ICT security and cyber risk monitoring
Objective of ICT security and cyber risk monitoring
The objective of information and communication technology (ICT) security and cyber risk monitoring is to promote the availability of safe, secure, reliable and at the same time innovative financial services. Therefore, the digital operational resilience of the financial market is one of the supervisory priorities of Latvijas Banka.
Market participants are tasked with developing and enhancing their capabilities to defend against growing and evolving cyber threats by strategically planning ICT protection and responding effectively to ICT vulnerabilities and security incidents, thereby ensuring the protection and viability of ICT.
This includes both the necessary technological resources and the awareness and knowledge of the capabilities to protect themselves – both for the financial institution itself and for society at large.
According to the European Union Agency for Cybersecurity (ENISA; see Threat Landscape — ENISA), these are the prime cyber threats with a potential to pose risks also to financial market participants:
DORA – the new ICT security framework for financial entities
Necessity to introduce DORA
DORA, or the Digital Operational Resilience Act, is Regulation (EU) 2022/2554 of the European Parliament and of the Council on digital operational resilience for the financial sector that entered into force on 17 January 2023.
The increased use of technology in the digitalisation process not only provides business opportunities for existing and new market participants, but also promotes a rise in risks. The framework aims to mitigate the risks associated with the digital transformation of the financial sector by setting common rules for all market participants. The rules apply to a wide range of financial institutions, including important ICT third-party service providers such as cloud service providers, telecommunication operators, software developers and other digital service providers.
Critical third-party service providers with cross-border reach and high concentration risk and systemic impact will be subject to centralised supervision at European level.
The exact definitions of the scope of DORA will be set out in the Law on the Digital Operational Resilience of the Financial Market (see the Draft Legislation website). Each financial entity identifies and categorises its own ICT service providers in compliance with the implementing technical standards, for example:
Regulatory framework under DORA
The DORA requirements are divided into five pillars and will be detailed in regulatory technical standards (RTS) and implementing technical standards (ITS), which are in the public consultation phase and are expected to be approved in 2024.
The first pillar of standards consists of essentially refined existing regulatory requirements and defines in detail two groups of standards.
The ICT Risk Management RTS set out harmonised requirements in relation to the existing risk framework for financial entities, based on the Guidelines on ICT and security risk management issued by the European Banking Authority.
The ICT Risk Management RTS are expected to harmonise the incident reporting framework, including incident classification and reporting requirements, and establish a common reporting format.
ICT Risk Management Framework | ICT Incident Reporting |
RTS "Risk Management" |
RTS "Incident Classification" |
Financial entities subject to the requirements laid down by Regulation (EU) 2022/2554 of the European Parliament and of the Council of 14 December 2022 on digital operational resilience for the financial sector (DORA), in accordance with Article 19 of this Regulation, report major ICT-related incidents and significant cyber threats to Latvijas Banka. The content of reports and templates is stipulated in the technical and implementing standards (RTS/ITS). Different templates can be used for reporting incidents and cyber threats: Financial entities report major ICT-related incidents and significant cyber threats to Latvijas Banka in XLSX (Microsoft Excel Open XML) file format according to the XLSX file templates published on Latvijas Banka's website (without altering the worksheet order and table placement in both templates). Financial entities send reports of incidents and significant cyber threats to the official e-address of Latvijas Banka. Credit institutions classified as significant submit reports using Latvijas Banka's file exchange service (FAS). The deadline for submitting the initial notification is 4 hours after the incident classification and 24 hours after the incident detection, 72 hours are allocated for the intermediate reporting and 1 month – for the submission of the final report. After collecting, analysing, and classifying incident information using templates (Excel file), financial entities prepare an initial notification followed by an intermediate report and a final report, and submit them to Latvijas Banka according to the specified deadlines. When submitting an intermediate report or a final report, the template retains the information previously provided in the initial notification or the intermediate report. If necessary, the previously submitted information in the relevant tables is revised. File templates for reports can be downloaded here: The file name format is aaa_v_nn_yyyymmdd.xlsx xls, where: aaa – file name prefix: "DORA_IR" – for major incident reports; "DORA_CYB" – for significant cyber threat reports; v – version number of the submitted incident report (for cyber threat reports, only "1" is used), where: "1" – initial notification; "2" – intermediate report; "3" – final report; nn – report sequence number, if there is more than one report on the submission day (consists of two digits, such as 01, 02, etc.); yyyymmdd – date of submission of the initial notification of the incident, where: yyyy – year; mm – month; dd – day. Financial entities can fill in the incident report template in Latvian or English. The availability of the contact points or employees indicated in the report must be ensured throughout the incident handling cycle. If the financial entity has also sent the incident report to the National Cyber Security Centre or consulted it about incident containment solutions, the initial notification must include the relevant information. If a financial entity plans to delegate or has delegated the reporting obligation to a third party or an ICT service provider, it must notify Latvijas Banka through the general communication procedure.
DORA also includes three new regulatory areas with significant implications for financial entities:
- risk management of third-party ICT providers – this is also expected to subject the third-party providers of critical ICT services of financial entities to regulatory requirements;
- operational resilience testing – this is expected to harmonise and standardise digital operational resilience testing requirements – following a risk-based approach, companies should implement assessments, testing, methodologies, solutions and tools that are appropriate to the size, business and risk profile of the company;
- European supervisory framework – this will ensure the overall functioning of the mechanism from a cross-border perspective and the supervision of critical third-party service providers by a single supervisor in cooperation with national competent authorities.
Digital resilience testing | Risk management of third-party ICT providers | Framework for the monitoring of critical service providers |
RTS "Threat-Led Penetration Testing" |
ITS "Supplier Information Register Form" |
RTS "Harmonisation of Monitoring Conditions" |
DORA is directly applicable, but in order to provide a legal basis for supervision, to define the supervisory authorities and their responsibilities, the relevant amendments to the national framework will be made in Latvia in 2024 and are planned to be developed and submitted to the Ministry of Finance for approval (Laws and regulations | Ministry of Finance (fm.gov.lv)).
DORA is directly applicable, but in order to provide a legal basis for supervision and to define the supervisory authorities and their responsibilities, the Ministry of Finance is drafting the Law on the Digital Operational Resilience of the Financial Market (see Legislation | Ministry of Finance (fm.gov.lv); the Draft Legislation Latvijas Banka's Regulation No 360 "Regulation on Information Technology and Security Risk Management" of 2 December 2024 applies until 17 January 2025. The new ICT security requirements have been set out under the DORA framework. Financial entities falling outside the scope of DORA will have to ensure compliance with the digital operational resilience requirements as of 2025 based on simplified ICT risk management rules. Latvijas Banka intends to issue the respective Regulation after receiving the relevant delegation. Latvijas Banka's Regulation No 361 "Regulation on Major Incident Reporting Related to Payment Services" of 2 December 2024 applies until 17 January 2025. After 17 January 2025, incident reporting and management will have to comply with the DORA requirements. The Financial and Capital Market Commission's Regulation No 84 "Regulations on Outsourcing Arrangements" of 6 July 2021 was reissued as Latvijas Banka's Regulation No 374 "Regulation on Outsourcing Arrangements for Credit Institutions, Payment Institutions and Electronic Money Institutions" of 16 December 2024. ICT third-party service providers are excluded from the outsourcing regulation, as the management requirements and the requirements for ICT contractual arrangements are set out in DORA. Three European Supervisory Authorities – the European Banking Authority, the European Securities Market Authority and the European Insurance and Occupational Pensions Authority – are compiling questions and answers to support consistent and effective application of the European Union regulation in the area of financial services. The database of questions and answers regarding DORA is available on the website of the European Insurance and Occupational Pensions Authority (see Joint Q&As - EIOPA) and can be navigated by selecting appropriate filters. The questions published there are the ones that market participants have most often found confusing. If you cannot find an answer to your question via the resources of the European Supervisory Authorities or Latvijas Banka, you can e-mail it to Question. In what cases and how does Latvijas Banka intend to exercise its right to request financial institutions to conduct threat-led penetration testing (TLPT)? Question. How will the branches of financial entities registered in Latvia be supervised? Question. Do we understand correctly that, with DORA becoming applicable, we will no longer have to report incidents to the European Central Bank but will instead report them to Latvijas Banka? Question. To what extent are the DORA requirements for ICT third-party service providers applicable to software licence distributors? We believe that several requirements are not really applicable, as a distributor does not process any financial institution data, and also the existence or non-existence of a distributor does not affect the operation of the software itself. Question. In the context of further improving the Law on the Digital Operational Resilience of the Financial Market, are there any plans to review the list of financial entities subject to simplified digital operational resilience requirements to align the requirements across the Baltic States, i.e. to avoid imposing stricter requirements on certain financial entities? Question. Is it true that non-bank lenders (instant loans) fall outside the scope of both DORA and NIS2 (National Cyber Security Law)? Question. Please confirm that we have understood correctly: only the existing ICT service contracts that support critical or important functions should be renewed (amended), i.e. not all existing ICT service contracts, but only those that support critical or important functions. As to other ICT contractual arrangements, their compliance with the management principles of third-party related ICT risks and associated risks must be evaluated (Article 28 of DORA). If necessary, these contractual arrangements must also be amended to provide for auditing rights, consent to cooperation with the competent authorities and the requirements referred to in Articles 30(1) and 30(2) of DORA regarding key contractual provisions.
Answer. DORA provides that the supervisor may request that testing is conducted by a wide range of financial entities, but the competent authority may apply exceptions based on the principle of proportionality. TLPT subjects will be selected by evaluating the maturity of their ICT governance and processes and criticality for the overall financial system, with a primary focus on systemically important market participants. The management of the entity will be notified well in advance of being selected to take part in the testing exercise, so that it can start the planning process and setting up test management teams.
Answer. The competent authority ensuring the supervision of branches is the financial market supervisor of the Member State where the parent financial entity is established.
Answer. Financial entities that previously reported major incidents to the European Central Bank will now report them to Latvijas Banka.
Answer. The implementing technical standards for the register of information outline requirements regarding the contractual arrangements to be registered in the register of ICT third-party service providers. They are based on the need for information to identify critical ICT providers and ensure their supervision at the European Union level. The register of information must contain information about software licences. In order to answer the question whether a distributor of licences is an ICT third-party service provider, one has to analyse the commitments outlined in the respective supply contract. An explanation by the European Securities and Markets Authority is available here: ESMA_QA_2103.
Answer. The proposal is to apply simplified digital operational resilience requirements to financial entities that fall outside the scope of DORA. At the national level, the scope of DORA can only be extended or narrowed with regard to specific categories of market participants, such as credit unions. This is not an option for other market segments.
Answer. Non-bank lenders are licensed and supervised by the Consumer Rights Protection Centre. In order to find out the status with regard to the requirements of the National Cyber Security Law, one can use the interactive tool NKDL tests.
Answer. The ICT contractual arrangements supporting critical and important functions have to include mandatory provisions based on the requirements set out by Commission Delegated Regulation (EU) 2024/1773 of 13 March 2024 supplementing Regulation (EU) 2022/2554 of the European Parliament and of the Council with regard to regulatory technical standards specifying the detailed content of the policy regarding contractual arrangements on the use of ICT services supporting critical or important functions provided by ICT third-party service providers, and an adequate management policy must be developed and implemented. Evaluating and renewing such contacts is a priority to ensure compliance.
Current status of regulatory documents related to DORA
Regulation (EU) 2022/2554 of the European Parliament and of the Council of 14 December 2022 on digital operational resilience for the financial sector and amending Regulations (EC) No 1060/2009, (EU) No 648/2012, (EU) No 600/2014, (EU) No 909/2014 and (EU) 2016/1011 Commission Delegated Regulation (EU) 2024/1774 of 13 March 2024 supplementing Regulation (EU) 2022/2554 of the European Parliament and of the Council with regard to regulatory technical standards specifying ICT risk management tools, methods, processes, and policies and the simplified ICT risk management framework Commission Delegated Regulation (EU) 2024/1773 of 13 March 2024 supplementing Regulation (EU) 2022/2554 of the European Parliament and of the Council with regard to regulatory technical standards specifying the detailed content of the policy regarding contractual arrangements on the use of ICT services supporting critical or important functions provided by ICT third-party service providers Commission Delegated Regulation (EU) 2024/1772 of 13 March 2024 supplementing Regulation (EU) 2022/2554 of the European Parliament and of the Council with regard to regulatory technical standards specifying the criteria for the classification of ICT-related incidents and cyber threats, setting out materiality thresholds and specifying the details of reports of major incidents Commission Delegated Regulation (EU) 2024/1502 of 22 February 2024 supplementing Regulation (EU) 2022/2554 of the European Parliament and of the Council by specifying the criteria for the designation of ICT third-party service providers as critical for financial entities Commission Implementing Regulation (EU) 2024/2956 of 29 November 2024 laying down implementing technical standards for the application of Regulation (EU) 2022/2554 of the European Parliament and of the Council with regard to standard templates for the register of information Commission Delegated Regulation (EU) 2024/1505 of 22 February 2024 supplementing Regulation (EU) 2022/2554 of the European Parliament and of the Council by determining the amount of the oversight fees to be charged by the Lead Overseer to critical ICT third-party service providers and the way in which those fees are to be paid ESAs Decision of 8 November 2024 concerning the reporting by competent authorities to the ESAs of information necessary for the designation of critical ICT third-party service providers in accordance with the Digital Operational Resilience Act (DORA) The second batch of draft regulatory standards and guidelines is available on the website of the European Insurance and Occupational Pensions Authority. RTS and ITS on content, format, templates and time frame for reporting major ICT incidents and notifying significant cyber threats RTS on threat-led penetration testing (TLPT) RTS on harmonisation of conditions enabling the conduct of the oversight activities RTS on the criteria to establish the Joint Examination Teams Guidelines on oversight cooperation Guidelines on the estimation of aggregated costs and losses caused by major ICT-related incidents Digital transformation of the financial market and digitalisation processes inevitably entail challenges related to: When embarking on ambitious digitalisation projects, the management body of an organisation should have such a risk management culture in place that includes development based on cutting-edge and innovative technologies, for example, the artificial intelligence. The cornerstone of this risk culture is effective communication across all organisational levels involved in digital transformation projects. This includes clear accountability for risks, their management and monitoring based on pre-defined criteria, while at the same time allowing for the testing of digital transformation initiatives. The risk management culture can be enhanced by implementing targeted programmes, such as innovation laboratories, where participants can directly assess the opportunities and risks associated with technologies. With financial market services becoming increasingly digitalised, the level of potential threats and damage arising from cyberattacks is rising. Having an effective risk management framework and an adequate risk appetite can help to strike balance between development and limiting the potential losses.