Translations:Digital Operational Resilienec Act (DORA)/25/en
Aus RI Wiki
Furthermore, financial entities must establish processes to ensure that ICT-related incidents are promptly identified, addressed, classified, and reported. Particularly severe ICT incidents, as defined under Article 18(1) DORA, must be reported to the competent supervisory authorities through a three-stage procedure. In cases where serious ICT incidents affect the financial interests of customers, financial entities must inform their customers immediately upon becoming aware of the incident. Cyber threats deemed significant under Article 18(2) DORA must also be recorded and may be reported voluntarily.