Recital 32

Recital 32

Digital Operational Resilience Act · UE 2022/2554

(32)

With ICT risk becoming more and more complex and sophisticated, good measures for the detection and prevention of ICT risk depend to a great extent on the regular sharing between financial entities of threat and vulnerability intelligence. Information sharing contributes to creating increased awareness of cyber threats. In turn, this enhances the capacity of financial entities to prevent cyber threats from becoming real ICT-related incidents and enables financial entities to more effectively contain the impact of ICT-related incidents and to recover faster. In the absence of guidance at Union level, several factors seem to have inhibited such intelligence sharing, in particular uncertainty about its compatibility with data protection, anti-trust and liability rules.

Luxembourg specificity
loi luxembourgeoise du 1er aout 2024 portant mise en oeuvre de DORA

In Luxembourg, the CSSF relies on the national sharing ecosystem run by CIRCL (Computer Incident Response Center Luxembourg, operator of Europe's reference MISP platform) and participates in TIBER-LU for advanced penetration testing. The law of 1 August 2024 implementing DORA designates the CSSF as competent authority and confirms the articulation with the law of 28 July 2023 transposing NIS 2 for financial entities also qualified as essential entities.

Luxgap practice: connect your SIEM to CIRCL's MISP instance from month one and trace every IOC consumed or published; it is the simplest evidence to present during a CSSF inspection to materialise your threat intelligence sharing setup.