EBA logo

EBA E-mail alert December 11, 2024

Final Q&As

Question ID: 2024_7047

Topic
ICT-related incidents (management / classification / reporting)
Subject matter
Critical Services Affected

Article 6 of the Delegated Act on the Classification of Major Incidents states that:

"For the purpose of determining the criticality of the services affected as referred to in Article 18(1), point (e), of Regulation (EU) 2022/2554, financial entities shall assess whether the incident:
(a) affects or has affected ICT services or network and information systems that support critical or important functions of the financial entity;
(b) affects or has affected financial services provided by the financial entity that require authorisation, registration or that are supervised by competent authorities;
(c) constitutes or has constituted a successful, malicious and unauthorised access to the network and information systems of the financial entity."

Can you confirm please that ALL three of the components are cumulatively required to trigger the criteria on Critical Services Affected?

Question ID: 2024_7096

Topic
Oversight framework of CTPPs
Subject matter
Exemption for Non-EU ICT Intra-group Service Providers

Is it accurate to interpret that an ICT intra-group service provider established outside the EU (non-EU country), providing critical services to an EU-based financial institution (parent undertaking), falls within the exemption outlined in Article 31(8) of DORA, thereby exempting the need for establishing a subsidiary within the EU?

Question ID: 2024_7050

Topic
ICT-related incidents (management / classification / reporting)
Subject matter
Duplicate ICT Incident Reporting

Is duplicate incident reporting via the ECB SSM Cyber Incident Reporting Framework required, alongside DORA incident reporting under Article 19?

You can edit or cancel your subscription at any time. This is a test version of the newsletter.
Please do not reply to this message. If you have questions, please visit our contact page.
Please refer to EBA’s Legal notice regarding the handling of your personal data.
© European Banking Authority - https://www.eba.europa.eu