2024-04-30
Added · Updated
The Malta Financial Services Authority issued this circular to establish the notification process for Authorised Persons to comply with Article 45 of the DORA Regulation regarding voluntary participation in Information-Sharing Arrangements. The document mandates that from 17 January 2025, entities within scope must notify the Authority of their membership or cessation of membership in these cyber threat intelligence exchanges, while the requirement remains voluntary for other persons. To facilitate this, the Authority provides a specific notification form and process available on its website for submitting such updates.
Circular Triq l-Imdina, Zone 1 Central Business District, Birkirkara CBD 1010 +356 2144 1155 communications@mfsa.mt www.mfsa.mt Information Sharing Arrangements under Regulation (EU) 2022/2554 on Digital Operational Resilience for the Financial Sector This circular is an update to Circular titled Regulation (EU) 2022/2554 and Amending Directive (EU) 2022/2556 on Digital Operational Resilience for the Financial Sector published on the EU Official Journal published by the Authority in January 2023. Chapter VI Information-sharing Arrangements (Article 45) of the DORA Regulation introduces an obligation on the Authorised Persons within scope (see Article 2 of the DORA Regulation) to notify competent authorities of their voluntary participation in InformationSharing Arrangements. The Malta Financial Services Authority (the ‘Authority’ or ‘MFSA’) is therefore introducing the means for Authorised Persons to fulfil this obligation. Information-Sharing Arrangements are established for the exchange of cyber threat information and intelligence, including indicators of compromise, tactics, techniques, and procedures, cyber security alerts and configuration tools. Membership in InformationSharing Arrangements is an encouraged practice. From the date of publication of this Circular (25 April 2024), any Authorised Person may, on a voluntary basis, notify the Authority of its participation in an Information-Sharing Arrangement upon validation of its membership, or, as applicable, of the cessation of its membership, once it takes effect. Once the DORA Regulation becomes applicable, that is, as of 17 January 2025, such notification will become mandatory for the Authorised Persons within scope, and will remain voluntary for all other Authorised Persons. The Authority is releasing the following material, available on the MFSA website (under Our Work > Supervisory ICT Risk and Cybersecurity):
Circular Triq l-Imdina, Zone 1 Central Business District, Birkirkara CBD 1010 +356 2144 1155 communications@mfsa.mt www.mfsa.mt Authorised Persons may request further information by sending an email to the Supervisory ICT Risk and Cybersecurity function on mirt@mfsa.mt.