Article 10
High materiality thresholds for determining significant cyber threats
For the purposes of Article 18(2) of Regulation (EU) 2022/2554, a cyber threat shall be considered significant where all of the following conditions are fulfilled:
(a) |
the cyber threat, if materialised, could affect or could have affected critical or important functions of the financial entity, or could affect other financial entities, third-party providers, clients or financial counterparts, based on information available to the financial entity; |
(b) |
the cyber threat has a high probability of materialisation at the financial entity or at other financial entities, taking into account at least the following elements:
|
(c) |
the cyber threat could, if materialised, meet any of the following:
|
Where, depending on the type of cyber threat and available information, the financial entity concludes that the materiality thresholds set out in Article 9(2), (3), (5) and (6) could be met, those thresholds may also be considered.