Featured Product

    EC Adopts NIS2 and DORA Directives

    January 13, 2023

    The European Commission (EC) finalized rules on the cybersecurity of sectors through a Directive on the Security of Network and Information Systems (NIS2 Directive). The NIS2 Directive entered into force on January 16, 2023 while EC adopted the Regulation 2022/2554 and the Directive 2022/2556 on digital operational resilience for the financial sector. The DORA Directive and Regulation will enter into force on January 16, 2023 while the European Union members states shall adopt and publish the measures necessary to comply with the DORA "Amending Directive" from January 17, 2025.

    The NIS2 Directive aims to strengthen cybersecurity risk management requirements as well as ensure companies that take appropriate and proportionate technical, operational, and organizational measures to manage the cybersecurity risks as well as prevent and minimize the impact of potential incidents. The NIS2 Directive will ensure a safer and stronger Europe by expanding significantly the sectors and type of entities falling under its scope and by strengthening security requirements for companies. The NIS2 Directive will replace the current Directive on Security of Network and Information Systems. The NIS2 Directive focuses on measures including incident response and crisis management, vulnerability handling and disclosure, policies and procedures to assess the effectiveness of cybersecurity risk management measures, and cybersecurity hygiene and training. To help enhance information-sharing and cooperation on cyber crisis management at both national and EU levels, the NIS2 Directive streamlines incident reporting obligations with more precise provisions on reporting, content, and timeline. Furthermore, there are more stringent supervisory measures for national authorities, as well as stricter enforcement requirements, along with the list of administrative sanctions, including fines for breach of the cybersecurity risk management and reporting obligations. Members states will have to transpose the NIS2 Directive into national law within 21 months from the entry into force of the Directive. During this time, member states shall adopt and publish the measures necessary to comply with this Directive.

    The DORA Amending Directive (Directive 2022/2556) will amend other Directives to align with DORA, including CRD IV, Solvency II, MiFID II, PSD2, UCITS and AIFMD. In-scope entities include credit institutions, payment institutions, electronic money institutions, investment firms, and crypto-asset service providers. Regulation 2022/2554 sets out uniform requirements concerning the security of network and information systems supporting the business processes of financial entities. It covers rules and requirements: 

    • applicable to information and communication technology (ICT) risk management; reporting of major ICT-related incidents and notifying, on a voluntary basis, significant cyber threats to the competent authorities; reporting of major operational or security payment-related incidents to the competent authorities by specified financial entities; and digital operational resilience testing; information and intelligence sharing in relation to cyber threats and vulnerabilities; and measures for the sound management of ICT third-party risk             
    • on the contractual arrangements concluded between ICT third-party service providers and financial entities
    • for the establishment and conduct of the Oversight Framework for critical ICT third-party service providers when providing services to financial entities
    • on cooperation among competent authorities, and rules on supervision and enforcement by competent authorities in relation to all matters covered by this Regulation

     

    Related Links

    Keywords: Europe, EU, Banking, Regtech, NIS2, Cyber Risk, DORA, Operational Resilience, ICT Risk, NIS Directive, EC

    Related Articles
    News

    BIS and Central Banks Experiment with GenAI to Assess Climate Risks

    A recent report from the Bank for International Settlements (BIS) Innovation Hub details Project Gaia, a collaboration between the BIS Innovation Hub Eurosystem Center and certain central banks in Europe

    March 20, 2024 WebPage Regulatory News
    News

    Nearly 25% G-SIBs Commit to Adopting TNFD Nature-Related Disclosures

    Nature-related risks are increasing in severity and frequency, affecting businesses, capital providers, financial systems, and economies.

    March 18, 2024 WebPage Regulatory News
    News

    Singapore to Mandate Climate Disclosures from FY2025

    Singapore recently took a significant step toward turning climate ambition into action, with the introduction of mandatory climate-related disclosures for listed and large non-listed companies

    March 18, 2024 WebPage Regulatory News
    News

    SEC Finalizes Climate-Related Disclosures Rule

    The U.S. Securities and Exchange Commission (SEC) has finalized the long-awaited rule that mandates climate-related disclosures for domestic and foreign publicly listed companies in the U.S.

    March 07, 2024 WebPage Regulatory News
    News

    EBA Proposes Standards Related to Standardized Credit Risk Approach

    The European Banking Authority (EBA) has been taking significant steps toward implementing the Basel III framework and strengthening the regulatory framework for credit institutions in the EU

    March 05, 2024 WebPage Regulatory News
    News

    US Regulators Release Stress Test Scenarios for Banks

    The U.S. regulators recently released baseline and severely adverse scenarios, along with other details, for stress testing the banks in 2024. The relevant U.S. banking regulators are the Federal Reserve Bank (FED), the Federal Deposit Insurance Corporation (FDIC), and the Office of the Comptroller of the Currency (OCC).

    February 28, 2024 WebPage Regulatory News
    News

    Asian Governments Aim for Interoperability in AI Governance Frameworks

    The regulatory landscape for artificial intelligence (AI), including the generative kind, is evolving rapidly, with governments and regulators aiming to address the challenges and opportunities presented by this transformative technology.

    February 28, 2024 WebPage Regulatory News
    News

    EBA Proposes Operational Risk Standards Under Final Basel III Package

    The European Union (EU) has been working on the final elements of Basel III standards, with endorsement of the Banking Package and the publication of the European Banking Authority (EBA) roadmap on Basel III implementation in December 2023.

    February 26, 2024 WebPage Regulatory News
    News

    EFRAG Proposes XBRL Taxonomy and Standard for Listed SMEs Under ESRS

    The European Financial Reporting Advisory Group (EFRAG), which plays a crucial role in shaping corporate reporting standards in European Union (EU), is seeking comments, until May 21, 2024, on the Exposure Draft ESRS for listed SMEs.

    February 23, 2024 WebPage Regulatory News
    News

    ECB to Expand Climate Change Work in 2024-2025

    Banking regulators worldwide are increasingly focusing on addressing, monitoring, and supervising the institutions' exposure to climate and environmental risks.

    February 23, 2024 WebPage Regulatory News
    RESULTS 1 - 10 OF 8957