Annex I TEMPLATES FOR THE REPORTING OF MAJOR INCIDENTS

LEU2025302EN110120241023EN0001.00016194
Number of fieldData field
General information about the financial entity
1.1Type of submission
1.2Name of the entity submitting the report
1.3Identification code of the entity submitting the report
1.4Type of financial entity affected
1.5Name of the financial entity affected
1.6LEI code of the financial entity affected
1.7Primary contact person name
1.8Primary contact person email
1.9Primary contact person telephone
1.10Second contact person name
1.11Second contact person email
1.12Second contact person telephone
1.13Name of the ultimate parent undertaking
1.14LEI code of the ultimate parent undertaking
1.15Reporting currency
Content of the initial notification
2.1Incident reference code assigned by the financial entity
2.2Date and time of detection of the major ICT-related incident
2.3Date and time of classification of the ICT-related incident as major
2.4Description of the major ICT-related incident
2.5Classification criteria that triggered the incident report
2.6Materiality thresholds for the classification criterion ‘Geographical spread’
2.7Discovery of the major ICT-related incident
2.8Indication whether the major ICT-related incident originates from a third-party provider or another financial entity
2.9Activation of business continuity plan, if activated
2.10Other relevant information
Content of the intermediate report
3.1Incident reference code provided by the competent authority
3.2Date and time of occurrence of the major ICT-related incident
3.3Date and time when services, activities or operations have been recovered
3.4Number of clients affected
3.5Percentage of clients affected
3.6Number of financial counterparts affected
3.7Percentage of financial counterparts affected
3.8Impact on relevant clients or financial counterparts
3.9Number of affected transactions
3.10Percentage of affected transactions
3.11Value of affected transactions
3.12Information on whether the numbers are actual or estimates, or whether there has not been any impact
3.13Reputational impact
3.14Contextual information about the reputational impact
3.15Duration of the major ICT-related incident
3.16Service downtime
3.17Information on whether the numbers for duration and service downtime are actual or estimates.
3.18Types of impact in the Member States
3.19Description of how the major ICT-related incident has an impact in other Member States
3.20Materiality thresholds for the classification criterion ‘Data losses’
3.21Description of the data losses
3.22Classification criterion ‘Critical services affected’
3.23Type of the major ICT-related incident
3.24Other types of incidents
3.25Threats and techniques used by the threat actor
3.26Other types of techniques
3.27Information about affected functional areas and business processes
3.28Affected infrastructure components supporting business processes
3.29Information about affected infrastructure components supporting business processes
3.30Impact on the financial interest of clients
3.31Reporting to other authorities
3.32Specification of ‘other’ authorities
3.33Temporary actions/measures taken or planned to be taken to recover from the incident
3.34Description of any temporary actions and measures taken or planned to be taken to recover from the incident
3.35Indicators of compromise
Content of the final report
4.1High-level classification of root causes of the incident
4.2Detailed classification of root causes of the incident
4.3Additional classification of root causes of the incident
4.4Other types of root cause types
4.5Information about the root causes of the incident
4.6Incident resolution summary
4.7Date and time when the incident root cause was addressed
4.8Date and time when the incident was resolved
4.9Information if the permanent resolution date of the incident differs from the initially planned implementation date
4.10Assessment of risk to critical functions for resolution purposes
4.11Information relevant for resolution authorities
4.12Materiality threshold for the classification criterion ‘Economic impact’
4.13Amount of gross direct and indirect costs and losses
4.14Amount of financial recoveries
4.15Information on whether the non-major incidents have been recurring
4.16Date and time of occurrence of recurring incidents