CSSF 25/892: quantifying ICT incident costs — adopt 3‑2‑1‑1‑0 immutable backups
Since 28/05/2025, the CSSF requires annual aggregated estimation of costs/losses from major ICT incidents (JC 2024 34). Immutable, isolated 3‑2‑1‑1‑0 backups cut financial impact and provide the required evidence.
CSSF 25/892: quantifying ICT incident costs — adopt 3‑2‑1‑1‑0 immutable backups
Verifiable fact — On 28 May 2025, the CSSF issued Circular CSSF 25/892 adopting the ESAs’ Joint Guidelines (JC 2024 34) on estimating aggregated annual costs and losses caused by major ICT-related incidents. This requirement applies to DORA entities (excluding micro‑enterprises) supervised in Luxembourg. Source: CSSF, ESAs.
Promise — Here is how an immutable and isolated backup policy (3‑2‑1‑1‑0) both reduces the financial impact of ransomware and provides the evidence required by DORA and the CSSF.
Facts
Since 28 May 2025, CSSF Circular 25/892 requires financial entities in scope of DORA to apply the Joint Guidelines JC 2024 34 to estimate and annually aggregate costs and losses caused by major ICT incidents (e.g., investigations, remediation, business interruption, data loss, legal fees). The CSSF specifies that this applies to all DORA entities (excluding micro‑enterprises), aligned with the EU framework and part of the digital operational resilience regime. Sources: CSSF, JC 2024 34 (PDF).
Context: in 2026, threats remain high and fast‑moving. Recent examples: the cyberattack against Swiss rail manufacturer Stadler (extortion demand ~CHF 10M) and Teams vishing‑led ransomware campaigns able to encrypt in under 17 hours. Sources: BleepingComputer, BleepingComputer.
The applicable legal framework
DORA (Regulation (EU) 2022/2554) requires:
- Arts. 11–12: an ICT continuity policy, response and recovery plans, and explicit backup and restoration policies, with immediate activation upon incident and post‑incident review.
- JC 2024 34 (adopted by CSSF 25/892): a harmonised methodology to estimate aggregated annual costs/losses from major ICT incidents (definitions, scope, aggregation, treatment of recoveries/insurance, templates). Sources: EUR‑Lex, ESAs.
Operational takeaway for Luxembourg executives: you must both limit the impact (resilience/continuity) and measure it against a common reference. In this respect, DORA’s operational resilience requirements structure the policies and evidence expected by the supervisor.
The technical solution to deploy
Immutable backups + network isolation via 3‑2‑1‑1‑0
- Principle: 3 copies, on 2 different media, 1 off‑site copy, 1 immutable/offline copy, 0 restores tested with errors (target). This makes backup destruction far harder for an attacker and shortens downtime.
- Immutability: object storage with object‑lock/WORM, retention policies, legal hold, MFA‑delete. Prevents backup alteration/deletion for a defined period, even by a compromised admin.
- Network isolation: logical/physical air‑gap, dedicated vaults, tiered backup accounts and networks, no transitive trust with production, separate keys/identities.
- Proven restores: regular recovery tests (bare‑metal, VMs, databases, SaaS), clean‑room scenarios to prevent re‑infection, validate RTO/RPO per critical environment.
- Telemetry and traceability: job logs, entropy/encryption anomaly signals, inventory of media/copies, retention timestamps. These feed JC 2024 34 templates directly (restore costs, downtime, avoided losses).
Frameworks: ISO/IEC 27001:2022 Annex A.8.13 Information backup and A.5.30 ICT readiness for business continuity; NIST CSF 2.0 “Recover”; CIS Control 11 Data Recovery.
How Luxgap delivers this
- Our ISO 27001 governance: scoping DORA requirements (Arts. 11–12) in your ISMS, mapping critical assets, threat‑modelling backup compromise scenarios (wiping, encryption, poisoning), retention and role‑segregation policies. Our fractional CISO team steers security‑to‑business alignment.
- Our 24/7 managed SOC: monitoring backup infrastructures (abnormal purge signals, dedup spikes, ransomware IOCs), evidence‑grade logging for CSSF reporting (downtime, restored volumes, actual MTTD/MTTR). Explore our managed SOC and incident detection offer.
- Our outsourced DPO and CISO consultants: alignment with JC 2024 34: defining cost/loss categories, collecting evidence (OT/IT, legal, insurance), annual consolidation and peer review before submission to the supervisor.
Real‑world case in Luxembourg or EU
A DORA‑in‑scope investment firm industrialised a 3‑2‑1‑1‑0 on‑prem + cloud design in 6 weeks: S3‑compatible immutable vault with object‑lock, dedicated logical air‑gap, separate accounts/keys, and quarterly clean‑room restore tests. Result: a simulated “encryption + backup wipe attempt” was contained with no data loss and controlled recovery of critical apps. Technical logs and the cost/recovery time dashboard were reused for the JC 2024 34 model, easing evidence‑based justification to internal audit and the supervisor.
First practical steps
- DORA Arts. 11–12 gap analysis: verify a written backup/recovery policy, role separation, backup set inventory, and documented tests.
- Enable immutability: where supported, enable WORM/object‑lock with coherent retention policies. Otherwise, implement a dedicated isolated vault with MFA‑delete and distinct KMS keys.
- Isolate the backup network: place backup targets behind separate accounts and segments, remove shared admin links with production.
- Test restoration: schedule a clean‑room restore exercise of a critical service this quarter, measure actual RTO/RPO, and document elapsed time and resources (raw input for JC 2024 34).
- Prepare CSSF 25/892 quantification: set up a cost collection runbook (internal, providers, insurance, business interruption) and a dashboard tracking service downtime — these feed the required annual estimate.
Official sources
- CSSF — Publication of Circular CSSF 25/892 (28/05/2025)
- ESAs — JC 2024 34, cost/loss guidelines (PDF)
- EUR‑Lex — Regulation (EU) 2022/2554 (DORA), esp. Arts. 11–12
To gauge field reality in 2026: BleepingComputer — Stadler (22/07/2026); BleepingComputer — Chaos via Teams (30/07/2026).
A question on this topic?
Our team usually replies within one business day. Configure your quote or write to us.
Build my quote →