IVASS letter to the market - Reporting of serious cyber incidents and cyber threats under the EU DORA Regulation

Category
Undertakings, Intermediaries
Description

IVASS has disclosed the operational procedures to be followed by insurance companies and larger insurance, reinsurance and ancillary insurance intermediaries to promptly report IVASS of serious cyber incidents and, on a voluntary basis, cyber threats under the EU DORA Regulation (Reg. EU 2022/2554 - Digital Operational Resilience Act).

The DORA Regulation, applicable as of January 17, 2025, aims to achieve adequate resilience of operators and the European financial system by, among other things, identifying measures for the prevention, response and recovery of operations in the event of an attack or incident.

issue date
14 February 2025