two new circulars: ICT-related incident classification and reporting for DORA entities and other Payment Service Providers and adoption
ESA Guidelines on the estimation
aggregated costs/losses The CSSF is hereby informing all supervised entities
updates concerning the provision
the ICT-related incident classification and reporting, following the entry into application
the DORA regulation. It must be noted that the updates not only concern entities falling under the scope
the DORA regulation and supervised by the CSSF1 (“DORA entities”), but also concern Payment Service Providers not under the scope
DORA. ICT-related incident classification and reporting: updates and issuance
one new circular The CSSF issued today new Circular CSSF 25/893 providing the practical modalities to be followed by DORA entities when reporting major ICT-related incidents and significant cyber threats to the CSSF. In addition, in order to apply the same incident classification and reporting framework to all Payment Service Providers (PSPs) under the Law
10 November 2009 on Payment Services (LPS), the CSSF has decided that PSPs who are not under the scope
DORA shall also fulfil their obligation in this domain (as per Article 105-2
LPS) by following the ICT-related incident and cyber threat classification and reporting procedures foreseen under DORA. PSPs not under the scope
DORA are therefore also under the scope
new Circular CSSF 25/893 and, to avoid a dual-reporting scheme, shall apply the DORA requirements for all ICT-related incidents (and not only the incidents related to payment services). A six-month transition period is granted, as further specified in the circular. For the time being, Circular CSSF 24/847 cannot be modified until Directive (EU) 2022/2555
14 December 2022 on measures for a high common level
cybersecurity across the Union (NIS 2 Directive) is transposed at national level, as it also covers the reporting requirements under NIS 1 law. However, while the scope
Circular CSSF 24/847 has not been modified and as specified in new circular CSSF 25/893, DORA entities and PSPs not under the scope
DORA are no longer subject to Circular CSSF 24/847 (without prejudice to the transition period mention above for PSPs not under the scope
DORA). For all other entities, Circular CSSF 24/847 continues to apply. The approach taken by the CSSF is depicted below: 28 May 2025 Circular CSSF 25/893 on reporting
major ICT-related incidents and significant cyber threats under the Digital Operational Resilience Act (DORA) CSSF circular PDF (207.99Kb) PDF (148.31Kb) 5 January 2024 Circular CSSF 24/847 on ICT-related incident reporting framework Communiqué
5 January 2024 CSSF circular PDF (300.89Kb) PDF (213.33Kb) New CSSF circular on the adoption
ESAs guidelines on the estimation
aggregated costs/losses caused by major ICT-related incidents The CSSF publishes today Circular CSSF 25/892 on the application
the Joint ESA Guidelines on the estimation
aggregated annual costs and losses caused by major ICT-related incidents under Regulation (EU) 2022/2554 (JC 2024 34). This circular applies to all DORA entities, other than microenterprises as defined in Article 3
DORA. 28 May 2025 Circular CSSF 25/892 Application
the Joint ESA Guidelines on the estimation
aggregated annual costs and losses caused by major ICT-related incidents under Regulation (EU) 2022/2554 (JC 2024 34) CSSF circular PDF (413.26Kb) PDF (591.29Kb) For any further questions please contact: ictrisksupervision@cssf.lu. 1 financial entities defined in Article 2
Regulation (EU) 2022/2554 on digital operational resilience for the financial sector Relevant for Central Securities Depositories (CSDs) Credit institutions Crowdfunding service providers Crypto-Assets Service Providers (CASPs) Data Reporting Service Providers (DRSPs) Investment firms Investment fund managers Issuers
Tokens Payment institutions/electronic money institutions/AISPs Pension fund Circulaire CSSF 25/893 sur la notification des incidents majeurs liés aux TIC et des cybermenaces importantes en vertu du règlement sur la résilience opérationnelle numérique (DORA) En cas de divergences entre les textes français et anglais, le texte anglais prévaut. Circulaire CSSF 25/893 sur la notification des incidents majeurs liés aux TIC et des cybermenaces importantes en vertu du règlement sur la résilience opérationnelle numérique (DORA) À toutes les entités financières telles que définies à l’article 2, paragraphe 1, points
frent ou rendent accessibles ;
major ICTrelated incidents and significant cyber threats under the Digital Operational Resilience Act (DORA) Circular CSSF 25/893 on reporting
major ICT-related incidents and significant cyber threats under the Digital Operational Resilience Act (DORA) To all financial entities defined in Article 2
Regulation (EU) 2022/2554 1 on digital operational resilience for the financial sector (hereafter “DORA”) and to all Payment Service Providers as referred to in Article 1
the Law
10 November 2009 on payment services (LPS). Luxembourg, 27 May 2025 Ladies and Gentlemen, As defined in Articles 18
DORA, financial entities subject to DORA are required to comply with the obligations for classifying and reporting major ICT-related incidents and, if applicable, significant cyber threats. The specifics regarding classification and reporting are detailed in the following Regulatory Technical Standards (RTS) and Implementing Technical Standards (ITS): • RTS on classification
ICT-related incidents and cyber threats 2 (hereafter “RTS on classification”), and • RTS and ITS on incident and voluntary cyber threats reporting (hereafter “RTS on incident reporting” 3 and “ITS on incident reporting” 4) Furthermore, with this circular the CSSF requires Payment Service Providers (PSPs) that are not in the scope
DORA to follow the ICT-related incident and cyber threat classification and reporting procedures under DORA in order to fulfil the reporting requirements stipulated under Article 105-2
the LPS. As a simplification, these PSPs shall follow the DORA requirements for all ICT-related incidents (i.e. including ICT-related incident not related to payment services), so as to avoid a dual reporting scheme. In this context, this circular also provides the practical modalities according to which financial entities in scope
this circular are required to notify the major ICT-related incidents as well as, if applicable, significant cyber threats to the CSSF. 1 Regulation (EU) 2022/2554
the European Parliament and
the Council
14 December 2022 on digital operational resilience for the financial sector and amending Regulations (EC) No 1060/2009, (EU) No 648/2012, (EU) No 600/2014, (EU) No 909/2014 and (EU) 2016/1011 2 Commission Delegated Regulation (EU) 2024/1772
13 March 2024 supplementing Regulation (EU) 2022/2554
the European Parliament and
the Council with regard to regulatory technical standards specifying the criteria for the classification
ICT-related incidents and cyber threats, setting out materiality thresholds and specifying the details
reports
major incidents 3 Commission Delegated Regulation (EU) 2025/301
23 October 2024 supplementing Regulation (EU) 2022/2554
the European Parliament and
the Council with regard to regulatory technical standards specifying the content and time limits for the initial notification
, and intermediate and final report on, major ICT-related incidents, and the content
the voluntary notification for significant cyber threats 4 Commission Implementing Regulation (EU) 2025/302
23 October 2024 laying down implementing technical standards for the application
Regulation (EU) 2022/2554
the European Parliament and
the Council with regard to the standard forms, templates, and procedures for financial entities to report a major ICT-related incident and to notify a significant cyber threat CIRCULAR CSSF 25/893 2/8 This circular is divided into four chapters: • Chapter 1 defines the scope
application; • Chapter 2 lists the requirements on classification and reporting
incident and cyber threats for PSPs not under DORA; • Chapter 3 defines the practical modalities for the reporting
major ICT-related incidents and significant cyber threats; • Chapter 4 provides for the entry into force
this circular. CIRCULAR CSSF 25/893 3/8 TABLE
CONTENTS Chapter 1: Scope
application ...................................................................................... 5 Chapter 2: Requirements on classification and reporting
incident and cyber threats for PSPs not under DORA.................................................................................................................. 6 Chapter 3: Practical modalities for major ICT-related incident notification and significant cyber threats reporting ................................................................................................................. 7 Chapter 4: Date
application ........................................................................................ 8 CIRCULAR CSSF 25/893 4/8 Chapter 1: Scope
application 1. The following entities are to be considered as financial entities in the framework
this circular: a) credit institutions, investment firms, market operators operating a trading venue and approved publication arrangements (APAs) with a derogation and authorised reporting mechanisms (ARMs) with a derogation within the meaning
the Law
5 April 1993 on the financial sector (LFS); b) payment institutions, account information service providers and electronic money institutions within the meaning
the Law
10 November 2009 on payment services (LPS); c) crypto asset service providers and issuers
asset-referenced tokens within the meaning
Regulation (EU) 2023/1114; d) central securities depositories within the meaning
the Law
6 June 2018 on central securities depositories (CSD Law); e) central counterparties within the meaning
the Law
15 March 2016 on OTC derivatives, central counterparties and trade repositories; f) management companies incorporated under Luxembourg law and subject to Chapter 15 or Article 125-2
, and Luxembourg branches
investment fund managers subject to Chapter 17, and investment companies which did not designate a management company within the meaning
the Law
17 December 2010 relating to undertakings for collective investment; g) alternative investment fund managers authorised under Chapter 2 and internally managed alternative investment funds within the meaning
point (b)
the Law
12 July 2013 on alternative investment fund managers (AIFM Law); h) institutions for occupational retirement provisions authorised in accordance with Article 2
the Law
13 July 2005 on institutions for occupational retirement provision in the form
pension savings companies with variable capital (SEPCAVs) and pension savings associations (ASSEPs); i) administrators
critical benchmarks within the meaning
point (b)
Regulation (EU) 2016/1011; j) crowdfunding service providers within the meaning
the Law
16 July 2019 on the operationalisation
European regulations in the area
financial services; k) Payment Service Providers (PSPs) as referred to in Article 1
the Law
10 November 2009 on payment services (LPS) that are not financial entities as defined in point 1 (a) and (b) above, i.e. branches in Luxembourg
PSPs incorporated in a third country, and POST Luxembourg. 2. The provisions
this circular are only applicable to entities in scope as defined in point (k) above, hereafter collectively referred to as “PSPs not under DORA”. 3. The provisions
this circular are applicable to all financial entities in scope as defined in point 1 (
the Financial Entities that are part
a legal entity whose head
fice is located in a different Member State
the European Union (EU branches) are expected to report their major ICT-related incidents and significant cyber threats under DORA to the competent authority
that Member State (home Member State) and are therefore excluded from the scope
this circular. Chapter 2: Requirements on classification and reporting
incident and cyber threats for PSPs not under DORA 5. For the purpose
this circular, the following definitions are derived from the DORA regulation and apply for PSPs not under DORA: a) ‘network and information system’ means:
signals by wire, radio, optical or other electromagnetic means, including satellite networks, fixed (circuit- and packet-switched, including internet) and mobile networks, electricity cable systems, to the extent that they are used for the purpose
transmitting signals, networks used for radio and television broadcasting, and cable television networks, irrespective
the type
information conveyed;
interconnected or related devices, one or more
which, pursuant to a programme, carry out automatic processing
digital data; or
their operation, use, protection and maintenance; b) ‘security
network and information systems’ means the ability
network and information systems to resist, at a given level
confidence, any event that may compromise the availability, authenticity, integrity or confidentiality
stored, transmitted or processed data or
the services
fered by, or accessible via, those network and information systems; c) ‘operational or security payment-related incident’ means a single event or a series
linked events unplanned by the financial entities, whether ICT-related or not, that has an adverse impact on the availability, authenticity, integrity or confidentiality
payment-related data, or on the payment-related services provided by the financial entity; d) ‘ICT-related incident’ means a single event or a series
linked events unplanned by the financial entity that compromises the security
the network and information systems, and have an adverse impact on the availability, authenticity, integrity or confidentiality
data, or on the services provided by the financial entity. This includes operational or security payment-related incidents;
the financial entity. This includes major operational or security paymentrelated incidents; g) ‘cyber threat’ means any potential circumstance, event or action that could damage, disrupt or otherwise adversely impact network and information systems, the users
such systems and other persons; h) ‘significant cyber threat’ means a cyber threat the technical characteristics
which indicate that it could have the potential to result in a major ICT-related incident or a major operational or security payment-related incident; i) ‘critical or important function’ means a function, the disruption
which would materially impair the financial performance
a financial entity, or the soundness or continuity
its services and activities, or the discontinued, defective or failed performance
that function would materially impair the continuing compliance
a financial entity with the conditions and obligations
its authorisation, or with its other obligations under applicable financial services law. 6. PSPs not under DORA are required to classify their ICT-related incidents and their cyber threats according to the criteria and materiality thresholds as defined in Chapters I, II and III
the RTS on classification. Chapters IV and V
the RTS on classification are not applicable to them.
the RTS on incident reporting. 10. Financial entities shall complete the relevant section(s)
the notification form, depending on the phase they are in. The first section refers to the initial notification as per Article 2
the RTS on incident reporting, the second section refers to the intermediate report as per Article 3
the RTS on incident reporting and the third section refers to the final report as per Article 4
the RTS on incident reporting. The notification form contains the data fields laid down in Annexes II and IV
the ITS on incident reporting. 11. Article 7
the ITS on incident reporting indicates that aggregated reporting is only possible if competent authorities have explicitly given the permission. In this regard, the CSSF informs financial entities that, after having carefully evaluated all
the conditions from points (a) to (d)
the ITS on incident reporting, no aggregated report is permitted when it comes to major ICT-related incident notifications. CIRCULAR CSSF 25/893 7/8 12. Financial entities that have outsourced the reporting obligations remain fully responsible for the fulfilment
incident reporting requirements within the applicable timeline and for the whole content
the notification forms. As specified in Article 6
the ITS on incident reporting, financial entities shall inform the CSSF as soon as possible
outsourcing
reporting obligations and at the latest prior to the first notification. In this regard, the following details must be provided to the CSSF (email address: ictrisksupervision@cssf.lu): a) Name, contact details and an identification code
the third party that will submit the notifications on behalf
the financial entity; b) Name, contact details and the related function
the persons at the third party to whom the related incident notification role will be assigned in the CSSF digital solution. Chapter 4: Date
application 13. For entities listed under points 1(
the EBA Guidelines (EBA/GL/2021/03) on major incident reporting under PSD2 is no longer applicable to them. 14. For entities listed under point 1(k):
the EBA Guidelines (EBA/GL/2021/03) on major incident reporting under PSD2 remain applicable to them. 15. Six months after the publication date
this circular, Circular CSSF 21/787 on application
the EBA Guidelines (EBA/GL/2021/03) on major incident reporting under PSD2 will be repealed. Claude WAMPACH Director Françoise KAUTHEN Director CIRCULAR CSSF 25/893 Marco ZWICK Director Jean-Pierre FABER Director Claude MARX Director General 8/8 Circulaire CSSF 24/847 sur le cadre de notification des incidents liés aux TIC CIRCULAIRE CSSF 24/847 En cas de divergences entre les textes français et anglais, le texte anglais prévaut. Circulaire CSSF 24/847 sur le cadre de notification des incidents liés aux TIC À toutes les Entités Surveillées au sens des lois modifiées et des règlements suivants, tels que précisés au point 2 : - la loi du 5 avril 1993 sur le secteur financier - la loi du 15 décembre 2000 sur les services financiers postaux - la loi du 10 novembre 2009 relative aux services de paiement - la loi du 17 décembre 2010 concernant les organismes de placement collectif - la loi du 12 juillet 2013 relative aux gestionnaires de fonds d’investissement alternatifs - la loi du 15 mars 2016 relative aux produits dérivés de gré à gré, aux contreparties centrales et aux référentiels centraux - la loi du 17 avril 2018 relative aux indices de référence - la loi du 6 juin 2018 relative aux dépositaires centraux de titres - la loi du 28 mai 2019 relative aux réseaux et aux systèmes d’information - la loi du 16 juillet 2019 relative à l’opérationnalisation de règlements européens dans le domaine des services financiers Luxembourg, le 5 janvier 2024 Mesdames, Messieurs, La présente circulaire vise à introduire un nouveau cadre de notification des incidents liés aux TIC en vue d’obtenir une meilleure vue d’ensemble plus structurée de la nature, de la fréquence, de l’importance et des conséquences des incidents liés aux TIC, en prenant également en compte le risque croissant lié aux TIC et à la sécurité dans le contexte d’un système financier mondial fortement interconnecté. Les dispositions de la présente circulaire se fondent sur l’article 53, paragraphe 1, de la loi modifiée du 5 avril 1993 relative au secteur financier (ci-après la « LSF »), l’article 31, paragraphe 4, de la loi modifiée du 10 novembre 2009 relative aux services de paiement (ci-après la « LSP »), l’article 2 de la loi modifiée du 15 décembre 2000 sur les services financiers postaux, l’article 147 de la loi modifiée du 17 décembre 2010 concernant les organismes de placement collectif (ci-après la « Loi OPCVM »), l’article 50 de la loi modifiée du 12 juillet 2013 relative aux gestionnaires de fonds d'investissement alternatifs (ci-après la « Loi GFIA »), l’article 2, paragraphe 1, de la loi modifiée du 15 mars 2016 relative aux produits dérivés de gré à gré, aux contreparties centrales et aux référentiels centraux (ci-après la « Loi EMIR »), l’article 2, paragraphe 1, de la loi du 17 avril 2018 relative aux indices de référence (ci-après la « Loi relative aux indices de référence »), l’article 2 de la loi du 6 juin 2018 relative aux dépositaires centraux de titres (ci-après la « Loi DCT »), et l’article 20-16 de la loi du 16 juillet 2019 relative à l’opérationnalisation de règlements européens dans le domaine des services financiers. Conformément à l’article 3 de la loi du 28 mai 2019 relative aux réseaux et aux systèmes d’information (ci-après la « Loi SRI »), la CSSF est également l’autorité compétente en termes de sécurité des réseaux et de l’information pour les établissements de crédit et les infrastructures des marchés financiers qui ont été identifiés en tant qu’opérateurs de services essentiels (ci-après les CIRCULAIRE CSSF 24/847 « OSE »), ainsi que pour les fournisseurs de services numériques (ci-après les « FSN ») qui sont déjà soumis à la surveillance de la CSSF (ci-après l’« autorité SRI »). L’objectif de la présente circulaire est de fixer les détails et modalités pratiques en matière d’obligations de notification prévues à l’article 8, paragraphes 4 et 5, à l’article 9, paragraphe 1, à l’article 11, paragraphes 3 et 4, et à l’article 12 de la Loi SRI et au règlement CSSF N° 24-01 relatif à la notification des incidents selon la loi du 28 mai 2019 1 (ci-après le « Règlement CSSF N° 24-01 ») notamment en ce qui concerne l’article 8, paragraphe 5, et l’article 11, paragraphe 3, de la Loi SRI. La présente circulaire apporte les modifications suivantes au mécanisme actuel de notification des incidents : • élargissement de la couverture des incidents qui est actuellement limitée à la fraude et aux incidents dus à des attaques informatiques externes conformément à la circulaire CSSF 11/504, en couvrant plus largement les incidents opérationnels et de sécurité liés aux TIC tout en évitant la double notification pour les incidents à notifier en vertu d’autres cadres de notification des incidents ; • introduction de notifications reposant sur la classification. Les Entités Surveillées seront tenues de classifier les incidents liés aux TIC sur base des critères énoncés dans la présente circulaire et de notifier à la CSSF les cas d’incidents liés aux TIC qui sont classifiés en tant qu’incidents majeurs ou significatifs ; • introduction d’un nouveau formulaire de notification d’incidents. Afin d’obtenir les données de manière structurée, les Entités Surveillées seront tenues de compléter et de soumettre un formulaire de notification d’incidents liés aux TIC au cas où l’incident lié aux TIC est classifié en tant qu’incident majeur ou significatif ; • introduction d’un chapitre spécifique pour couvrir dans la même circulaire les exigences en matière de notification d’incidents (précédemment communiqué de manière bilatérale aux Entités Surveillées qui tombent sous le champ d’application de la Loi SRI) en vue d’appliquer le nouveau formulaire de notification d’incidents et les exigences pratiques aux notifications d’incidents évalués comme significatifs en vertu de la Loi SRI. La présente circulaire est divisée en quatre chapitres : • Le chapitre 1 (Définitions et champ d’application) fixe les définitions applicables aux fins de la présente circulaire et établit le champ d’application ; • Le chapitre 2 (Exigences générales) établit les exigences pour la classification et les notifications d’incidents liés aux TIC ; • Le chapitre 3 (Exigences spécifiques en vertu de la Loi SRI et du Règlement CSSF N° 24-01) est dédié aux exigences spécifiques pour les Entités Surveillées qui sont soumises à la Loi SRI et au Règlement CSSF N° 24-01 et qui sont définies comme OSE ou FSN ; • Le chapitre 4 (Date d’application) prévoit l’entrée en vigueur de la présente circulaire. Règlement CSSF N° 24-01 du 5 janvier 2024 relatif à la notification des incidents selon la loi du 28 mai 2019 portant transposition de la directive (UE) 2016/1148 du Parlement européen et du Conseil du 6 juillet 2016 concernant des mesures destinées à assurer un niveau élevé commun de sécurité des réseaux et des systèmes d’information dans l’Union européenne. 1 CIRCULAIRE CSSF 24/847 TABLE DES MATIÈRES Chapitre 1 : Définitions et champ d’application ....................................................................... 5 Section 1.1 : Définitions .................................................................................................... 5 Section 1.2 : Champ d’application ...................................................................................... 7 Chapitre 2 : Exigences générales .......................................................................................... 8 Section 2.1 : Incidents à notifier ........................................................................................ 8 Section 2.2 : Classification des incidents liés aux TIC ............................................................ 9 Section 2.3 : Notification d’incidents majeurs liés aux TIC ..................................................... 9 Chapitre 3 : Exigences spécifiques en vertu de la Loi SRI et du Règlement CSSF N° 24-01 ......... 11 Section 3.1 : Notifications d’incidents par les Entités Surveillées qui sont également des OSE .. 11 Section 3.2 : Notifications d’incidents par les Entités Surveillées qui sont également des FSN .. 11 Chapitre 4 : Date d’application ........................................................................................... 12 CIRCULAIRE CSSF 24/847 Chapitre 1 : Définitions et champ d’application Section 1.1 : Définitions 1. Aux fins de la présente circulaire, on entend par 2: a) « Réseaux et systèmes d’information » : i. un réseau de communications électroniques au sens de l’article 2, point 1°, de la loi du 17 décembre 2021 sur les réseaux et les services de communications électroniques 3 ; ii. tout dispositif ou tout ensemble de dispositifs interconnectés ou apparentés, dont un ou plusieurs éléments assurent, en exécution d’un programme, un traitement automatisé de données numériques ; ou iii. les données numériques stockées, traitées, récupérées ou transmises par les éléments visés aux points i. et ii. ci-dessus en vue de leur fonctionnement, utilisation, protection et maintenance. b) « Sécurité des réseaux et des systèmes d’information » : la capacité des réseaux et des systèmes d’information de résister, à un niveau de confiance donné, à des actions qui compromettent la disponibilité, l’authenticité, l’intégrité ou la confidentialité des données stockées ou transmises ou faisant l’objet d’un traitement, ou des services que ces réseaux et systèmes d’information
frent ou rendent accessibles.
frent dans l’Union européenne. On considère que la notion de « sans retard injustifié » est considérée comme respectée lorsque les Entités Surveillées soumettent leur notification d’incident conformément aux délais indiqués à la section 2.3 (Notification d’incidents majeurs liés aux TIC) et à l’annexe I. 26. Les Entités Surveillées qui sont également des FSN doivent :
detection
the incident yyyy-mm-dd hh:mm 5. Date and time
classification
the incident as major List
world countries yyyy-mm-dd hh:mm Choice (multiple) - Select all that apply • • • • • • 6. Criteria triggering the major ICT-related incident report • • CIRCULAIRE CSSF 24/847 Clients or financial counterparts affected Transactions affected Reputational impact Service downtime Geographical spread Data losses entailed in relation to availability, authenticity, integrity or confidentiality Criticality
the services affected Economic impact 15/24 Data Field description / Question Field type Proposed options Choice (multiple) – Select • • • • • • • • one option 7. The incident was detected by 7.1. If "Other", specify Alphanumeric 8. General description
the incident Alphanumeric IT security Staff member Internal audit Consumer / payment service user External auditor Third party provider Attacker / warning Other Provide a general description
the incident, its immediate impact and including the measures that have been taken so far 9. Short description
impact in other EU member states Alphanumeric
this notification?
the incident, Alphanumeric Proposed options Provide a detailed description
the incident, including (if known and/or applicable): - How the incident started - Background and incident detection, who was involved, what happened, how did it evolve? - Cause
the incident
beginning
the incident - if known hh:mm Choice (multiple) – Select one option 5. Who is leading the investigation
the incident?
the main options. Then, as applicable, select the subcategories CIRCULAIRE CSSF 24/847 Choice (multiple) Select all that apply • • • • • Group Supervised entity Service provider Security company Other • • • • • Under investigation Malware Social engineering Insider/Third Party Provider Threat Intrusion/Unauthorised access 17/24 Data Field description / Question 6.1.1. If "Other", specify Field type • • • • Denial
service System/Process failure Human error Other • Malware o Ransomware o Trojan horse o Virus/Worm/Spyware o Other (Malware) Social engineering o Phishing/*ishing o Other (Social engineering) Insider/Third Party Provider Threat o Accidental data leakage/corruption o Intentional misuse
access rights by insider o Intentional misuse
access rights by service provider o Other (Insider/Third Party Provider Threat) Intrusion/Unauthorised access o Brute force attack o Malicious script injection and/or OS commanding o Unauthorized use
resources, copyright o Account/application compromise o Other exploited vulnerability o Other (Intrusion/Unauthorised access) Denial
service System/Process failure o Hardware failure o Software/application failure o Network failure o Database/Storage failure o Physical damage o Other (System/Process failure) Alphanumeric Choice (multiple) - 6.
internal users impacted Numeric Choice (multiple) – Actual or estimated Select one option 8.1.
customers impacted Numeric Choice (multiple) – Actual or estimated Select one option 8.2.
internal procedures and documentation Improper operations Latency issues Recovery issues Lack
staff awareness and/or compliance Unauthorised software/wrong version Inadequate privileged account management Inadequate email/web browser protection Inadequate malware defences Inadequate identity access management Inadequate security configurations for secure hardware and software on devices, laptops, workstations, servers Inadequate boundary defences Inadequate control
network ports, protocols and services Inadequate resilience and/or back-up
systems or files Unsecured network devices (firewalls, routers, switches) Inadequate maintenance and monitoring
logs Inadequate DDoS defences Inadequate penetration and security testing Inadequate patch management Inadequate application software security controls (webbased and other applications) Other 22/24 Data Field description / Question Field type 2.
the incident? (select all that apply) Choice (multiple) – • • • • • • • • • • • Website Instant messaging Phone Insider attack (privileged user) E-mail Third party network Unauthorised devices Insider attack (regular / business users) Lost / stolen devices Chat rooms / social media Other – • • • • • Group Supervised entity Service provider Security company Other – • • • Police Other None Select all that apply 4.
the effectiveness
the action taken Choice 9.
the incident? Choice 10.1. Provide the date and time when then incident was closed yyyy-mm-dd hh:mm (multiple) Proposed options – • • • • Highly effective Moderately effective Not effective Not yet available – • • • • Resolved Contained Ongoing Unknown Select one option (multiple) Select one option or is expected to be closed if known CIRCULAIRE CSSF 24/847 24/24 Circular CSSF 24/847 ICT-related incident reporting framework CIRCULAR CSSF 24/847 Circular CSSF 24/847 ICT-related incident reporting framework To all Supervised Entities within the meaning
the following laws, as amended, and regulations as further specified in point 2: - Law
5 April 1993 on the financial sector - Law
15 December 2000 on postal financial services - Law
10 November 2009 on payment services - Law
17 December 2010 relating to undertakings for collective investment - Law
12 July 2013 on alternative investment fund managers - Law
15 March 2016 on OTC derivatives, central counterparties and trade repositories - Law
17 April 2018 on benchmarks - Law
6 June 2018 on Central Securities Depositories - Law
28 May 2019 on Network and Information Systems - Law
16 July 2019 on the operationalisation
European regulations in the area
financial services Luxembourg, 5 January 2024 Ladies and Gentlemen, The purpose
this Circular is to introduce a new ICT-related incident reporting framework in order to acquire a better and more structured overview
the nature, frequency, significance and impact
ICT-related incidents, also considering the growing ICT and security risk in the context
a highly interconnected global financial system. The provisions
this Circular are based on Article 53
the Law
5 April 1993 on the financial sector, as amended (hereafter “LFS”), Article 31
the Law
10 November 2009 on payment services, as amended (hereafter “LPS”), Article 2
the Law
15 December 2000 on postal financial services, as amended, Article 147
the Law
17 December 2010 relating to undertakings for collective investment, as amended (hereafter “UCITS Law”), Article 50
the Law
12 July 2013 on alternative investment fund managers, as amended (hereafter “AIFM Law”), Article 2
the Law
15 March 2016 on OTC derivatives, central counterparties and trade repositories, as amended (hereafter “EMIR Law”), Article 2
the Law
17 April 2018 on benchmarks (hereafter “Benchmark Law”), Article 2
the Law
6 June 2018 on Central Securities Depositories (hereafter “CSD Law”), and Article 20-16
the Law
16 July 2019 on the operationalisation
European regulations in the area
financial services. According to Article 3
the Law
28 May 2019 on Network and Information Systems (hereafter “NIS Law”), the CSSF is also the competent authority in terms
network and information security for the credit institutions and the financial market infrastructures that have been identified as Operators
Essential Services (hereafter “OES”), as well as for Digital Service Providers (hereafter “DSP”) which are already under the supervision
the CSSF (“NIS authority”). The objective
this circular is to lay down the practical details and modalities for the reporting obligations set forth in Articles 8
the NIS Law and in CSSF Regulation No 24-01 CIRCULAR CSSF 24/847 2/24 relating to the notification
incidents according to the Law
28 May 2019 1 (hereafter “CSSF Regulation No 24-01”) regarding specifically Articles 8
the NIS Law. This Circular brings the following changes to the current incident reporting mechanism: • Increases the incident coverage, currently limited to fraud and incidents due to external computer attacks as per Circular CSSF 11/504, by covering more broadly ICT operational and security incidents while avoiding double reporting for incidents to be notified under other incident notification frameworks. • Introduces reporting based on classification. Supervised Entities will be required to classify ICTrelated incidents based on the criteria indicated in this Circular and to notify to the CSSF the cases where ICT-related incidents are classified as major or significant incidents. • Introduces a new incident reporting notification form. To obtain data in a structured form, Supervised Entities will be required to complete and submit an ICT-related incident notification form in case the ICT-related incident is classified as a major or significant incident. • Introduces a specific chapter to cover in the same Circular the incident notification requirements (previously communicated via bilateral communications to Supervised Entities that are under the scope
the NIS Law) in order to apply the new incident reporting notification forms and practical requirements to the notifications
incidents assessed as significant under the NIS Law. This Circular is divided in four chapters: • Chapter 1 (Definitions and scope
application) sets out the definitions applicable for the purpose
this Circular and defines the scope
application; • Chapter 2 (General requirements) sets out the requirements for the classification and reporting
the ICT-related incidents; • Chapter 3 (Specific requirements under the NIS Law and CSSF Regulation No 24-01) is dedicated to specific requirements for those Supervised Entities that are subject to the NIS Law and CSSF Regulation No 24-01 and that are defined as OES or DSP; • Chapter 4 (Date
application) provides for the entry into force
this Circular. 1 CSSF Regulation No 24-01
5 January 2024 relating to the notification
incidents according to the Law
28 May 2019 transposing Directive (EU) 2016/1148
the European Parliament and
the Council
6 July 2016 concerning measures for a high common level
security
network and information systems across the European Union. CIRCULAR CSSF 24/847 3/24 TABLE
CONTENTS Chapter 1: Definitions and scope
application ................................................................. 5 Section 1.1: Definitions ............................................................................................... 5 Section 1.2: Scope
application .................................................................................. 7 Chapter 2: General requirements .................................................................................... 9 Section 2.1: Incidents to be notified .............................................................................. 9 Section 2.2: ICT-related incident classification................................................................ 9 Section 2.3: Major ICT-related incident notification ....................................................... 10 Chapter 3: Specific requirements under NIS Law and CSSF Regulation No 24-01 ................ 11 Section 3.1: Incident notification by Supervised Entities who are also OES ....................... 11 Section 3.2: Incident notification by Supervised Entities who are also DSP ....................... 11 Chapter 4: Date
application ...................................................................................... 12 CIRCULAR CSSF 24/847 4/24 Chapter 1: Definitions and scope
application Section 1.1: Definitions 1. For the purpose
this Circular, the following definitions apply 2: a) “Network and information system” means: i. an electronic communications network within the meaning
, paragraph 1,
the Law
17 December 2021 on electronic communications networks and services 3; ii. any device or group
interconnected or related devices, one or more
which, iii. digital data stored, processed, retrieved or transmitted by elements covered under pursuant to a program, perform automatic processing
digital data; or points i. and ii. above for the purposes
their operation, use, protection and maintenance. b) “Security
network and information systems” means the ability
network and information systems to resist, at a given level
confidence, any action that compromises the availability, authenticity, integrity or confidentiality
stored or transmitted or processed data or the related services
fered by, or accessible via, those network and information systems. c) “ICT-related incident” means a single event or a series
linked events unplanned by the Supervised Entity that compromises the security
the network and information systems, and has an adverse impact on the availability, authenticity, integrity or confidentiality
data, or on the services provided by the Supervised Entity. d) “Major ICT-related incident” means an ICT-related incident that has a high adverse impact on the network and information systems that support critical or important functions
the Supervised Entity. e) “Critical or important function” means a function, the disruption
which would materially impair the financial performance
a Supervised Entity, or the soundness or continuity
its services and activities, or the discontinued, defective or failed performance
that function would materially impair the continuing compliance
a Supervised Entity with the conditions and obligations
its authorisation, or with its other obligations under applicable financial services laws. f) “Operator
Essential Services” (“OES”) means, in accordance with point
the NIS Law, a public or private entity
a type referred to in the annex to the NIS Law, and which meets the criteria laid down in Article 7
the NIS law 4. Definitions in points 1.
the NIS Law and CSSF Regulation No 24-01. 2 3 ‘Electronic communications network’ means transmission systems, whether or not based on a permanent infrastructure or centralised administration capacity, and, where applicable, switching or routing equipment and other resources, including network elements which are not active, which permit the conveyance
signals by wire, radio, optical or other electromagnetic means, including satellite networks, fixed (circuit- and packetswitched, including internet) and mobile networks, electricity cable systems, to the extent that they are used for the purpose
transmitting signals, networks used for radio and television broadcasting, and cable television networks, irrespective
the type
information conveyed. 4 In its competence as NIS authority, the CSSF already notified the relevant Supervised Entities
their identification as OES when the NIS Law entered into force. The CSSF will reconfirm the relevant Supervised Entities
their status as OES at the latest by 1 March 2024. The Supervised Entities which will not receive this notification at that date are therefore not designated as OES, without prejudice to potential future designation. CIRCULAR CSSF 24/847 5/24 g) “Digital Service Provider” (“DSP”) means, in accordance with point
the NIS Law, a private entity that provides a digital service as defined in point
the NIS Law 5. h) “Essential service” means a service which is essential for the maintenance
critical societal and/or economic activities and which is listed as essential service in Article 2
6 CSSF Regulation No 20-04
15 July 2020 . i) “Significant incident” means an incident having a significant impact on the continuity
the essential services provided by an OES or on the provision
a digital service provided 7 by a DSP within the European Union. For the purpose
this Circular, a significant incident is by default considered as a “Major ICT-related incident”. 2. The following entities are to be considered as Supervised Entities in the frame
this Circular: a) credit institutions and professionals
the financial sector within the meaning
the LFS; b) approved publication arrangements (APAs) with a derogation and authorised reporting mechanisms (ARMs) with a derogation within the meaning
the LFS; c) payment institutions and electronic money institutions within the meaning
the LPS; d) POST Luxembourg governed by the Law
15 December 2000 on postal financial services 8; e) management companies incorporated under Luxembourg law and subject to Chapter 15
the UCITS Law; f) management companies incorporated under Luxembourg law and subject to Articles 1251 or 125-2
the UCITS 2010 Law; g) Luxembourg branches
IFMs subject to Chapter 17
the UCITS Law; h) investment companies which did not designate a management company within the meaning
the UCITS Law; i) alternative investment fund managers authorised under Chapter 2
the AIFM Law; j) internally managed alternative investment funds within the meaning
point (b)
the AIFM Law; k) central counterparties (CCPs) within the meaning
EMIR 9, including Tier 2 third-country CCPs within the meaning
EMIR, complying with the relevant requirements
EMIR in accordance with point (a)
EMIR; l) central securities depositories within the meaning
the CSD Law; 5 In its competence as NIS authority, the CSSF already informed relevant Supervised Entities
their consideration as DSP when the NIS Law entered into force. The CSSF will reconfirm the relevant Supervised Entities
their status as DSP at the latest by 1 March 2024. The Supervised Entities which will not receive this information at that date are therefore not considered as DSP, without prejudice to potential future information. 6 CSSF Regulation No 20-04
15 July 2020 on the definition
essential services under the Law
28 May 2019 transposing Directive (EU) 2016/1148
the European Parliament and
the Council
6 July 2016 on measures to ensure a common high level
network and information system security in the European Union. 7 Definition in alignment with the NIS Law. For the sake
clarity, the wording “postal financial services” has the meaning provided for in Article 1
the Law
15 December 2000, as amended. 8 9 Regulation (EU) No 648/2012
the European Parliament and
the Council
4 July 2012 on OTC derivatives, central counterparties and trade repositories. CIRCULAR CSSF 24/847 6/24 m) administrators
critical benchmarks within the meaning
point (b)
the Benchmark Regulation 10; n) crowdfunding Service Providers within the meaning
the Law
16 July 2019 on the operationalisation
European regulations in the area
financial services; o) credit institutions and the financial market infrastructures for which according to Article 3
the NIS Law the CSSF is the competent authority in terms
network and information security and that have been identified as OES, p) support PSF authorised in accordance with Article 29-3
the LFS for which according to Article 3
the NIS Law the CSSF is the competent authority in terms
network and information security and that have been informed by the CSSF
their consideration as DSP under the NIS Law. Section 1.2: Scope
application 3. This Circular defines the supervisory expectations that must be complied with in the event
an ICT-related incident. 4. The provisions
(General requirements)
this Circular are applicable to all Supervised Entities as defined in point 2
Entities incorporated in a third country shall be deemed to be included in the notion
Supervised Entity. 5. Branches in Luxembourg
the Entities that are part
a legal entity whose head
fice is located in a different Member State
the European Economic Area (EEA) (EEA branches) are subject to the supervision
the competent authority
that Member State (home Member State). However, as the CSSF is competent for ensuring that EEA branches comply with the specific requirements laid down in the sectoral legal and regulatory frameworks 11, this Circular applies if an ICT-related incident impacts areas for which the CSSF retains an oversight responsibility. 6. The provisions
(Specific requirements under the NIS Law and CSSF Regulation No 24-01)
this Circular are only applicable to those Supervised Entities that are also OES4 or DSP5. 7. With the aim
preventing double reporting, Supervised Entities in scope
this Circular are not required to notify under this Circular the incidents they notify in compliance with: a) Circular CSSF 21/787 on the “Application
the EBA Guidelines (EBA/GL/2021/03) on Major Incident Reporting under PSD2”, and/or; b) Cyber Incident Reporting for Supervised Entities defined as significant institutions falling under the direct supervision
the ECB, and/or; c) Article 45
Regulation (EU) No 909/2014 on notification
incidents resulting from the risks that key participants, service and utility providers, other central securities 10 Regulation (EU) 2016/1011
the European Parliament and
the Council
8 June 2016 on indices used as benchmarks in financial instruments and financial contracts or to measure the performance
investment funds and amending Directives 2008/48/EC and 2014/17/EU and Regulation (EU) No 596/2014. Notably in the context
investment services in accordance with the MiFID Law, the AML/CFT Law, the provision
asset management services and depositary tasks for Undertakings for Collective Investments established in Luxembourg. 11 CIRCULAR CSSF 24/847 7/24 depositories (CSDs) or other market infrastructures might pose to the CSD’s operations, and/or; d) Article 71
Commission Delegated Regulation (EU) 2017/392
11 November 2016 supplementing Regulation (EU) No 909/2014 on reporting
material operational incidents to the competent authority. 8. By way
exception from point 7 above, Supervised Entities falling under by point 7.b) and who are also OES, are required to report to the CSSF as per this Circular those incidents that impact the continuity
the essential services they provide, in addition to their other incident reporting obligations. CIRCULAR CSSF 24/847 8/24 Chapter 2: General requirements Section 2.1: Incidents to be notified 9. Supervised Entities shall notify the following incidents in accordance with the procedure defined in section 2.3: a) Any successful malicious unauthorised access to the network and information systems. For the purpose
this circular these successful malicious unauthorised accesses are to be considered as major ICT-related incidents.
the following criteria: a) the number and/or relevance
clients 12 or financial counterparts affected and, where applicable, the amount or number
transactions affected by the ICT-related incident, and whether the ICT-related incident has caused reputational impact; b) the duration
the ICT-related incident, including the service downtime;
the services affected, including the Supervised Entity’s transactions and operations; f) the economic impact, in particular direct and indirect costs and losses,
the ICT-related incident in both absolute and relative terms.
the ICT-related incident is available to the Supervised Entities, but no later than 24 hours after the detection
that ICT-related incident. If longer time is needed to classify the ICT-related incident, Supervised Entities shall explain in the initial notification submitted to the competent authority the reasons thereof. Where the deadline Supervised Entities who are also OES shall consider the number
users affected by the disruption to the essential service. Supervised Entities who are also DSP shall consider the number
users affected by the incident, in particular those who use the digital service to provide their own services. 12 CIRCULAR CSSF 24/847 9/24 for classification falls on a weekend day or a bank holiday, Supervised Entities may classify the incident on the next working day. Section 2.3: Major ICT-related incident notification 14. Supervised Entities shall, within the time limits laid down in Annex I, submit the following notifications
major ICT-related incidents to the CSSF:
whether mitigation measures have been fully implemented, and when the actual impact figures are available to replace estimates. In this notification Supervised Entities can add any follow-up and additional information that is deemed relevant for the ICT-related incident. 15. When the ICT-related incident proves to have or will potentially have a very serious impact (e.g., complete unavailability
the systems), the Supervised Entity shall notify the CSSF as soon as possible within the given timeframe, and if necessary, before the formal submission
the notification form.
the notification form, depending on the phase they are in (i.e., section “Initial information” for initial notification, section “Incident cause, classification and impact” for intermediate notification and section “Root cause – Follow-up and additional information” for final notification). The notification form contains the data fields laid down in Annex II. 18. The sections
the notification form must be submitted in the order indicated in point 14. Should the Supervised Entity have all the information required available at the time
the initial notification, a single submission (containing all the sections
the notification form) shall be made. 19. Supervised Entities shall also notify the competent authority when, as a result
the continuous assessment
the ICT-related incident, it is identified that an already reported ICT-related incident no longer fulfils the criteria to be considered major and is not expected to fulfil them before the ICT-related incident is resolved. In this case, Supervised Entities shall reclassify the ICT-related incident as soon as this circumstance is detected and provide an explanation
the reasons justifying this reclassification in the section “Initial information”
the notification form. 20. Supervised Entities may outsource the reporting obligations under this chapter to a thirdparty provider. In case
such outsourcing, the Supervised Entity remains fully responsible for the fulfilment
the ICT-related incident reporting requirements within the applicable timeline and for the whole content
the incident reporting. CIRCULAR CSSF 24/847 10/24 Chapter 3: Specific requirements under NIS Law and CSSF Regulation No 24-01 Section 3.1: Incident notification by Supervised Entities who are also OES 21. In compliance with Article 8
the NIS Law, Supervised Entities who are also OES shall notify, without undue delay, the CSSF
incidents having a significant impact on the continuity
the essential services they provide. The notion
“without undue delay” is considered complied with when Supervised Entities submit their incident notification in line with the time limits indicated in section 2.3 (Major ICT-related incident notification) and in Annex I. 22. In this respect, in compliance with Article 8
the NIS Law and CSSF Regulation No 2401, Supervised Entities who are also OES shall assess whether an incident is to be classified as a significant incident by applying mutatis mutandis the requirements stated in section 2.2 (ICT-related incident classification) and shall notify the significant incidents in compliance with the requirements stated in section 2.3 (Major ICT-related incident notification).
the NIS Law and CSSF Regulation No 24-01 mentions that DSPs shall notify, without undue delay, the competent authority
incidents having a significant impact on the provision
a digital service they provide within the European Union. The notion
“without undue delay” is considered complied with when Supervised Entities submit their incident notification in line with the time limits indicated in section 2.3 (Major ICT-related incident notification) and in Annex I. 26. Supervised Entities who are also DSP shall: a) assess whether an incident (including successful malicious unauthorised accesses, as defined under point 9.a)
section 2.1) is to be classified as a significant incident in line with Articles 3 and 4
Commission Implementing Regulation (EU) 2018/151
30 January 2018 13 providing details on Article 11
the NIS Law; 13 Commission Implementing Regulation (EU) 2018/151
30 January 2018 laying down rules for application
Directive (EU) 2016/1148
the European Parliament and
the Council as regards further specification
the elements to be taken into account by digital service providers for managing the risks posed to the security
network and information systems and
the parameters for determining whether an incident has a substantial impact. CIRCULAR CSSF 24/847 11/24 b) apply mutatis mutandis points 12 and 13
section 2.2 (ICT-related incident classification); c) notify the significant incidents in compliance with the requirements stated in section 2.3 (Major ICT-related incident notification). 27. When an incident is classified both as a significant incident and as a major ICT-related incident, Supervised Entities who are also DSP shall notify only once the incident and indicate in their notification that the incident is also notified under the NIS Law. Chapter 4: Date
application 28. This Circular shall enter into force on 1 April 2024 for the Supervised Entities as defined in point 2
notifications II. Data fields 12/24 Annex I: Deadlines and explanations for submission
notifications Relevant section to be filled in and Deadlines Explanatory notes Classification
the incident as major Classification
the incident as major Within 24 hours after the detection
the ICTrelated incident Reminder
point 15: When the ICT-related incident proves to have or submitted N/A Where the deadline for classification falls on a weekend day or a bank holiday, Supervised Entities may classify the incident on the next working day. will potentially have a very serious impact (e.g., complete unavailability
the systems), the Supervised Entity shall notify the CSSF as soon as possible within the given timeframe, and if necessary, before the formal submission
the notification form. INITIAL INFORMATION Within 4 hours after the classification
the incident as major The “INITIAL INFORMATION” section contains the Where the deadline for notification falls on a be included in the notification the first time it is weekend day or a bank holiday, Supervised general information about the incident that shall submitted. Entities may notify the incident on the next working day. INCIDENT CAUSE, CLASSIFICATION IMPACT AND Within 3 working days after the submission to the The section “INCIDENT CAUSE, CLASSIFICATION CSSF
the INITIAL INFORMATION AND IMPACT” provides a more detailed description
the incident, its consequences and the corrective measures that were taken to CIRCULAR CSSF 24/847 13/24 recover. If the Supervised Entity has updates to previous reports (
the same incident), an updated version
the section
the form may be submitted. ROOT CAUSE – FOLLOW-UP AND ADDITIONAL Within 20 working days after the submission to The section “ROOT CAUSE – FOLLOW-UP AND INFORMATION the ADDITIONAL CSSF
the INCIDENT CLASSIFICATION AND IMPACT CAUSE, INFORMATION” provides information regarding the root cause analysis, lessons learned and any other relevant information. When submitting this information, the Supervised Entity shall review the other sections
the form and update these, where appropriate. CIRCULAR CSSF 24/847 14/24 Annex II: Data fields Section – Initial Information Data Field description / Question Field type Proposed options Alphanumeric
detection
the incident yyyy-mm-dd hh:mm 5. Date and time
classification
the incident as major List
world countries yyyy-mm-dd hh:mm Choice (multiple) - Select all that apply • • • • • • 6. Criteria triggering the major ICT-related incident report • • CIRCULAR CSSF 24/847 Clients or financial counterparts affected Transactions affected Reputational impact Service downtime Geographical spread Data losses entailed in relation to availability, authenticity, integrity or confidentiality Criticality
the services affected Economic impact 15/24 Data Field description / Question Field type Proposed options Choice (multiple) – Select • • • • • • • • one option 7. The incident was detected by 7.1. If "Other", specify Alphanumeric 8. General description
the incident Alphanumeric IT security Staff member Internal audit Consumer / payment service user External auditor Third party provider Attacker / warning Other Provide a general description
the incident, its immediate impact and including the measures that have been taken so far 9. Short description
impact in other EU member states Alphanumeric
this notification?
the incident, Alphanumeric Proposed options Provide a detailed description
the incident, including (if known and/or applicable): - How the incident started - Background and incident detection, who was involved, what happened, how did it evolve? - Cause
the incident
beginning
the incident - if known hh:mm Choice (multiple) – Select one option 5. Who is leading the investigation
the incident?
the main options. Then, as applicable, select the subcategories CIRCULAR CSSF 24/847 Choice (multiple) Select all that apply • • • • • Group Supervised entity Service provider Security company Other • • • • • Under investigation Malware Social engineering Insider/Third Party Provider Threat Intrusion/Unauthorised access 17/24 Data Field description / Question 6.1.1. If "Other", specify Field type • • • • Denial
service System/Process failure Human error Other • Malware o Ransomware o Trojan horse o Virus/Worm/Spyware o Other (Malware) Social engineering o Phishing/*ishing o Other (Social engineering) Insider/Third Party Provider Threat o Accidental data leakage/corruption o Intentional misuse
access rights by insider o Intentional misuse
access rights by service provider o Other (Insider/Third Party Provider Threat) Intrusion/Unauthorised access o Brute force attack o Malicious script injection and/or OS comm
AI explanation based on the official legal text. Indicative, not a substitute for legal advice.