2023-06-21
Added · Updated
The document requires credit institutions, payment institutions, and electronic money institutions in Portugal to classify phishing incidents as significant cybersecurity and payment security incidents, mandating their reporting to the Bank of Portugal and other competent authorities based on materiality criteria. Institutions must enhance their operational risk management frameworks by monitoring and assessing phishing events in line with EBA guidelines on ICT risk and security. Furthermore, institutions are obligated to accurately record operational losses associated with phishing, including provisions for client compensation, in compliance with applicable accounting and supervisory reporting standards.