern the rapid implementation of these technical standards, their adoption by the European Commission, and official publication for direct application in Member States.

Context and Objectives

The document responds to the obligation set by Article 20 of DORA, which aims to standardize notification requirements for major ICT incidents and cyber threats in the European financial sector. The issue is the diversity of practices and notification deadlines, which complicate incident management and the taking of measures by authorities. The stakes are operational resilience, prevention of systemic risks and protection of financial service users. The objectives are to define the content of notifications and reports, submission deadlines, as well as standardized forms and procedures. The scope is limited to major incidents and significant threats, with particular attention to proportionality according to the size and profile of entities, while ensuring consistency with the NIS2 directive. The limits concern application to financial entities and consideration of sectoral specificities within a harmonized framework.

Summary of Key Points by Theme

Proportionality and entity specificities:

- Some actors requested differentiated deadlines according to size, sector or service criticality. The ESAs preferred a harmonized framework to avoid complexity, but integrated proportionality by simplifying forms and adapting deadlines (p. 6-7).

Notification and reporting deadlines:

- Initial notification: deadline of 4 hours after classification as major, or at the latest 24 hours after awareness, with reduction of mandatory fields (7 instead of 17) to lighten the burden.

- Intermediate report: extended deadline to 72 hours after initial notification, with obligation for rapid update after activity restoration.

- Final report: deadline of one month after the last intermediate report, removal of the notion of "permanent" resolution for clarity (p. 8-10).

Notification during weekends and public holidays:

- Limitation of obligations to systemic entities, banks, central counterparties and critical entities according to NIS2.

- Submission deadline postponed to noon of the next working day, instead of one hour after start of activity (p. 10-11).

Interconnection with NIS2:

- Requirements are aligned and at least equivalent to those of NIS2, with comparable deadlines and consistency in notification content (p. 11-12).

Form content:

- Overall reduction of 30% of fields (from 84 to 59).

- Initial notification: 10 fields including 7 mandatory, focused on essential information.

- Intermediate and final: adapted fields to provide detailed information as incident management progresses (p. 12-14).

Report aggregation:

- Possibility for a third-party provider or financial group to submit a consolidated report for several entities supervised by the same authority, under strict conditions (incident caused by the third party, individual classification, authority authorization, exclusion of significant entities such as major banks) (p. 13-14).

Technical standards:

- RTS define report content, deadlines and criteria.

- ITS specify forms, procedures, management of recurring incidents, incident reclassification, and notification outsourcing modalities (p. 15-26).

Templates and glossary:

- Annexes detail the fields to be completed, their nature, mandatory status according to report type, and instructions for completion.

- Fields cover general information, incident description, impact, measures taken, costs, etc. (p. 27-44).

Main Results and Lessons Learned

Established facts:

- Adoption of harmonized technical standards for notification of major incidents and cyber threats in the European financial sector.

- Precise deadlines: initial within 4 hours after classification (or 24h after awareness), intermediate within 72 hours after initial notification, final within one month following the last intermediate report.

- Simplification of forms to reduce burden in the initial phase.

- Introduction of a possibility of report aggregation for certain cases.

- Alignment with the NIS2 directive ensuring regulatory consistency.

Hypotheses:

- Proportionality is ensured by form simplification and consideration of sectoral specificities in incident classification.

- Proposed deadlines balance the need for rapid authority reaction and entities’ capacity to collect information.

Interpretations:

- Reduction of fields and extension of deadlines for intermediate and final reports respond to sector actors’ concerns about administrative burden.

- Limitation of notifications during weekends to systemic entities aims to reduce operational costs without compromising supervision.

Uncertainties:

- The real impact of report aggregation on supervision quality and speed remains to be observed.

- Practical application of deadlines in complex or multi-entity incidents may require future adjustments.

Conclusions and Recommendations

The ESAs recommend rapid adoption of the joint technical standards (RTS and ITS) by the European Commission, followed by their publication in the Official Journal of the European Union for direct application. These standards ensure effective harmonization, reduction of administrative burden for financial entities, and better capacity of authorities to manage major incidents and cyber threats. Identified priorities are:

- Implementation of adjusted deadlines for notification and reports.

- Adoption of simplified and standardized forms.

- Establishment of report aggregation mechanisms under control of competent authorities.

- Maintenance of consistency with the NIS2 directive.

No specific deadline is mentioned in the provided pages, but entry into force is planned twenty days after publication in the Official Journal.

Key takeaways

References

Year
2024
Type
Standard
Level
Intermediate
Licence
Attribution required
Original document
https://www.eba.europa.eu/sites/default/files/2024-07/6d341d14-0c54-4…
Read the original document ← Back to the library

Synthesis note written from the full document by DataSAI Academy. This note comes from the scientific library of the DataSAI Academy, open to all.