2024-04-15
Added
The Decision establishes that payment service providers must classify operational or security incidents as major when at least one high‑impact criterion or three low‑impact criteria from the defined table are met, using thresholds such as affected transactions exceeding 10 % of the provider’s regular volume or 31 000 000 Denars, downtime over one hour, or economic impact up to 0.1 % of Tier 1 capital. Providers are required to submit an initial report using template A within three days of the incident being classified as major and to determine the classification within 24 hours of detection, followed by an intermediate report (template B) after recovery or within three business days, and a final report (template C) no later than 20 business days after business recovery, with extensions possible upon request. The decision applies to all licensed payment service providers established before its effective date, obliges compliance no later than 19 February 2024, and renders Item 47 of the Decision on Methodology for bank’s information system security void as of 20 February 2024, with the decision entering into force upon publication in the Official Gazette.
NBRM published 7 documents in the last 30 days — get each new one by email the day it lands.
Pursuant to Article 47 paragraph 1 item 6 of the Law on the National Bank of the Republic of North Macedonia (Official Gazette of the Republic of North Macedonia No. 158/10, 123/12, 43/14, 153/15, 6/16, 83/18 and Official Gazette of the Republic of North Macedonia No. 110/21) and Article 123 paragraph 9 of the Law on Payment Services and Payment Systems (Official Gazette of the Republic of North Macedonia No. 90/22), the National Bank of the Republic of North Macedonia Council has adopted the following DECISION on the guidelines on major operational and security incident classification and reporting
I. GENERAL PROVISIONS
After determining the affected transactions, their total value and their percentage of the usual volume of payment transactions provided by the affected payment service shall be determined. If the payment service provider estimates that the result is not representative, it shall be obliged to use a different representative value calculation and inform the National Bank of the reason for using the chosen approach.
2.2. Payment service users affected- The payment service providers shall
determine the number of payment service users affected by the incident and their percentage in the total number of payment service users. Affected payment service users shall understand all customers that have a contract with the affected payment service provider that grants them payment services and that have suffered or will likely suffer consequences of the incident for more than 1 (one) hour. The service downtime shall be calculated from the moment of incident occurrence to the moment regular activities have been restored at the same quality level of the service which was affected by the incident. In accordance with the previous activities, payment service providers shall estimate the number of users that would use the payment service during the incident. If the case when the payment service provider is part of a group, offers or uses operational services of other entities, it shall be obliged to take into consideration only its own users of payment services. Payment service providers shall take as the total number of payment service users the aggregated figure of domestic and cross-border payment service users contractually bound to them at the time of the incident and with access to the affected payment service, regardless of their size and their active or passive status.
2.3 Network or information system security breach- The payment service
providers shall determine whether certain malicious activity has jeopardized the availability, authenticity, integrity and confidentiality of the network or information systems (including data) of payment-related services.
2.4 Service downtime- The payment service providers shall determine the time
period in which the initiating and/or the payment service provision or the access to payment account is not available to the payment service user or the time in which the payment order could not be executed. The service downtime shall be counted from the moment the downtime starts, considering the working hours of the payment service providers. If the payment service provider is unable to determine the moment of service downtime, it is obliged to calculate the downtime period from the moment it was detected.
2.5 Economic impact- The payment service providers shall determine the total
financial costs which are directly or indirectly connected to the incident, as well as their relative value in relation to the payment service provider's capital. Financial loss denote the lost funds or property, expenditures for hardware or software replacement, other expenses related to forensics or additional
measures, fees due to nonperformance of contractual obligations, penalties, damages to third parties and lost income. Payment service providers shall take into consideration only the indirect losses that are already known or are very likely to occur.
2.6 High level of internal escalation- The payment service providers shall
determine whether or not the members of the management bodies have been or will be informed about the incident. The payment service providers shall also determine whether, due to the impact of the incident on the payment services, a crisis mode is likely to be triggered in accordance with the business continuity plan.
2.7 Other payment service providers and infrastructures potentially
affected - The payment service providers shall determine the possible impact of the incident on the system i.e. its potential to replicate at other payment service provider. For such purpose, it is assessed whether the incident’s impact on the financial system has been replicated at other payment service providers, i.e. whether it could affect the smooth functioning of the financial system infrastructure.
2.8 Reputational impact- Payment service providers shall determine negative
impact of the incident on the customers’ trust in the payment service provider and the loss of trust in both payment service and payment system. For that purpose, the payment service providers shall consider the following:
Whether there are complaints of adverse effect from the incident by payment service users and/or other payment service providers; whether the incident had a visible impact on the payment services due to which it is likely to receive media coverage (traditional and modern channels-social networks); whether contractual obligations have been breached due to which legal consequences to the payment service provider are likely to occur; whether regulatory obligations have been breached and whether it would lead to undertaking regulatory measures against the payment service provider or a similar incident has occurred before.
3. The payment service providers shall assess an incident by determining, for each
classification criteria if the relevant thresholds are or will probably be reached (listed in
Table 1 of this item), before the incident is resolved.
Criteria Low impact High impact
Affected transactions (> 10% of the payment service provider’s regular level of transactions (in terms of number of transactions) and Service downtime > 1 hour *) or (> 31 000 000 Denars (> 25% of the payment service provider’s regular level of transactions (in terms of number of transactions) or (> 310 000 000 Denars)
and incident duration > 1 hour *)
Payment services users affected
( > 5.000 and incident duration > 1 hour *) or (>10% of the payment service provider’s payment service users and incident duration > 1 hour *) (> 50 000) or (>25% of the payment service provider’s payment service users ) Service downtime > 2 hours Not applicable Network or information system security impairment Yes Not applicable Economic impact Not applicable Direct damage:
Maximum of: (0,1% of
Tier 1 capital; Denar
12.400.000 million)
or
Indirect damage:
Denar 310,000,000
million
Enhanced level of internal communication
Yes Yes, and activation of crisis situation in accordance with the business continuity plan Possibility for other payment service providers and infrastructures to be affected Yes Not applicable Reputational impact Yes Not applicable *The service downtime threshold longer than 1 (one) hour refers to operational incidents that affect the initiation and/or processing of payment transactions.
Payment service providers shall resort to estimations if they do not have actual data to
support their judgments of whether or not a given threshold is or will probably be reached before the incident is resolved. The estimate referred to in paragraph 1 of this item of this Decision could be used during the initial phase of the incident.
Payment service providers shall carry out this assessment on a continuous basis during
the lifetime of the incident, to identify classification status change, either upwards (from non-major to major) or downwards (from major to non-major). The National Bank shall be immediately informed of each status reclassification from major to non-major incident.
III. NOTIFICATION OF MAJOR OPERATIONAL AND SECURITY INCIDENT TO THE
NATIONAL BANK
Payment service providers shall prepare and submit a major operational and security
incident Report to the National Bank, prescribed in the Annex 1 of this Decision. Payment service providers shall submit an initial, intermediate and final report for each incident, using the sections A, B or C o the template prescribed in Annex 1 of this Decision. Payment service providers are considered to have duly submitted data if they:
If the regular activities fail to recover, the payment service provider shall submit an intermediate report within three business days upon the initial report submission.
14. The intermediate report shall include a detailed description of the incident and its effects
by filling out the template B. In case actual data are not available, payment service providers shall make use of estimations when filling out the required template sections.
15. Payment service providers shall update the information provided in templates A and B, if
significant changes occurred since the last intermediate report.
16. Should business be back to normal within three days since the incident was classified as
major, payment service provider shall submit both initial and intermediate report (templates A and B) to the National Bank within three days from item 11 of this Decision. Final report
17. Payment service providers shall submit a final report when the root cause analysis has
taken place by filling out the template C.
18. Payment service providers shall submit the final report to the National Bank no later than
20 business days from the business recovery date.
Should payment service providers fail to detect the root cause problem or have no clear data on updates of previous reports, they shall require an extension of the deadline from the National Bank to submit the final report from paragraph 1 of this item. In the requirement referred to in paragraph 2 of this item of the Decision, payment service providers shall state the reasons for the delay, as well as an estimated date for the final report.
19. Payment service providers shall inform the National Bank in their final report of:
Payment service providers that have been established up to the date this Decision becomes applicable and hold a founding and operating license shall apply the provision referred to in item 47 of the Decision on Methodology for bank’s information system security (Official
Gazette of the Republic of Macedonia “No. 78/18) until the date of harmonizing its operations with the requirements of this Decision, as of 19 February 2024.
22. Item 47 of the Decision on the Methodology for bank’s information system security (Official
Gazette of the Republic of Macedonia No. 78/ 18) shall become void as of 20 February 2024.
23. This Decision shall enter into force on the date of its publication in the Official Gazette of
the Republic of North Macedonia.
D no. 02-15/XXII-9/2022
28 December 2022
Skopje
Anita Angelovska Bezhoska
Governor and Chairman of the Council of the
National Bank of the
Republic of North Macedonia
Annex1:
Template A (Initial report)
Template B (Intermediate report)
Template C (Final report)
Read the rest free
Source: National Bank of the Republic of North Macedonia — original document · Summary generated with machine assistance and reviewed before publication; the authoritative text is the regulator's original document. How RegAlert works
More like this from NBRM
NBRM published 7 documents in the last 30 days. We email you each new one the day it's published.