Source: OJ L 333, 27.12.2022, p. 1–79

Current language: FR

Article 14 Communication


Summary What does Article 14 of the DORA regulation say?

This article sits within the broader ICT risk management framework established under Article 6 and focuses specifically on communication obligations.

It requires financial entities to have crisis communication plans in place for disclosing major ICT-related incidents or vulnerabilities to clients, counterparts, and the public.

Beyond external disclosure, it also addresses internal communication, requiring separate policies that distinguish between staff who are actively involved in managing ICT risk and those who simply need to be kept informed.

Finally, it mandates that at least one designated person within the entity is responsible for executing the communication strategy and handling public and media relations during ICT-related incidents.

Important points:

  • Have crisis communication plans in place for the responsible disclosure of major ICT-related incidents or vulnerabilities to clients, counterparts, and the public.
  • Implement separate communication policies for internal staff, distinguishing between those managing ICT risk and those who only need to be informed.
  • At least one person within the financial entity must be designated to implement the ICT incident communication strategy and handle public and media functions.

Springlex's summary of the article, a reading aid, not a substitute for the legal text.

    1. Aux fins du cadre de gestion du risque lié aux TIC visé à l’article 6, paragraphe 1, les entités financières mettent en place des plans de communication en situation de crise qui favorisent une divulgation responsable, au minimum, des incidents majeurs liés aux TIC ou des vulnérabilités majeures aux clients et aux contreparties ainsi qu’au public, le cas échéant.

    1. Aux fins du cadre de gestion du risque lié aux TIC, les entités financières mettent en œuvre des politiques de communication à l’intention des membres du personnel interne et des parties prenantes externes. Les politiques de communication à l’intention du personnel tiennent compte de la nécessité d’établir une distinction entre le personnel participant à la gestion du risque lié aux TIC, en particulier le personnel responsable de la réponse et du rétablissement, et le personnel qui doit être informé.

    1. Au moins une personne au sein de l’entité financière est chargée de mettre en œuvre la stratégie de communication concernant les incidents liés aux TIC et remplit la fonction d’information du public et des médias à cette fin.

We're continuously improving our platform to serve you better.

Your feedback matters! Let us know how we can improve.

Found a bug?

Springflod is a Swedish boutique consultancy firm specialising in cyber security within the financial services sector.

We offer professional services concerning information security governance, risk and compliance.

Crafted with ❤️ by Springflod