**Title: Cyprus Financial Firms Face New Cyber Incident Reporting Rules**
The Cyprus Securities and Exchange Commission (CySEC) has introduced new guidance aimed at enhancing the accountability of financial firms regarding major information and communications technology (ICT) incidents. This directive, released on Tuesday, mandates that all financial entities under CySEC’s supervision calculate and report the annual costs and losses associated with significant ICT-related incidents.
The new requirements encompass a wide array of financial entities regulated in Cyprus, including investment firms, crypto-asset service providers, issuers of asset-referenced tokens, central securities depositories, central counterparties, trading venues, alternative investment fund managers, management companies, and crowdfunding service providers. This broad scope underscores the importance of cybersecurity across various sectors within the financial landscape.
The impetus for these new guidelines stems from the adoption of joint recommendations by Europe’s three financial supervisory authorities, which outline how firms should assess the combined annual financial impact of major ICT incidents. CySEC's guidance aims to clarify how regulated entities should complete the reporting template mandated by the EU’s Digital Operational Resilience Act (DORA).
Under the new rules, financial entities that experience major ICT-related incidents during the reporting period are required to calculate the total costs and losses incurred from those incidents. This calculation is designed to encompass all financial repercussions stemming from significant ICT incidents within the selected reference year. Entities must decide whether to use either the completed calendar year or the finalized accounting year for their reference period, and this choice must be explicitly stated in their reports to ensure consistency in future submissions.
CySEC has established a standard timeline for these reports, which must be submitted by June 30 each year following the reference year in which the incidents occurred. Notably, the requirements apply solely to firms that have encountered major ICT-related incidents during the specified reporting period.
To accommodate the unique circumstances of the financial sector, CySEC has introduced a special deadline for incidents that occur in 2025. Firms that experience major ICT-related incidents in that year must submit their reports to CySEC by September 30, 2026.
For clarity, CySEC provided examples illustrating how the reporting periods and deadlines will function. For instance, if a financial entity experiences two major ICT-related incidents on January 10, 2026, and March 30, 2026, and opts for the calendar year as its reference period, both incidents would be reported together. This report would then need to be submitted to CySEC by June 30, 2027. Conversely, if a firm experiences a significant incident on December 12, 2025, it would include this incident in its report due by September 30, 2026.
These new reporting obligations are part of broader European initiatives aimed at bolstering the resilience of the financial sector against disruptions caused by cyber incidents, technological failures, and other ICT-related challenges. For Cyprus, the implementation of these rules introduces additional reporting responsibilities for firms operating within the national financial regulatory framework, with CySEC serving as the primary authority for receiving and processing this critical information.
The introduction of these guidelines reflects a growing recognition of the need for enhanced cybersecurity measures in the financial industry, particularly as the frequency and sophistication of cyber threats continue to rise. By requiring financial firms to systematically assess and report the financial impact of ICT-related incidents, CySEC aims to foster a culture of transparency and accountability, ultimately contributing to a more secure financial environment in Cyprus.
As firms prepare to comply with these new regulations, they are encouraged to review the joint European guidelines thoroughly to ensure accurate reporting. The emphasis on consistent reporting practices is expected to facilitate better understanding and management of risks associated with ICT incidents, thereby strengthening the overall resilience of the financial sector in Cyprus.
In conclusion, the new reporting rules set forth by CySEC represent a significant step towards enhancing the operational resilience of financial firms in Cyprus, aligning with broader European efforts to safeguard the financial system against the increasing threats posed by cyber incidents.