2023-09-23 | 24008Added · Updated
Regulated financial institutions must alert the Central Bank of any cybersecurity incident within 24 hours of awareness and submit a completed reporting template within 72 hours. Reportable incidents are defined by material impacts on the financial system, critical infrastructure, data confidentiality, or high internal severity levels. Companies are required to provide regular updates until the incident is resolved and submit a post-incident review upon closure. Failure to comply with these notification timelines and requirements may result in enhanced supervisory oversight or compliance directions.