News

Cyprus financial firms face new cyber incident reporting rules

Cyprus Mail · 2026-09-08

AI SUMMARY

• What happened: The Cyprus Securities and Exchange Commission (CySEC) introduced new guidance requiring financial firms to calculate and report annual costs and losses from major information and communications technology (ICT) incidents. • Why it matters: This initiative aims to enhance accountability and transparency in the financial sector, addressing the growing need for improved cybersecurity measures amid rising cyber threats. • What to watch next: Firms will need to comply with these reporting requirements by June 30 each year, with special deadlines for incidents occurring in 2025, as they adapt to the new regulations and review European guidelines for accurate reporting.

**Title: Cyprus Financial Firms Face New Cyber Incident Reporting Rules**

The Cyprus Securities and Exchange Commission (CySEC) has introduced new guidance aimed at enhancing the accountability of financial firms regarding major information and communications technology (ICT) incidents. This directive, released on Tuesday, mandates that all financial entities under CySEC’s supervision calculate and report the annual costs and losses associated with significant ICT-related incidents.

The new requirements encompass a wide array of financial entities regulated in Cyprus, including investment firms, crypto-asset service providers, issuers of asset-referenced tokens, central securities depositories, central counterparties, trading venues, alternative investment fund managers, management companies, and crowdfunding service providers. This broad scope underscores the importance of cybersecurity across various sectors within the financial landscape.

The impetus for these new guidelines stems from the adoption of joint recommendations by Europe’s three financial supervisory authorities, which outline how firms should assess the combined annual financial impact of major ICT incidents. CySEC's guidance aims to clarify how regulated entities should complete the reporting template mandated by the EU’s Digital Operational Resilience Act (DORA).

Under the new rules, financial entities that experience major ICT-related incidents during the reporting period are required to calculate the total costs and losses incurred from those incidents. This calculation is designed to encompass all financial repercussions stemming from significant ICT incidents within the selected reference year. Entities must decide whether to use either the completed calendar year or the finalized accounting year for their reference period, and this choice must be explicitly stated in their reports to ensure consistency in future submissions.

CySEC has established a standard timeline for these reports, which must be submitted by June 30 each year following the reference year in which the incidents occurred. Notably, the requirements apply solely to firms that have encountered major ICT-related incidents during the specified reporting period.

To accommodate the unique circumstances of the financial sector, CySEC has introduced a special deadline for incidents that occur in 2025. Firms that experience major ICT-related incidents in that year must submit their reports to CySEC by September 30, 2026.

For clarity, CySEC provided examples illustrating how the reporting periods and deadlines will function. For instance, if a financial entity experiences two major ICT-related incidents on January 10, 2026, and March 30, 2026, and opts for the calendar year as its reference period, both incidents would be reported together. This report would then need to be submitted to CySEC by June 30, 2027. Conversely, if a firm experiences a significant incident on December 12, 2025, it would include this incident in its report due by September 30, 2026.

These new reporting obligations are part of broader European initiatives aimed at bolstering the resilience of the financial sector against disruptions caused by cyber incidents, technological failures, and other ICT-related challenges. For Cyprus, the implementation of these rules introduces additional reporting responsibilities for firms operating within the national financial regulatory framework, with CySEC serving as the primary authority for receiving and processing this critical information.

The introduction of these guidelines reflects a growing recognition of the need for enhanced cybersecurity measures in the financial industry, particularly as the frequency and sophistication of cyber threats continue to rise. By requiring financial firms to systematically assess and report the financial impact of ICT-related incidents, CySEC aims to foster a culture of transparency and accountability, ultimately contributing to a more secure financial environment in Cyprus.

As firms prepare to comply with these new regulations, they are encouraged to review the joint European guidelines thoroughly to ensure accurate reporting. The emphasis on consistent reporting practices is expected to facilitate better understanding and management of risks associated with ICT incidents, thereby strengthening the overall resilience of the financial sector in Cyprus.

In conclusion, the new reporting rules set forth by CySEC represent a significant step towards enhancing the operational resilience of financial firms in Cyprus, aligning with broader European efforts to safeguard the financial system against the increasing threats posed by cyber incidents.

Source: Cyprus Mail
RELATED NEWS

More Stories

All News
News

Cyprus National Guard chief calls for constant readiness - UA.NEWS

• What happened: The chief of the Cyprus National Guard has called for a state of constant readiness among military forces in response to ongoing regional tensi...

News

Could Cyprus become a flashpoint between Israel and Turkey?

• What happened: Israel and Greece signed a landmark €3.035 billion defense agreement, enhancing Greece's air defense capabilities with advanced Israeli te...

News

National Guard chief calls for constant readiness

• What happened: National Guard chief Lieutenant General Emmanouel Theodorou called for constant operational readiness of the National Guard in response to ongo...

News

British base police appeal for witnesses after fatal highway crash

• What happened: A 76-year-old man, Demetris Potamitis, was killed in a traffic accident on the Limassol-Paphos highway after stopping to retrieve a refrigerato...

News

House speaker condemns parking incident at Parliament

• What happened: House Speaker Annita Demetriou condemned a driver who parked in a disabled spot at Parliament, obstructing access for a person with a disabilit...

News

Cyprus records one of its rainiest summers in decades in 2026

• What happened: Cyprus experienced one of its rainiest summers in decades, with rainfall reaching 327% of the seasonal norm, significantly impacting the island...