2023-06-21
Added · Updated
The document requires credit institutions, payment institutions, and electronic money institutions in Portugal to classify phishing incidents as significant cybersecurity and payment security incidents, mandating their reporting to the Bank of Portugal and other competent authorities based on materiality criteria. Institutions must enhance their operational risk management frameworks by monitoring and assessing phishing events in line with EBA guidelines on ICT risk and security. Furthermore, institutions are obligated to accurately record operational losses associated with phishing, including provisions for client compensation, in compliance with applicable accounting and supervisory reporting standards.
Circular Letter No. CC/2023/00000025 Sent to: Credit Institutions, Payment Institutions and Electronic Money Institutions. Mod. 40000375/T – 01/14 Subject: Circular Letter Prudential Treatment of Phishing
The increasing digitalization of financial services activities, as well as the current geopolitical and economic context, foster a growing risk of cybersecurity threats in Portugal, which may affect institutions directly or indirectly through critical service providers and critical infrastructures or through the clients of these institutions.
Thus, it is essential that institutions ensure adequate management of the risks to which they are exposed, namely the risk associated with information and communication technologies, with a view to protecting their solvency and avoiding disruptions in their activity, thereby prejudicing the stability of the financial system.
In the area of risk associated with information and communication technologies, phishing – in the broad sense of the term, i.e., including vishing, smishing and other types of social engineering techniques, as defined in the glossary of concepts of the National Cybersecurity Centre1 – has been assuming increasing relevance, given the expressive increase in identified cases in recent months.
As such, taking into account the current legal and regulatory framework, it is justified to transmit a set of recommendations with a view to ensuring the minimization of the impacts associated with phishing events.
In these terms, the Bank of Portugal, after consulting the European Central Bank and the National Cybersecurity Centre, within the powers attributed to it by Articles 14 and 17 of Law No. 5/98, of January 31 (Organic Law), and under the provisions of Articles 92 and 115-T of the General Regime of Credit Institutions and Financial Companies, approved by Decree-Law No. 298/92, of December 31 (RGICSF) and Articles 60, paragraph 3 and 70, paragraph 3 of the Legal Regime of Payment Services and Electronic Money, approved by Decree-Law No. 91/2018, of November 12 (RJSPME), transmits to the credit institutions, payment institutions and electronic money institutions with headquarters in Portugal, and to the branches of institutions of these types, authorized to carry out activity in Portugal with headquarters in countries that are not Member States of the European Union, the following:
Communication Duties
The occurrence of situations of deception, fraud, or similar nature, using phishing techniques, in accounts of holders with the institutions (“phishing incidents”)2 , constitutes: i) a cybersecurity incident, within the meaning of point (c) of paragraph 2 of Article 1 of Instruction No. 21/2019 of the Bank of Portugal, regarding the duty to report significant cybersecurity incidents; and ii) a security incident, within the scope of Instruction No. 1/2019 of the Bank of Portugal, regarding the reporting of incidents of
1 https://www.cncs.gov.pt/pt/glossario/#linhasobservacao. 2 This Circular Letter is limited to phishing events directed at the institutions' clients, without prejudice to the applicability of these and other recommendations and requirements in the management of phishing events directed at the institutions' own employees.
Mod. 40000375/T – 01/14 severe nature related to the provision of payment services under the Revised Payment Services Directive3 .
In this sense, institutions must observe the duty to communicate to the Bank of Portugal provided for in the aforementioned Instructions, whenever the applicable materiality criteria are met. For the assessment of these criteria, institutions must consider the series of events, and not individual events, when there is evidence that they are related. Institutions must also always observe the provisions of paragraph 11 of Article 4 of Instruction No. 21/2019, as well as the provisions of paragraphs 8.3 and 8.5 of Instruction No. 1/2019.
Additionally, institutions must ensure the diligent, proactive and timely compliance with the duties of information towards other competent authorities regarding the occurrence of these incidents, namely those of a judicial, data protection or cybersecurity nature, with a view to the effective resolution of the incidents and to mitigating the potential systemic impact, by contagion, of the incidents.
Risk Management Framework
The occurrence of phishing incidents constitutes an indication of potential deficiencies in the institutions' operational risk management framework, and therefore must be subject to registration, monitoring, assessment and action by the internal control functions, in particular the risk management function.
In this regard, the importance of institutions observing the provisions of the Guidelines on the management of risk associated with information and communication technology and security (EBA/GL/2019/044) of the European Banking Authority is emphasized, in particular in the following paragraphs: 31 points (e) and (f) (management and recertification of access), 31 point (g) (authentication methods), 38 to 40 (security monitoring), 59 and 60 (problem and incident management in matters of information and communication technologies), 91 (crisis communication) and 92 to 98 (management of the relationship with payment service users).
Operational Losses
The occurrence of phishing incidents may result in direct financial charges related to their resolution and may also constitute an indication of potential future loss arising, for example, from the obligation to reimburse clients by initiating legal proceedings by them before the competent bodies. In this sense, institutions must have adequate methods for the recording of operational losses, including estimates for the establishment of provisions considered necessary, which safeguard compliance: (i) with the applicable accounting rules, in compliance with Notice No. 5/2015 of the Bank of Portugal, namely, for this purpose, the provisions of the International Accounting Standard on Provisions, Contingent Liabilities and Contingent Assets; (ii) with reporting obligations for supervisory purposes, namely those provided for in Commission Implementing Regulation (EU) 2021/451 of December 17, 2020; and (iii) with requirements regarding internal capital self-assessment, including in reputational terms, as provided for in Article 115-J of the RGICSF and in Instruction No. 3/2019 of the Bank of Portugal.
3 Directive (EU) 2015/2366 of the European Parliament and of the Council of November 25, 2015 on payment services in the internal market, amending Directives 2002/65/EC, 2009/110/EC and 2013/36/EU and Regulation (EU) No 1093/2010, and repealing Directive 2007/64/EC. 4 Incorporated into the national regulatory framework as disclosed through Circular Letter No. CC/2020/00000029.
Mod. 40000375/T – 01/14
Institutions must register these incidents in their operational risk loss event database, and duly justify the decision whenever they deem not to register an operational loss associated in the case of significant phishing incidents directed at clients.
The Bank of Portugal will continue to intensify its supervisory actions in this matter, in articulation with the European Central Bank in the context of the Single Supervisory Mechanism and in collaboration with other relevant national competent authorities, taking into account the main risks and vulnerabilities for the activity of credit institutions, payment institutions and electronic money institutions and with particular focus on the aforementioned dimensions.