The Digital Operational Resilience Act (DORA) mandates that financial entities within the EU classify ICT incidents by severity and report major incidents to supervisory authorities. This article delves into the classification criteria, thresholds, and the reporting timeline of 4 hours, 24 hours, and 72 hours, ensuring compliance with DORA's stringent requirements.
The Digital Operational Resilience Act (DORA) mandates that financial entities within the EU classify ICT incidents by severity and report major incidents to supervisory authorities. This article delves into the classification criteria, thresholds, and the reporting timeline of 4 hours, 24 hours, and 72 hours, ensuring compliance with DORA's stringent requirements.
Understanding DORA Incident Classification: Major vs Non-Major Criteria
Under DORA, financial entities must distinguish between major and non-major ICT incidents. The classification is crucial as it determines the reporting obligations and the level of response required. Major incidents are those that significantly disrupt the operations of the financial entity or have a substantial impact on the financial system's stability, market integrity, or consumer protection.
The criteria for determining whether an incident is major include the scale of the impact, the duration of the disruption, the geographical spread, the criticality of the services affected, and the extent of data loss or compromise. Non-major incidents, while still requiring attention, do not meet these thresholds and thus have less stringent reporting requirements.
The 5 Classification Criteria: Clients, Duration, Spread, Data, Criticality
To accurately classify ICT incidents, DORA outlines five key criteria:
Clients Affected
The number of clients affected by an incident is a primary factor in its classification. An incident impacting a significant portion of the client base, particularly those involving sensitive or critical services, is more likely to be deemed major.
Duration of Disruption
The length of time an incident disrupts operations is critical. Prolonged disruptions, especially those exceeding 24 hours, are indicative of major incidents due to their potential to cause significant operational and financial harm.
Geographical Spread
Incidents with a wide geographical impact, affecting multiple regions or countries, are classified as major. The broader the spread, the greater the potential for systemic risk and regulatory concern.
Data Loss or Compromise
The extent of data loss or compromise is a critical factor. Incidents involving significant data breaches, particularly of sensitive or personal data, are likely to be classified as major due to the potential harm to clients and reputational damage.
Criticality of Services
The criticality of the affected services to the financial entity's operations and the financial system as a whole is a determining factor. Incidents impacting core banking functions, payment systems, or other critical infrastructure are typically classified as major.
Reporting Timeline: Initial (4h), Intermediate (24h), Final (1 month)
DORA establishes a structured timeline for reporting major ICT incidents to ensure timely and effective communication with supervisory authorities.
Initial Notification (4 Hours)
Financial entities must notify their supervisory authority within four hours of identifying a major incident. This initial report should include a brief description of the incident, its impact, and any immediate measures taken to mitigate its effects.
Intermediate Report (24 Hours)
Within 24 hours, an intermediate report must be submitted, providing more detailed information on the incident's nature, the affected systems and services, and the steps being taken to resolve the issue. This report should also include an assessment of the potential impact on clients and the financial system.
Final Report (1 Month)
A comprehensive final report is required within one month of the incident's resolution. This report should cover the root cause analysis, the effectiveness of the response measures, lessons learned, and any long-term remediation actions planned to prevent recurrence.
Notification to Supervisory Authorities and Affected Clients
In addition to the structured reporting timeline, DORA requires financial entities to notify both supervisory authorities and affected clients of major incidents.
Supervisory Authorities
Notifications to supervisory authorities must be timely and include all relevant information to enable effective oversight and response coordination. This ensures that authorities can assess the potential systemic impact and take necessary actions to safeguard the financial system.
Affected Clients
Clients affected by major incidents must be informed promptly, particularly if their data has been compromised or if the incident significantly impacts the services they rely on. Clear communication is essential to maintain trust and comply with data protection obligations.
Incident Register Requirements and Data Fields
DORA mandates that financial entities maintain a detailed incident register, documenting all ICT incidents, regardless of their classification. This register serves as a critical tool for internal analysis and regulatory scrutiny.
Required Data Fields
The incident register should include the following data fields:
- Date and time of the incident
- Description of the incident and its impact
- Classification as major or non-major
- Affected systems and services
- Number of clients impacted
- Duration and geographical spread
- Data loss or compromise details
- Response measures and timelines
- Root cause analysis and remediation actions
Maintaining a comprehensive incident register not only aids in compliance but also supports continuous improvement in incident management processes.
Practical Incident Classification Decision Tree
To facilitate the classification process, financial entities can implement a decision tree model. This model guides the assessment of incidents against the five classification criteria, helping to determine whether an incident is major or non-major.
Decision Tree Steps
- 1Assess Client Impact: Determine the number of clients affected and the criticality of the services impacted.
- 2Evaluate Duration: Consider the length of the disruption and its potential to extend beyond 24 hours.
- 3Analyze Geographical Spread: Identify the regions affected and assess the potential for cross-border impact.
- 4Examine Data Compromise: Evaluate the extent and sensitivity of any data loss or breach.
- 5Determine Service Criticality: Assess the importance of the affected services to the entity's operations and the financial system.
By following these steps, financial entities can systematically classify incidents, ensuring compliance with DORA and effective incident management.
Next Step with NexCyber
Ensuring compliance with DORA's ICT incident classification and reporting requirements is crucial for financial entities operating in the EU. NexCyber offers comprehensive solutions to help you assess your current processes and enhance your operational resilience. Visit [NexCyber](https://www.nexcyber.eu/assess?utm_source=editorial&utm_campaign=dora-ict-incident-severity-classification-matrix) to learn more about how we can support your compliance journey.