ICT incident reporting

  • CSSF Circular 26/915: DORA Circulars Re-Mapped for Third-Country Branches

    On 27 August 2026 the CSSF published Circular 26/915, and it applies with immediate effect. Circular CSSF 26/915 updates the Luxembourg ICT and outsourcing circular framework following the European Commission position on DORA’s applicability to third-country branches. It removes the TCB categories within the CSSF’s remit from the relevant pre-DORA circular provisions and maps them…

  • DORA for Third-Country Branches in Luxembourg: Circular CSSF 26/915

    On 27 August 2026 the CSSF issued Circular CSSF 26/915, applicable with immediate effect, to bring specified third-country branches into the CSSF circular framework for DORA. For Luxembourg purposes, the governing scope is the branch perimeter set out in Circular CSSF 26/915 and in each amended circular; the change is not a blanket head-office-only test…

  • ECB AI Cybersecurity Letter: The 31 October 2026 JST Action Plan

    On 7 July 2026, the Chair of the ECB Supervisory Board, Claudia Buch, wrote to the CEO of every significant institution under a letter numbered SSM-2026-0301 and titled “Addressing AI-enabled cybersecurity threats”. The ECB AI cybersecurity letter does one operationally concrete thing behind its strategic language: it gives each directly supervised bank until 31 October…

  • DORA ICT Incident Reporting: What the ESAs First Annual Report Reveals

    If your firm filed a major incident under DORA in 2025, that report has now been counted. On 3 June 2026 the three European Supervisory Authorities published their first annual report on major ICT-related incidents, putting a hard number on what used to be guesswork: how many major incidents the EU financial sector reports, where…