2023-06-21

Added · Updated

Circular Letter No. CC/2023/00000025

The document requires credit institutions, payment institutions, and electronic money institutions in Portugal to classify phishing incidents as significant cybersecurity and payment security incidents, mandating their reporting to the Bank of Portugal and other competent authorities based on materiality criteria. Institutions must enhance their operational risk management frameworks by monitoring and assessing phishing events in line with EBA guidelines on ICT risk and security. Furthermore, institutions are obligated to accurately record operational losses associated with phishing, including provisions for client compensation, in compliance with applicable accounting and supervisory reporting standards.

Banco de Portugal logo

Portugal

Banco de Portugal

Scan of the document's first page
Share

BDP published 1 document in the last 30 days — get each new one by email the day it lands.

Read the rest free

Lineage: In force

amendssupersedesissued underrefers toproposed or not in RegAlertarrows run from the older text to the one that changes it

Source: Banco de Portugal — original document · Summary generated with machine assistance and reviewed before publication; the authoritative text is the regulator's original document. How RegAlert works

More like this from BDP

BDP published 1 document in the last 30 days. We email you each new one the day it's published.