2024-04-30

Added · Updated

Information Sharing Arrangements under Regulation (EU) 2022/2554 on Digital Operational Resilience for the Financial Sector

The Malta Financial Services Authority issued this circular to establish the notification process for Authorised Persons to comply with Article 45 of the DORA Regulation regarding voluntary participation in Information-Sharing Arrangements. The document mandates that from 17 January 2025, entities within scope must notify the Authority of their membership or cessation of membership in these cyber threat intelligence exchanges, while the requirement remains voluntary for other persons. To facilitate this, the Authority provides a specific notification form and process available on its website for submitting such updates.

Malta Financial Services Authority logo

Malta

Malta Financial Services Authority

Click to view thumbnail

Circular Triq l-Imdina, Zone 1 Central Business District, Birkirkara CBD 1010 +356 2144 1155 communications@mfsa.mt www.mfsa.mt Information Sharing Arrangements under Regulation (EU) 2022/2554 on Digital Operational Resilience for the Financial Sector This circular is an update to Circular titled Regulation (EU) 2022/2554 and Amending Directive (EU) 2022/2556 on Digital Operational Resilience for the Financial Sector published on the EU Official Journal published by the Authority in January 2023. Chapter VI Information-sharing Arrangements (Article 45) of the DORA Regulation introduces an obligation on the Authorised Persons within scope (see Article 2 of the DORA Regulation) to notify competent authorities of their voluntary participation in Information￾Sharing Arrangements. The Malta Financial Services Authority (the ‘Authority’ or ‘MFSA’) is therefore introducing the means for Authorised Persons to fulfil this obligation. Information-Sharing Arrangements are established for the exchange of cyber threat information and intelligence, including indicators of compromise, tactics, techniques, and procedures, cyber security alerts and configuration tools. Membership in Information￾Sharing Arrangements is an encouraged practice. From the date of publication of this Circular (25 April 2024), any Authorised Person may, on a voluntary basis, notify the Authority of its participation in an Information-Sharing Arrangement upon validation of its membership, or, as applicable, of the cessation of its membership, once it takes effect. Once the DORA Regulation becomes applicable, that is, as of 17 January 2025, such notification will become mandatory for the Authorised Persons within scope, and will remain voluntary for all other Authorised Persons. The Authority is releasing the following material, available on the MFSA website (under Our Work > Supervisory ICT Risk and Cybersecurity):

  1. An Information-Sharing Arrangements Notification Process, establishing the process to notify the participation in, or the cessation of membership from, an Information-Sharing Arrangement;
  2. The Information-Sharing Arrangements Notification Form, to be sent by Authorised Persons to the Authority to notify their participation in Information-Sharing Arrangements upon validation of their membership, or, as applicable, of the cessation of their membership, once it takes effect. 30 April 2024

Circular Triq l-Imdina, Zone 1 Central Business District, Birkirkara CBD 1010 +356 2144 1155 communications@mfsa.mt www.mfsa.mt Authorised Persons may request further information by sending an email to the Supervisory ICT Risk and Cybersecurity function on mirt@mfsa.mt.