DORA-Art14-P1

Article
14 (1)
Pillar
ICT Risk Management
Regulation Ref
Regulation (EU) 2022/2554, Article 14(1)
Last Reviewed
2026-01-15

Financial entities shall put in place resources and capabilities to monitor, handle and follow up on ICT-related incidents, and shall ensure that root causes are identified, documented and addressed to prevent the occurrence of such incidents.

Evidence Profiles

ICT Incident Lessons Learned Reports PARTIAL

Plain text reports documenting lessons learned from ICT-related incidents, including root cause analysis, corrective actions, and process improvements as required by DORA Article 14.

Formats
PLAIN_TEXT PDF
Evidence Class
ict-lessons-learned
Availability
PARTIAL
Update Frequency
event-driven
Typical Author
Incident Manager
Approval Chain
Incident Manager → CISO

Content Sections

Expected Fields

Common Quality Issues

View Example

Generated example artifact using the default institution profile (COMMON availability, synthetic data only).

PLAIN_TEXT — Inline Preview
ICT INCIDENT LESSONS LEARNED REPORTS
Nordvik Bank AG
Reporting Period: 1 July 2024 — 31 December 2024
Prepared by: Incident Manager
Reviewed by: Katrin Halvorsen, CISO
Classification: Internal — Restricted

━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━

INCIDENT SUMMARY

During the reporting period, 14 ICT incidents were recorded. Lessons learned
reviews were conducted for all 8 incidents classified as Severity 2 (Major) or
above. The remaining 6 Severity 3-4 incidents were reviewed in aggregate at the
monthly ICTRC meeting.

  Severity     Count    Lessons Learned Conducted    Root Cause Analysis
  ─────────────────────────────────────────────────────────────────────────────
  1 (Critical)   0        N/A                          N/A
  2 (Major)      3        3                            3
  3 (Minor)      5        Aggregate review             2
  4 (Low)        6        Aggregate review             0
  Total         14        8 (individual)               5

━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━

INCIDENT 1: CORE BANKING PERFORMANCE DEGRADATION

Incident ID:     INC-2024-0847
Incident Date:   18 September 2024
Duration:        3 hours 45 minutes
Severity:        2 (Major)
Affected System: Temenos T24 Core Banking
Business Impact: Slow transaction processing; customer-facing delays in internet
                 and mobile banking; 247 customer complaints received

Root Cause Analysis:
  Proximate cause: Database connection pool exhaustion due to a long-running
  batch query that was inadvertently scheduled during peak hours.

  Contributing factors:
    — Batch scheduling change was not reviewed through the change management
      process (human error)
    — Connection pool monitoring alert threshold was set too high (90% vs
      recommended 75%)
    — No automated circuit breaker to isolate batch workloads from online
      transaction processing

Corrective Actions:
  CA-01  Enforce change management review for all batch schedule modifications
         Status: COMPLETED (25 September 2024)
  CA-02  Reduce connection pool alert threshold from 90% to 75%
         Status: COMPLETED (20 September 2024)
  CA-03  Implement workload isolation between batch and online processing
         Status: IN PROGRESS (target: Q1 2025)

Process Improvements:
  — Updated change management procedure to explicitly include batch scheduling
    changes in scope
  — Added connection pool utilisation to the SOC real-time dashboard

━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━

INCIDENT 2: PHISHING ATTACK — CREDENTIAL COMPROMISE

Incident ID:     INC-2024-0912
Incident Date:   7 October 2024
Duration:        6 hours (detection to containment)
Severity:        2 (Major)
Affected System: Microsoft 365, Active Directory
Business Impact: 3 employee accounts compromised; no data exfiltration confirmed;
                 precautionary password reset for 120 users in affected department

Root Cause Analysis:
  Proximate cause: Targeted spear-phishing email impersonating the Bank's HR
  department, directing employees to a credential harvesting page. Three
  employees entered their credentials before the campaign was detected.

  Contributing factors:
    — Phishing email bypassed email security gateway due to use of a newly
      registered domain not yet in threat intelligence feeds
    — Affected employees had not completed the Q3 2024 phishing awareness
      refresher training
    — MFA was enforced but the attacker used an adversary-in-the-middle
      technique to capture session tokens

Corrective Actions:
  CA-01  Deploy phishing-resistant MFA (FIDO2 hardware keys) for all employees
         with access to sensitive systems
         Status: IN PROGRESS (target: Q1 2025)
  CA-02  Implement conditional access policies requiring compliant devices
         Status: COMPLETED (15 October 2024)
  CA-03  Enhance email security gateway with AI-based impersonation detection
         Status: COMPLETED (1 November 2024)
  CA-04  Conduct targeted phishing awareness training for affected department
         Status: COMPLETED (14 October 2024)

Process Improvements:
  — Added adversary-in-the-middle attack scenarios to phishing simulation programme
  — Updated incident response playbook for credential compromise scenarios
  — Implemented automated session token revocation upon confirmed phishing

━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━

INCIDENT 3: NETWORK SWITCH FAILURE — BRANCH CONNECTIVITY LOSS

Incident ID:     INC-2024-1034
Incident Date:   22 November 2024
Duration:        5 hours 20 minutes
Severity:        2 (Major)
Affected System: Branch WAN (Swisscom MPLS), 12 branch offices
Business Impact: 12 branches unable to process transactions for 5+ hours;
                 estimated revenue impact CHF 85,000; 89 customer complaints

Root Cause Analysis:
  Proximate cause: Core aggregation switch at Swisscom's Zurich PoP experienced
  a firmware bug causing a routing loop, affecting MPLS circuits to 12 branches.

  Contributing factors:
    — Single aggregation point for branch connectivity (no redundant path)
    — Swisscom incident notification delayed by 45 minutes
    — Branch fallback to 4G backup connectivity failed for 4 branches due to
      expired SIM cards

Corrective Actions:
  CA-01  Negotiate dual-path MPLS connectivity with Swisscom for critical branches
         Status: IN PROGRESS (target: Q2 2025)
  CA-02  Implement automated 4G SIM card expiry monitoring
         Status: COMPLETED (5 December 2024)
  CA-03  Establish SLA for Swisscom incident notification (target: 15 minutes)
         Status: IN PROGRESS (contract renegotiation)

Process Improvements:
  — Added branch connectivity to the SOC monitoring dashboard
  — Updated BCP procedures for branch-level ICT outages
  — Triggered policy change: all third-party SLAs to include notification
    timeline requirements

━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━

AGGREGATE REVIEW: SEVERITY 3-4 INCIDENTS

Common themes identified across 11 lower-severity incidents:

  Theme                          Occurrences    Action Taken
  ─────────────────────────────────────────────────────────────────────────────
  Patch-related service restart   3             Improved patch testing in staging
  Certificate expiry              2             Deployed automated cert monitoring
  Disk space exhaustion           2             Implemented predictive alerting
  User access provisioning error  2             Updated RBAC provisioning workflow
  Scheduled maintenance overrun   2             Revised maintenance window planning

━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━

CORRECTIVE ACTION SUMMARY

  Total corrective actions identified:     18
  Completed:                               11
  In progress:                              5
  Not started:                              2

  Total root cause analyses performed:      5
  Policy changes triggered:                 2
    — Change management procedure updated (batch scheduling)
    — Third-party SLA notification requirements added

━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━

Follow-Up Status:
  Next review of open corrective actions: February 2025 ICTRC meeting
  Next reporting period: 1 January 2025 — 30 June 2025

Prepared by: Incident Manager
Reviewed by: Katrin Halvorsen, CISO
Date: 10 January 2025

Expected Structured Facts

Example structured facts that Detrixa would extract from this evidence (synthetic data, deterministic seed).

ict_lessons_learned_status — fs-ict-lessons-learned
{
  "factId": "c1d2e3f4-a5b6-7890-cdef-100000000016",
  "evidenceId": "a0b1c2d3-e4f5-6789-abcd-100000000016",
  "evidenceClassId": "ict-lessons-learned",
  "factType": "ict_lessons_learned_status",
  "data": {
    "reporting_period_start": "2024-07-01",
    "reporting_period_end": "2024-12-31",
    "incidents_reviewed": 14,
    "lessons_documented": 14,
    "corrective_actions_identified": 18,
    "corrective_actions_completed": 11,
    "root_cause_analyses_performed": 5,
    "policy_changes_triggered": 2
  },
  "provenance": "deterministic",
  "extractorVersion": "dora-test-generator/0.1.0",
  "extractedAt": "2025-01-15T09:00:00Z",
  "supersededBy": null
}

Fact Schemas

ict_lessons_learned_status

Schema ID
fs-ict-lessons-learned
Control
DORA-Art14-P1

Valid Ranges

reporting_period_end
within last 12 months
lessons_documented
should be >= incidents_reviewed for thorough process

JSON Schema

{
  "properties": {
    "corrective_actions_completed": {
      "minimum": 0,
      "type": "integer"
    },
    "corrective_actions_identified": {
      "minimum": 0,
      "type": "integer"
    },
    "incidents_reviewed": {
      "minimum": 0,
      "type": "integer"
    },
    "lessons_documented": {
      "minimum": 0,
      "type": "integer"
    },
    "policy_changes_triggered": {
      "minimum": 0,
      "type": "integer"
    },
    "reporting_period_end": {
      "format": "date",
      "type": "string"
    },
    "reporting_period_start": {
      "format": "date",
      "type": "string"
    },
    "root_cause_analyses_performed": {
      "minimum": 0,
      "type": "integer"
    }
  },
  "required": [
    "reporting_period_start",
    "reporting_period_end",
    "incidents_reviewed",
    "lessons_documented"
  ],
  "type": "object"
}