As per Article 16(2) of Regulation (EU) No 1093/2010 (EBA Regulation), 1094/2010 (EIOPA Regulation) and 1095/2010 (ESMA regulation), any guidelines and recommendations developed by the ESAs shall be accompanied by an Impact Assessment (IA) which analyses 'the potential related costs and benefits'.
This analysis presents the IA of the main policy options included in this Consultation Paper (CP) on Joint Guidelines (RTS) on the estimation of aggregated annual costs and losses caused by major ICT- related incidents.
A. Problem identification
According to Article 11 of the Regulation 2022/2554 (DORA), financial entities, other than microenterprises, shall report to the competent authorities, upon their request, an estimation of aggregated annual costs and losses caused by major ICT-related incidents.
The costs and losses can be measured in various way, and also may be estimated differently across sectors and financial entities. Without further specifications, the data on costs and losses r
…