Content of the voluntary notification of significant cyber threats
Article 6
The content of the voluntary notification in relation to significant cyber threats as referred to in Article 19(2) of Regulation (EU) 2022/2554 shall cover all of the following: (a) general information about the notifying financial entity as set out in Article 1; (b) the date and time of detection of the significant cyber threat and any other relevant timestamps related to the significant cyber threat; (c) a description of the significant cyber threat; (d) information about the potential impact of the significant cyber threat on the financial entity, its clients, or financial counterparts; (e) the classification criteria that would have triggered a major incident report laid down in Articles 1 to 8 of Delegated Regulation (EU) 2024/1772 if the cyber threat had materialised; (f) information about the status of the significant cyber threat and any changes in the threat activity; (g) where applicable, a description of the actions taken by the financial entity to prevent the materialisation of the significant cyber threats; (h) information about any notification of the significant cyber threat to other financial entities or authorities; (i) where applicable, information on indicators of compromise; (j) where available, any other relevant information.