DORA-Art11-P1

Article
11 (1)
Pillar
ICT Risk Management
Regulation Ref
Regulation (EU) 2022/2554, Article 11(1)
Last Reviewed
2026-01-15

Financial entities shall put in place a comprehensive ICT business continuity policy as an integral part of the operational business continuity policy, including response and recovery plans for ICT-related incidents.

Evidence Profiles

ICT Response and Recovery Plan COMMON

Documented plan for responding to and recovering from ICT-related incidents, including escalation procedures, communication protocols, and recovery procedures as required by DORA Article 11.

Formats
PDF DOCX
Evidence Class
ict-response-recovery-plan
Availability
COMMON
Update Frequency
annual
Typical Author
Business Continuity Manager
Approval Chain
Business Continuity Manager → CIO → Board Risk Committee

Content Sections

Expected Fields

Common Quality Issues

View Example

Generated example artifact using the default institution profile (COMMON availability, synthetic data only).

PLAIN_TEXT — Inline Preview
ICT RESPONSE AND RECOVERY PLAN
Nordvik Bank AG
Plan Reference: PLAN-RR-2025-001
Version 3.0 | Approved: 12 January 2025 | Next Review: 12 January 2026
Plan Owner: Business Continuity Manager
Classification: Confidential

━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━

PLAN OVERVIEW

This ICT Response and Recovery Plan ("the Plan") defines the procedures for
responding to and recovering from ICT-related incidents at Nordvik Bank AG ("the
Bank"), in accordance with DORA Article 11. The Plan covers all critical and
important ICT systems and business functions, including those supported by
third-party ICT service providers.

The Plan is activated when an ICT incident is classified as Severity 1 (Critical)
or Severity 2 (Major) under the Bank's Incident Classification Framework, or when
the Business Continuity Manager determines that normal incident management
procedures are insufficient to restore services within agreed timelines.

Key Recovery Objectives:
  — Recovery Time Objective (RTO): 4 hours for critical systems
  — Recovery Point Objective (RPO): 1 hour for critical systems
  — Last successful test: 15 November 2024 (tabletop exercise)
  — Next scheduled test: 15 May 2025 (live failover exercise)

━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━

INCIDENT CLASSIFICATION

Incidents are classified based on impact to business operations:

  Severity   Impact Description                          Response Time
  ─────────────────────────────────────────────────────────────────────────────
  1 (Critical) Complete loss of a critical business       Immediate activation
               function or data breach affecting          of this Plan
               >10,000 customers

  2 (Major)    Significant degradation of a critical      Activation within
               function or complete loss of an            30 minutes
               important function

  3 (Minor)    Degradation of an important function       Standard incident
               or loss of a standard function             management

  4 (Low)      Minor disruption with no material          Standard incident
               business impact                           management

━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━

ESCALATION PROCEDURES

3.1 Escalation Chain

  Detection (SOC/IT Ops)
    → Incident Manager (within 15 minutes of detection)
      → Business Continuity Manager (Severity 1-2, within 30 minutes)
        → CIO and CISO (Severity 1-2, within 1 hour)
          → CRO and CEO (Severity 1, within 2 hours)
            → Board Chair (Severity 1 with systemic impact, within 4 hours)
              → Competent Authority (per DORA Article 19 timelines)

3.2 Contact List

  Role                          Primary Contact        Backup Contact
  ─────────────────────────────────────────────────────────────────────────────
  Incident Manager              [Name, Phone]          [Name, Phone]
  Business Continuity Manager   [Name, Phone]          [Name, Phone]
  CIO                           [Name, Phone]          [Name, Phone]
  CISO                          [Name, Phone]          [Name, Phone]
  CRO                           [Name, Phone]          [Name, Phone]
  CEO                           [Name, Phone]          [Name, Phone]

  Contact list maintained separately in secure document CONT-RR-2025-001.
  Updated quarterly; last update: 6 January 2025.

━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━

COMMUNICATION PROTOCOLS

4.1 Internal Communication

  — Crisis communication channel: Dedicated Microsoft Teams channel
    ("ICT Crisis Response") activated upon Plan invocation
  — Status updates: Every 30 minutes during active incident
  — All-staff notification: Via email and intranet for incidents affecting
    employee-facing systems

4.2 External Communication

  — Customer notification: Via internet banking portal, mobile app push
    notification, and social media (pre-approved templates)
  — Regulatory notification: Per DORA Article 19 timelines (initial
    notification within 4 hours for major incidents)
  — Media handling: All media enquiries directed to Head of Communications;
    no staff to make public statements without authorisation

━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━

RECOVERY PROCEDURES

5.1 Recovery Priority Order

  Priority   System/Function                    RTO      RPO
  ─────────────────────────────────────────────────────────────────────────────
  P1         Payment Processing (SWIFT)          2h       30min
  P1         Core Banking (Temenos T24)          4h       1h
  P2         Digital Banking Channels            4h       1h
  P3         AML/CFT Compliance System           4h       1h
  P4         Security Monitoring (SIEM)          1h       0
  P5         Regulatory Reporting                24h      4h
  P6         ATM/Branch Services                 8h       2h
  P7         Email and Collaboration             24h      4h

5.2 Recovery Scenarios

  Scenario A — Data Centre Failure (Zurich DC-1)
    1. Activate DR site (Geneva DC-2)
    2. Failover database replication (Oracle Data Guard)
    3. Redirect network traffic via DNS/BGP changes
    4. Verify core banking and payment processing functionality
    5. Restore digital channels via AWS (unaffected)
    6. Estimated recovery time: 3-4 hours

  Scenario B — Ransomware Attack
    1. Isolate affected systems from network
    2. Assess scope of encryption/compromise
    3. Activate forensic investigation team
    4. Restore from immutable backups (air-gapped)
    5. Rebuild affected systems from known-good images
    6. Estimated recovery time: 4-24 hours depending on scope

  Scenario C — Cloud Provider Outage (AWS)
    1. Activate degraded-mode operations for digital channels
    2. Redirect customer traffic to call centre and branches
    3. Monitor AWS status page and support channels
    4. If prolonged (>4 hours), activate multi-region failover
    5. Estimated recovery time: dependent on provider

  Scenario D — Third-Party Service Provider Failure
    1. Activate alternative processing arrangements per contract
    2. Implement manual workarounds for affected functions
    3. Engage provider incident management team
    4. Estimated recovery time: per contractual SLA

5.3 Third-Party Recovery Dependencies

  Provider              Service                  Contractual RTO   Exit Strategy
  ─────────────────────────────────────────────────────────────────────────────
  AWS                   Cloud infrastructure      4h (SLA)         In development
  Temenos AG            Core banking support       8h (SLA)         Documented
  SWIFT                 Payment messaging          2h (SLA)         N/A (utility)
  Swisscom              WAN connectivity           4h (SLA)         Documented

━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━

RECOVERY TIME OBJECTIVES

  System Category     RTO Target    RPO Target    Last Validated
  ─────────────────────────────────────────────────────────────────────────────
  Critical systems     4 hours       1 hour        15 Nov 2024
  Important systems    24 hours      4 hours       15 Nov 2024
  Standard systems     72 hours      24 hours      Not yet tested

━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━

RECOVERY POINT OBJECTIVES

RPO is achieved through the following backup and replication mechanisms:

  — Oracle Data Guard: Synchronous replication to Geneva DC-2 (RPO ≈ 0)
  — Daily incremental backups: All critical systems (RPO ≤ 24h worst case)
  — Transaction log shipping: Every 15 minutes for core banking (RPO ≤ 15min)
  — AWS cross-region replication: For digital banking data (RPO ≤ 1h)

━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━

TESTING SCHEDULE

  Test Type              Frequency     Last Test        Next Test
  ─────────────────────────────────────────────────────────────────────────────
  Tabletop exercise      Semi-annual   15 Nov 2024      15 May 2025
  Walkthrough test       Annual        20 Jun 2024      20 Jun 2025
  Live failover (DR)     Annual        18 Oct 2024      18 Oct 2025
  Communication test     Semi-annual   15 Nov 2024      15 May 2025

━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━

Document History:
  v3.0  12 Jan 2025  Updated for DORA compliance; added third-party dependencies
  v2.5  15 Jan 2024  Annual review; updated recovery scenarios
  v2.0  12 Jan 2023  Major revision; added cloud recovery procedures

Approved by: Board Risk Committee
Signature:   [Board Risk Committee Chair]
Date:        12 January 2025

Expected Structured Facts

Example structured facts that Detrixa would extract from this evidence (synthetic data, deterministic seed).

ict_response_recovery_status — fs-ict-response-recovery
{
  "factId": "c1d2e3f4-a5b6-7890-cdef-100000000012",
  "evidenceId": "a0b1c2d3-e4f5-6789-abcd-100000000012",
  "evidenceClassId": "ict-response-recovery-plan",
  "factType": "ict_response_recovery_status",
  "data": {
    "plan_version": "3.0",
    "approval_date": "2025-01-12",
    "rto_hours": 4.0,
    "rpo_hours": 1.0,
    "last_test_date": "2024-11-15",
    "test_result_successful": true,
    "covers_third_party_dependencies": true,
    "next_test_date": "2025-05-15"
  },
  "provenance": "deterministic",
  "extractorVersion": "dora-test-generator/0.1.0",
  "extractedAt": "2025-01-15T09:00:00Z",
  "supersededBy": null
}

Fact Schemas

ict_response_recovery_status

Schema ID
fs-ict-response-recovery
Control
DORA-Art11-P1

Valid Ranges

approval_date
within last 18 months
last_test_date
within last 12 months
rto_hours
typically 2-24 hours for critical functions

Related Schemas

JSON Schema

{
  "properties": {
    "approval_date": {
      "format": "date",
      "type": "string"
    },
    "covers_third_party_dependencies": {
      "type": "boolean"
    },
    "last_test_date": {
      "format": "date",
      "type": "string"
    },
    "next_test_date": {
      "format": "date",
      "type": "string"
    },
    "plan_version": {
      "type": "string"
    },
    "rpo_hours": {
      "minimum": 0,
      "type": "number"
    },
    "rto_hours": {
      "minimum": 0,
      "type": "number"
    },
    "test_result_successful": {
      "type": "boolean"
    }
  },
  "required": [
    "plan_version",
    "approval_date",
    "rto_hours",
    "rpo_hours",
    "last_test_date"
  ],
  "type": "object"
}