2024-07-17
Added
The European Supervisory Authorities draft Regulatory Technical Standards to specify criteria for identifying financial entities required to perform threat-led penetration tests, including revised selection criteria for insurance and reinsurance undertakings and increased quantitative thresholds for payment and electronic money institutions. The standards mandate testing methodologies aligned with the TIBER-EU framework, requiring mandatory purple teaming during the closure phase and permitting the use of internal testers under specific conditions. It establishes requirements for testers, threat intelligence providers, and supervisory cooperation, with an expected application date of 17 January 2025 following European Commission adoption.
EBA published 1 document in the last 30 days — get each new one by email the day it lands.
Final Report
Draft Regulatory Technical Standards specifying elements related to threat led penetration tests under Article 26(11) of Regulation (EU) 2022/2554 JC 2024 29 17 July 2024
Contents
Executive Summary 2
Background and rationale 4
Draft Regulatory Technical Standards 20
Impact assessment 61
Feedback from the ESAs’ Stakeholders Groups 68
Feedback on the public consultation 77
Executive Summary
Reasons for publication
Regulation (EU) 2022/2554 of the European Parliament and of the Council of 14 December
2022 on digital operational resilience for the financial sector and amending Regulations (EC) No 1060/2009, (EU) No 648/2012, (EU) No 600/2014, (EU) No 909/2014 and (EU) 2016/1011 (hereinafter ‘DORA’) under its Article 26(11), tasks the ESAs, ‘in agreement with the ECB’ to develop draft regulatory technical standards (‘RTS’) ‘in accordance with the TIBER-EU framework’ to specify further the criteria used for identifying financial entities required to perform threat-led penetration testing (TLPT), the requirements and standards governing the use of internal testers, the requirements in relation to scope, testing methodology and approach for each phase of the testing, results, closure and remediation stages and the type of supervisory and other relevant cooperation needed for the implementation of TLPT and for the facilitation of mutual recognition. Section 2 of this report presents in detail the mandate and background to the final draft RTS which is included in Section 3.
This report follows a consultation paper (CP) which presented a first draft of the RTS and 32
questions and was open to comments from the public from 8 December 2023 to 4 March 2024.
A total of 111 responses were received to the public consultation, covering all sectors. The
ESAs have also received input from the ESAs’ Stakeholders Groups.
Respondents appeared to be very concerned with the requirements applying to TLPT providers
(both testers and threat intelligence providers), which were mostly deemed too strict considering the limited availability of these providers on the existing market. The proposed testing process has also been massively commented, including many requests for more clarity, in particular in respect of TLPTs involving several financial entities and an ICT service provider (in case of pooled testing or joint test), and for more time in particular for the closure phase. The feedback received is presented in detail in Sections 5 and 6.
The ESAs assessed the concerns raised to decide which changes, if any, should be made to the
draft RTS. In the light of the comments received, the ESAs agreed with some of the proposals and their underlying arguments and have introduced changes to the draft RTS.
The main changes relate to: (i) the criteria to be used to select insurance and reinsurance
undertakings required to perform TLPT by default, which have been revised to allow for more predictability for market stakeholders (ii) TLPTs involving several financial entities and/or ICT service providers (intragroup or third parties) in pooled TLPTs and joint TLPTs, with clarifications of the related processes which also require extended cooperation between the
Read the rest free, and get an email when EBA publishes again
Source: European Banking Authority — original document · Summary generated with machine assistance and reviewed before publication; the authoritative text is the regulator's original document. How RegAlert works
More like this from EBA
EBA published 1 document in the last 30 days. We email you each new one the day it's published.