RISKORIA ADVISING & PROFESSIONAL SERVICES D.O.O. · ZAGREB+385 97 737 1345INFO@RISKORIA.EU

Banking and finance

For financial entities the DORA regulation is lex specialis and takes precedence for incident reporting, so the first question is always which regime applies to what.

What the Act requires of this sector

Banking and financial market infrastructure are two Annex I sectors. For banking, Annex III names the Croatian National Bank (HNB), and for financial market infrastructure the Croatian Financial Services Supervisory Agency (HANFA), as the bodies competent for sectoral legislation.

The competent CSIRT for both sectors is the national CERT, not the national cyber security centre as for most other sectors. That is the difference most easily overlooked in practice, and it changes where an incident report goes.

Alongside the Cybersecurity Act, finance is also covered by the regulation on digital operational resilience for the financial sector. The first task is to separate what falls under which, because much of the requirements overlap but the deadlines and recipients do not.

Where this sector usually gets stuck

Two regimes for the same incidentWithout a clear decision on who notifies whom, hours are lost.
Critical third party providersContractual clauses and audit rights are often missing.
Resilience testingThe requirements are stricter than most expect.

What we do for you

01Separating obligations under the law and under DORA02An incident reporting procedure with clear addressees03Review of third party contracts04An ICT risk register05Preparing the evidence file

Who from the sector falls in scope

WHOCATEGORYNOTE
Credit institutionsEssential or importantAnnex III names the Croatian National Bank for sectoral legislation; the CSIRT is the national CERT
Trading venue operators and central counterpartiesEssential or importantAnnex III names the Croatian Financial Services Supervisory Agency
Central securities depositoriesEssential or importantPart of financial market infrastructure; the Croatian Financial Services Supervisory Agency is competent

The category is set by the competent authority and the level of measures by the national risk assessment; both are explained in the overview of the Act.

CASE FROM PRACTICE · UNITED STATES, NOVEMBER 2023

Ransomware halted clearing in the Treasury market

The US arm of a large international bank lost its clearing systems to a ransomware attack. For a time trades were settled by a workaround route, and the unit cut its network off from the rest of the group. Supervisors did not ask first whether a ransom had been paid; they asked how long it took to establish the scope and notify counterparties.

SOURCE: Public incident reporting and statements by US supervisory authorities, November 2023.

Frequently asked questions

The questions financial entities ask first, mostly about separating the Act from DORA.

Does the law or DORA apply to us?

Both, but for financial entities DORA is lex specialis and takes precedence on ICT risk management and incident reporting. The requirements overlap across much of their scope, but the deadlines, forms and recipients are not the same. The first step is a written delimitation requirement by requirement, so that one record serves both wherever possible and both versions are kept where they diverge.

Who do we report an incident to?

For banking and financial market infrastructure the CSIRT is the national CERT. Obligations to the central bank or the financial services supervisor run in parallel, as does notification to the data protection authority for personal data breaches.

What is required of contracts with service providers?

Security clauses, a right of audit and inspection, an obligation to report incidents, an exit strategy and a list of subcontractors. A register of ICT service contracts is a requirement in its own right.

How demanding is resilience testing?

More demanding than most expect. Alongside regular testing, some entities also face threat led penetration testing.

Do you perform the audit?

No. Riskoria prepares and leads the compliance work; the formal audit is performed by a certified managed security service provider.

Who is our competent authority?

For banking, Annex III of the Act names the Croatian National Bank, and for financial market infrastructure the Croatian Financial Services Supervisory Agency, as the bodies competent for sectoral legislation.

Related pages

The pages that set out in full what finance has to show in measures and evidence.

Let us separate the two regimes before an incident.

Half an hour, no obligation. We separate what falls under the Act and what falls under DORA.

Book a callINFO@RISKORIA.EU · +385 97 737 1345