Recital 33

Recital 33

Digital Operational Resilience Act · UE 2022/2554

(33)

In addition, doubts about the type of information that can be shared with other market participants, or with non-supervisory authorities (such as ENISA, for analytical input, or Europol, for law enforcement purposes) lead to useful information being withheld. Therefore, the extent and quality of information sharing currently remains limited and fragmented, with relevant exchanges mostly being local (by way of national initiatives) and with no consistent Union-wide information-sharing arrangements tailored to the needs of an integrated financial system. It is therefore important to strengthen those communication channels.

Luxembourg specificity
loi du 1er aout 2024 portant mise en oeuvre du reglement (UE) 2022/2554 (DORA) et circulaire CSSF 22/806

In Luxembourg, the CSSF frames cyber information sharing via CSSF Circular 22/806 on ICT outsourcing and the TIBER-LU framework for intelligence-based penetration testing. The law of 1 August 2024 implementing the DORA Regulation clarifies that sharing with peers does not breach the professional secrecy of Article 41 of the law of 5 April 1993 on the financial sector, provided it is carried out within the formalised framework of DORA Article 45.

Luxgap practice: we map your sharing matrix with the CSSF, BCL, CERT.LU, HCPN and sectoral communities (ABBL, ALFI, FS-ISAC), and we document the articulation with Article 41 LSF to secure each flow in case of inspection.