EBA logo

EBA E-mail alert 2 October, 2026

Final Q&As

Question ID: 2026_7779

Topic
ICT-related incidents (management / classification / reporting)
Subject matter
Scope of Article 6 lit. c RTS

Is the criticality of the services affected pursuant to Article 6 (c) RTS to be assumed for every successful, malicious and unauthorised access to the network and information systems of the financial entity, regardless of whether the affected systems support critical or important functions? 

You can edit or cancel your subscription at any time. This is a test version of the newsletter.
Please do not reply to this message. If you have questions, please visit our contact page.
Please refer to EBA’s Legal notice regarding the handling of your personal data.
© European Banking Authority - https://www.eba.europa.eu