Cyber threat information sharing under DORA Article 45

Cyber threat information sharing under DORA – from regulatory requirement to practical approach

DORA Article 45 enables – but does not require – cyber threat information sharing between financial firms. How to make it a practical approach that creates value.

Summary: Cyber threat information sharing under DORA Article 45 is voluntary – but handled well it can help you detect threats earlier and prioritise the right actions. Here we move from regulatory requirement to a practical, proportionate approach for assessment, sharing, reporting and follow-up.

Cyber threat information sharing is one of the parts of DORA that easily ends up overlooked. Much of the focus is often on incident reporting, third-party risk, testing and governance. But handled well, cyber threat information can make a big difference.

A warning about a vulnerability, an indicator of compromise or a lesson from an incident at another organisation can help you detect threats earlier, prioritise the right measures and reduce the consequences if something does happen.

At the same time, information sharing is not just a technical question. It is also about responsibility, confidentiality, data protection, competition law, incident processes and how the information is actually used in the business.

What does DORA say?

DORA Article 45 gives financial firms the possibility to exchange cyber threat information and intelligence with one another. That can include, for example:

  • indicators of compromise
  • attackers’ methods and tactics
  • cybersecurity alerts
  • information about vulnerabilities
  • configuration advice and protective measures
  • lessons from incidents

The purpose should be to strengthen digital operational resilience. The information sharing should take place within trusted communities and through arrangements that protect the sensitive nature of the information.

That is important. Cyber threat information can be highly valuable, but it can also contain details that should not be shared freely.

Is information sharing mandatory?

No. DORA does not require all financial firms to take part in an information-sharing network.

The rule says that financial firms may exchange cyber threat information, under certain conditions. That means the organisation needs to make a deliberate assessment: are there relevant forums or networks, what value can they provide and what risks or requirements come with participation?

For some organisations, participation can be valuable. For others, it may be more relevant to first strengthen the internal handling of cyber threat information, incidents, vulnerabilities and threat monitoring.

What matters is that the question is not handled by routine. A decision to participate, wait or abstain should be based on an actual assessment.

What needs to be assessed before participating?

Before the organisation joins an information-sharing arrangement, a few questions should be answered:

  • What type of information is shared?
  • Which organisations take part?
  • How are members and permissions controlled?
  • What rules apply to onward sharing?
  • Are there confidentiality, data-protection or competition-law constraints?
  • Does participation require specific resources or technical platforms?

It also needs to be clear who internally is responsible for the participation. It is not enough for one person to get access to a forum. The organisation needs to know how the information is received, assessed and passed on to the right process.

If a firm chooses to take part in such an arrangement, the competent authority must be notified once the membership has been validated. The authority must also be notified when participation ends. For firms under Finansinspektionen’s (the Swedish FSA’s) supervision, this therefore needs to be tied to the regular process for authority contact.

Information sharing only creates value if the information is acted on

The big practical risk is that the information sharing becomes passive.

The organisation joins a network, gets access to alerts and indicators, but the information never reaches the right function or does not lead to any assessment.

A vulnerability alert may need to go to patch or vulnerability management. An indicator of compromise may need to be checked in logs or security monitoring. Information about an ongoing attack campaign may need to lead to enhanced monitoring, contact with a supplier or an updated risk assessment.

A simple way of working can be:

  1. The information is received.
  2. Relevance and reliability are assessed.
  3. Any sharing marking or confidentiality is checked.
  4. The information is sent to the right function, for example IT, the SOC, incident handling, risk or the supplier owner.
  5. Measures are handled in existing processes.
  6. Significant decisions and measures are documented.

Not all information needs to lead to a new activity. But information relevant to the organisation’s risk picture, systems, suppliers or incident capability needs to be able to be acted on.

Not all information should be shared

DORA does not mean the organisation should share all the information it has about cyber threats or incidents.

Before information is shared externally, the organisation needs to assess what may actually be shared, and with whom.

That can involve, for example:

  • whether the information is reliable enough
  • whether the network’s rules allow onward sharing
  • whether details could identify customers, employees or suppliers
  • whether the material contains trade secrets
  • whether the information could reveal your own vulnerabilities
  • whether the details are sensitive from a competition-law perspective
  • whether the information should be anonymised or limited

There should therefore be a clear difference between normal sharing within an approved forum and sharing that requires specific approval from, for example, information security, legal, data protection or management.

The goal is to contribute to collective resilience without at the same time creating new risks.

Information sharing is not the same as reporting

It is easy to confuse information sharing with reporting. In practice, three things need to be kept apart.

1. Mandatory incident reporting

Financial firms covered by DORA must report major ICT-related incidents to the competent authority according to set criteria, formats and deadlines.

2. Voluntary reporting of significant cyber threats

DORA also gives the possibility to voluntarily report significant cyber threats to Finansinspektionen when the threat is judged relevant to the financial system, service users or customers.

3. Information sharing within trusted communities

This is the sharing of cyber threat information with other participants in an information-sharing arrangement under Article 45.

The same event or threat picture can touch more than one process. But the processes have different purposes, recipients and legal preconditions. Sharing information within a network therefore does not replace incident reporting to the authority.

How much documentation is needed?

Information sharing does not have to become a big new package of documents. For most organisations it is better to build the area into existing governance.

It can be enough to have:

  • a principle in the information security governance
  • a practical work instruction
  • a responsible function
  • a simple register of evaluated and active arrangements
  • a control point in the incident and reporting process
  • traceable documentation of important decisions, disclosures and measures

What matters is not how many documents exist. What matters is that the organisation can show how decisions are made, how received information is used, how external sharing is controlled and how participation is followed up.

Common pitfalls

A common pitfall is to treat participation in information sharing as a mandatory requirement. It is not. It can, however, be relevant and valuable, depending on the organisation’s risk picture and needs.

Another pitfall is to create an entirely separate process for each type of information. In many cases, cyber threat information should instead feed into existing processes for incidents, vulnerabilities, risk, supplier governance or continuity.

A third pitfall is to document everything at the same level. That creates administration but not necessarily better security. Documentation should focus on information that leads to a significant assessment, measure, disclosure, incident or escalation.

Perhaps the most important pitfall is that the information sharing never reaches the business. An indicator that does not reach security monitoring, a vulnerability alert that does not reach IT or an incident lesson that does not influence the risk work creates limited value.

A practical minimum level

A proportionate handling of DORA’s rules on information sharing can build on a few simple steps:

  1. Map relevant information-sharing arrangements.
  2. Assess value, risks, terms and resource needs.
  3. Document the decision to participate, wait or abstain.
  4. Assign a responsible function and participants if the organisation takes part.
  5. Notify the competent authority when membership is validated or ends.
  6. Ensure received information can be handled in existing processes.
  7. Check confidentiality, data protection and the right to share before information is shared externally.
  8. Connect the work to incident and authority reporting.
  9. Follow up on whether the participation actually provides value.

It is not more administration that creates resilience. It is the right information to the right function at the right time.

How Kristensson i Skåne can support the work

Kristensson i Skåne helps financial organisations translate DORA’s requirements into practical and proportionate ways of working.

We can support with, for example:

  • current-state analysis and gap analysis against DORA
  • developing or adapting governing documents
  • a work instruction for information sharing and cyber threat information
  • connection to incident and authority reporting
  • allocation of responsibility and decision paths
  • documentation support and audit trails
  • review and simplification of existing DORA processes
  • ongoing GRC or CISO support as a service

Our starting point is practical. Information sharing should not become an isolated compliance activity. It should contribute to better decisions, faster measures and stronger operational resilience.

Would you like to see whether your handling of information sharing under DORA is sufficient, proportionate and usable in practice? Read more about our work with information security and governance or contact us and we will have a first conversation.

Frequently asked questions about DORA and information sharing

Does DORA require all financial firms to join an information-sharing network?

No. DORA Article 45 enables voluntary information sharing between financial firms, but does not create a general requirement for everyone to participate.

Must Finansinspektionen be informed about membership?

For firms under FI’s supervision, FI should normally be notified once participation in an information-sharing arrangement under Article 45 has been validated. FI should also be notified when participation ends.

Must the firm share information regularly?

No. DORA does not specify any particular frequency. Sharing should happen when the organisation has relevant, reliable and permitted information that can contribute to resilience.

Must all received cyber threat information be documented?

No. It is more reasonable to document information that leads to a significant assessment, measure, incident, external disclosure or escalation.

Is information sharing the same as incident reporting?

No. Information sharing under Article 45 is something other than the mandatory reporting of major ICT-related incidents and the voluntary reporting of significant cyber threats under Article 19.

Sources: DORA, Article 45 – cyber threat information sharing. Finansinspektionen (the Swedish FSA) – reporting of major ICT-related incidents and significant cyber threats.

This is an overview and not legal advice. Every organisation needs to assess its requirements based on its operations, supervision, risk picture and existing DORA governance.