Recital 3
Digital Operational Resilience Act · UE 2022/2554
| (3) | The European Systemic Risk Board (ESRB) reaffirmed in a 2020 report addressing systemic cyber risk how the existing high level of interconnectedness across financial entities, financial markets and financial market infrastructures, and particularly the interdependencies of their ICT systems, could constitute a systemic vulnerability because localised cyber incidents could quickly spread from any of the approximately 22 000 Union financial entities to the entire financial system, unhindered by geographical boundaries. Serious ICT breaches that occur in the financial sector do not merely affect financial entities taken in isolation. They also smooth the way for the propagation of localised vulnerabilities across the financial transmission channels and potentially trigger adverse consequences for the stability of the Union’s financial system, such as generating liquidity runs and an overall loss of confidence and trust in financial markets. |
In Luxembourg, the CSSF is the competent authority for DORA and has published CSSF Circular 24/847 on ICT incident reporting, which directly operationalises this recital: any major incident must be notified to allow the CSSF and ESRB to identify potential systemic propagation across the financial centre. The concentration of Luxembourg financial entities on a few shared ICT providers (eBRC, LuxConnect, POST Telecom) makes this exercise particularly sensitive.
Luxgap practice: we include by default the structuring ICT providers of the Luxembourg financial centre in your dependency graph to measure your real sectoral concentration risk.