Financial entities shall put in place resources and capabilities to monitor, handle and follow up on ICT-related incidents, and shall ensure that root causes are identified, documented and addressed to prevent the occurrence of such incidents.
Plain text reports documenting lessons learned from ICT-related incidents, including root cause analysis, corrective actions, and process improvements as required by DORA Article 14.
ict-lessons-learnedGenerated example artifact using the default institution profile (COMMON availability, synthetic data only).
ICT INCIDENT LESSONS LEARNED REPORTS
Nordvik Bank AG
Reporting Period: 1 July 2024 — 31 December 2024
Prepared by: Incident Manager
Reviewed by: Katrin Halvorsen, CISO
Classification: Internal — Restricted
━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━
INCIDENT SUMMARY
During the reporting period, 14 ICT incidents were recorded. Lessons learned
reviews were conducted for all 8 incidents classified as Severity 2 (Major) or
above. The remaining 6 Severity 3-4 incidents were reviewed in aggregate at the
monthly ICTRC meeting.
Severity Count Lessons Learned Conducted Root Cause Analysis
─────────────────────────────────────────────────────────────────────────────
1 (Critical) 0 N/A N/A
2 (Major) 3 3 3
3 (Minor) 5 Aggregate review 2
4 (Low) 6 Aggregate review 0
Total 14 8 (individual) 5
━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━
INCIDENT 1: CORE BANKING PERFORMANCE DEGRADATION
Incident ID: INC-2024-0847
Incident Date: 18 September 2024
Duration: 3 hours 45 minutes
Severity: 2 (Major)
Affected System: Temenos T24 Core Banking
Business Impact: Slow transaction processing; customer-facing delays in internet
and mobile banking; 247 customer complaints received
Root Cause Analysis:
Proximate cause: Database connection pool exhaustion due to a long-running
batch query that was inadvertently scheduled during peak hours.
Contributing factors:
— Batch scheduling change was not reviewed through the change management
process (human error)
— Connection pool monitoring alert threshold was set too high (90% vs
recommended 75%)
— No automated circuit breaker to isolate batch workloads from online
transaction processing
Corrective Actions:
CA-01 Enforce change management review for all batch schedule modifications
Status: COMPLETED (25 September 2024)
CA-02 Reduce connection pool alert threshold from 90% to 75%
Status: COMPLETED (20 September 2024)
CA-03 Implement workload isolation between batch and online processing
Status: IN PROGRESS (target: Q1 2025)
Process Improvements:
— Updated change management procedure to explicitly include batch scheduling
changes in scope
— Added connection pool utilisation to the SOC real-time dashboard
━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━
INCIDENT 2: PHISHING ATTACK — CREDENTIAL COMPROMISE
Incident ID: INC-2024-0912
Incident Date: 7 October 2024
Duration: 6 hours (detection to containment)
Severity: 2 (Major)
Affected System: Microsoft 365, Active Directory
Business Impact: 3 employee accounts compromised; no data exfiltration confirmed;
precautionary password reset for 120 users in affected department
Root Cause Analysis:
Proximate cause: Targeted spear-phishing email impersonating the Bank's HR
department, directing employees to a credential harvesting page. Three
employees entered their credentials before the campaign was detected.
Contributing factors:
— Phishing email bypassed email security gateway due to use of a newly
registered domain not yet in threat intelligence feeds
— Affected employees had not completed the Q3 2024 phishing awareness
refresher training
— MFA was enforced but the attacker used an adversary-in-the-middle
technique to capture session tokens
Corrective Actions:
CA-01 Deploy phishing-resistant MFA (FIDO2 hardware keys) for all employees
with access to sensitive systems
Status: IN PROGRESS (target: Q1 2025)
CA-02 Implement conditional access policies requiring compliant devices
Status: COMPLETED (15 October 2024)
CA-03 Enhance email security gateway with AI-based impersonation detection
Status: COMPLETED (1 November 2024)
CA-04 Conduct targeted phishing awareness training for affected department
Status: COMPLETED (14 October 2024)
Process Improvements:
— Added adversary-in-the-middle attack scenarios to phishing simulation programme
— Updated incident response playbook for credential compromise scenarios
— Implemented automated session token revocation upon confirmed phishing
━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━
INCIDENT 3: NETWORK SWITCH FAILURE — BRANCH CONNECTIVITY LOSS
Incident ID: INC-2024-1034
Incident Date: 22 November 2024
Duration: 5 hours 20 minutes
Severity: 2 (Major)
Affected System: Branch WAN (Swisscom MPLS), 12 branch offices
Business Impact: 12 branches unable to process transactions for 5+ hours;
estimated revenue impact CHF 85,000; 89 customer complaints
Root Cause Analysis:
Proximate cause: Core aggregation switch at Swisscom's Zurich PoP experienced
a firmware bug causing a routing loop, affecting MPLS circuits to 12 branches.
Contributing factors:
— Single aggregation point for branch connectivity (no redundant path)
— Swisscom incident notification delayed by 45 minutes
— Branch fallback to 4G backup connectivity failed for 4 branches due to
expired SIM cards
Corrective Actions:
CA-01 Negotiate dual-path MPLS connectivity with Swisscom for critical branches
Status: IN PROGRESS (target: Q2 2025)
CA-02 Implement automated 4G SIM card expiry monitoring
Status: COMPLETED (5 December 2024)
CA-03 Establish SLA for Swisscom incident notification (target: 15 minutes)
Status: IN PROGRESS (contract renegotiation)
Process Improvements:
— Added branch connectivity to the SOC monitoring dashboard
— Updated BCP procedures for branch-level ICT outages
— Triggered policy change: all third-party SLAs to include notification
timeline requirements
━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━
AGGREGATE REVIEW: SEVERITY 3-4 INCIDENTS
Common themes identified across 11 lower-severity incidents:
Theme Occurrences Action Taken
─────────────────────────────────────────────────────────────────────────────
Patch-related service restart 3 Improved patch testing in staging
Certificate expiry 2 Deployed automated cert monitoring
Disk space exhaustion 2 Implemented predictive alerting
User access provisioning error 2 Updated RBAC provisioning workflow
Scheduled maintenance overrun 2 Revised maintenance window planning
━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━
CORRECTIVE ACTION SUMMARY
Total corrective actions identified: 18
Completed: 11
In progress: 5
Not started: 2
Total root cause analyses performed: 5
Policy changes triggered: 2
— Change management procedure updated (batch scheduling)
— Third-party SLA notification requirements added
━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━
Follow-Up Status:
Next review of open corrective actions: February 2025 ICTRC meeting
Next reporting period: 1 January 2025 — 30 June 2025
Prepared by: Incident Manager
Reviewed by: Katrin Halvorsen, CISO
Date: 10 January 2025
Example structured facts that Detrixa would extract from this evidence (synthetic data, deterministic seed).
ict_lessons_learned_status — fs-ict-lessons-learned
{
"factId": "c1d2e3f4-a5b6-7890-cdef-100000000016",
"evidenceId": "a0b1c2d3-e4f5-6789-abcd-100000000016",
"evidenceClassId": "ict-lessons-learned",
"factType": "ict_lessons_learned_status",
"data": {
"reporting_period_start": "2024-07-01",
"reporting_period_end": "2024-12-31",
"incidents_reviewed": 14,
"lessons_documented": 14,
"corrective_actions_identified": 18,
"corrective_actions_completed": 11,
"root_cause_analyses_performed": 5,
"policy_changes_triggered": 2
},
"provenance": "deterministic",
"extractorVersion": "dora-test-generator/0.1.0",
"extractedAt": "2025-01-15T09:00:00Z",
"supersededBy": null
}
fs-ict-lessons-learnedDORA-Art14-P1reporting_period_endlessons_documented{
"properties": {
"corrective_actions_completed": {
"minimum": 0,
"type": "integer"
},
"corrective_actions_identified": {
"minimum": 0,
"type": "integer"
},
"incidents_reviewed": {
"minimum": 0,
"type": "integer"
},
"lessons_documented": {
"minimum": 0,
"type": "integer"
},
"policy_changes_triggered": {
"minimum": 0,
"type": "integer"
},
"reporting_period_end": {
"format": "date",
"type": "string"
},
"reporting_period_start": {
"format": "date",
"type": "string"
},
"root_cause_analyses_performed": {
"minimum": 0,
"type": "integer"
}
},
"required": [
"reporting_period_start",
"reporting_period_end",
"incidents_reviewed",
"lessons_documented"
],
"type": "object"
}