My bookmarksSign up free

Commission Delegated Regulation (EU) 2017/589 Article 18

Commission Delegated Regulation (EU) 2017/589 Article 18

Security and limits to access

Article 18

1.   An investment firm shall implement an IT strategy with defined objectives and measures which: (a) is in compliance with the business and risk strategy of the investment firm and is adapted to its operational activities and the risks to which it is exposed; (b) is based on a reliable IT organisation, including service, production, and development; (c) complies with an effective IT security management. 2.   An investment firm shall set up and maintain appropriate arrangements for physical and electronic security that minimise the risks of attacks against its information systems and that includes effective identity and access management. Those arrangements shall ensure the confidentiality, integrity, authenticity, and availability of data and the reliability and robustness of the investment firm's information systems. 3.   An investment firm shall promptly inform the competent authority of any material breaches of its physical and electronic security measures. It shall provide an incident report to the competent authority, indicating the nature of the incident, the measures taken following the incident and the initiatives taken to avoid similar incidents from recurring. 4.   An investment firm shall annually undertake penetration tests and vulnerability scans to simulate cyber-attacks. 5.   An investment firm shall ensure that it is able to identify all persons who have critical user access rights to its IT systems. The investment firm shall restrict the number of such persons and shall monitor their access to IT systems to ensure traceability at all times.

Read the full instrument → · Read this in context: SECTION 3 — Means to ensure resilience →

Other provisions in SECTION 3 — Means to ensure resilience

Compiled from an official source version. Later amendments or repeals may not be reflected; the official text prevails. · Read the official text ↗ · Data as of 2026-07-04

CitationArticle 18 of Commission Delegated Regulation (EU) 2017/589 (LawPlayer, data as of 2026-07-04)

© European Union, https://eur-lex.europa.eu, 1998-2026. Reuse authorised under Commission Decision 2011/833/EU, provided the source is acknowledged.

What to look at next