2026-06-17

Added · Updated

Amendments to Proper Conduct of Banking Business Directive No. 366 on Reporting of Technology Failure Incidents, Information Security Incidents, and Cyber Attacks

The Bank of Israel updates Proper Conduct of Banking Business Directive No. 366 to align terminology with Directive 364 and modify reporting obligations for Payment Service Providers with Prudential Importance License Holders, who are now required to report only incidents with material impact on the banking system rather than all incidents. The definition of Significant Technology Failure Incident is expanded to include severe internal disruptions, while the definition of Technology Failure Incident is moved to Directive 364. A new requirement mandates that incident investigations be conducted by or involve an independent party, and entities must document the rationale for any decision not to report an incident.

Bank of Israel logo

Israel

Bank of Israel

Scan of the document's first page
Share

Get BOI alerts — same-day email on every new publication.

Read the rest free

Lineage: In force

Management of IT, Information S…2024Management of IT, Information Security, and Cyber Defense Risks (2024-11-18)Reporting of Technological Fail…2026Reporting of Technological Failures, Data Security Incidents, and Cyber Attacks (2026-06-17)Amendments to Proper Conductof Banking Business Directive…2026-06-17 · this documentAmendments to Proper Conduct of Banking Business Directive No. 366 on Reporting of Technology Failure Incidents, Information Security Incidents, and Cyber Attacks (2026-06-17)
amendssupersedesissued underrefers toproposed or not in RegAlertarrows run from the older text to the one that changes it

Source: Bank of Israel — original document · Summary generated with machine assistance and reviewed before publication; the authoritative text is the regulator's original document. How RegAlert works

More like this from BOI

We email you every new BOI publication the day it's published.