DORA-Art16-P1

Article
16 (1)
Pillar
ICT Risk Management
Regulation Ref
Regulation (EU) 2022/2554, Article 16(1)
Last Reviewed
2026-01-15

Financial entities shall have in place communication plans enabling a responsible disclosure of ICT-related incidents or major vulnerabilities to clients and counterparts as well as to the public, as appropriate.

Evidence Profiles

ICT Incident Communication Plan PARTIAL

Plan defining communication procedures for ICT-related incidents and vulnerabilities, including stakeholder notification templates, escalation paths, and public disclosure criteria as required by DORA Article 16.

Formats
PDF
Evidence Class
ict-communication-plan
Availability
PARTIAL
Update Frequency
annual
Typical Author
Head of Communications
Approval Chain
Head of Communications → CISO → CEO

Content Sections

Expected Fields

Common Quality Issues

View Example

Generated example artifact using the default institution profile (COMMON availability, synthetic data only).

PLAIN_TEXT — Inline Preview
ICT INCIDENT COMMUNICATION PLAN
Nordvik Bank AG
Plan Reference: PLAN-COMM-2025-001
Version 2.1 | Approved: 10 January 2025 | Next Review: 10 January 2026
Plan Owner: Head of Communications
Classification: Confidential

━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━

1. COMMUNICATION OBJECTIVES

This plan defines the communication procedures for ICT-related incidents and
vulnerabilities at Nordvik Bank AG ("the Bank"), in accordance with DORA Article 16.
The plan ensures responsible, timely, and accurate disclosure to all relevant
stakeholders while protecting the Bank's interests and maintaining public trust.

Objectives:
  (a) Ensure timely notification of affected stakeholders
  (b) Maintain transparency while protecting sensitive investigation details
  (c) Comply with regulatory notification requirements (DORA Article 19)
  (d) Minimise reputational damage through proactive communication
  (e) Coordinate internal and external messaging for consistency

━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━

2. STAKEHOLDER IDENTIFICATION

  Category              Stakeholders                    Notification Priority
  ─────────────────────────────────────────────────────────────────────────────
  Internal              Board of Directors               P1 (within 4 hours)
                        Executive Management             P1 (within 2 hours)
                        All Staff                        P2 (within 8 hours)
                        Affected Business Units          P1 (within 1 hour)

  Regulatory            FINMA                            P1 (per DORA Art. 19)
                        ECB/SSM (if applicable)          P1 (per DORA Art. 19)
                        National CSIRT                   P1 (within 24 hours)

  Clients               Affected retail customers        P2 (within 24 hours)
                        Affected corporate clients       P1 (within 12 hours)
                        All customers (if systemic)      P2 (within 48 hours)

  Counterparties        Correspondent banks              P2 (within 24 hours)
                        Payment scheme operators          P1 (within 12 hours)

  Public                Media                            P3 (as determined)
                        General public                   P3 (as determined)

  Third Parties         Affected ICT providers           P1 (within 4 hours)
                        Cyber insurance provider         P2 (within 24 hours)

Stakeholder categories: 6
Contact lists maintained in secure document CONT-COMM-2025-001, updated quarterly.

━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━

3. NOTIFICATION TEMPLATES

The following pre-approved notification templates are maintained and tested:

  Template ID   Purpose                          Approval Level
  ─────────────────────────────────────────────────────────────────────────────
  TMPL-REG-001  Initial regulatory notification   CISO + Legal
                (DORA Article 19 — within 4h)
  TMPL-REG-002  Intermediate regulatory report    CISO + Legal
                (DORA Article 19 — within 72h)
  TMPL-REG-003  Final regulatory report           CISO + CRO + Legal
                (DORA Article 19 — within 1 month)
  TMPL-CUS-001  Customer notification — service   Head of Communications
                disruption
  TMPL-CUS-002  Customer notification — data      Head of Communications + Legal
                breach
  TMPL-INT-001  Internal staff notification       Head of Communications
  TMPL-MED-001  Press statement — service         CEO + Head of Communications
                disruption
  TMPL-MED-002  Press statement — security        CEO + Head of Communications
                incident                          + Legal
  TMPL-CPT-001  Counterparty notification         CIO + Head of Communications

All templates are reviewed semi-annually and updated following lessons learned
from incident communication exercises.

━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━

4. ESCALATION PATHS

4.1 Communication Escalation Chain

  SOC / Incident Manager
    → CISO (all Severity 1-2 incidents, within 1 hour)
      → Head of Communications (if external communication required, within 2 hours)
        → CEO (if media statement required or public disclosure, within 4 hours)
          → Board Chair (if systemic impact or regulatory escalation, within 4 hours)

4.2 Regulatory Notification Escalation (DORA Article 19)

  Major ICT Incident Detected
    → CISO classifies as major incident (within 2 hours)
      → Legal reviews notification content (within 3 hours)
        → Initial notification submitted to competent authority (within 4 hours)
          → Intermediate report submitted (within 72 hours)
            → Final report submitted (within 1 month)

4.3 Decision Authority

  Communication Type              Decision Authority
  ─────────────────────────────────────────────────────────────────────────────
  Internal staff notification     Head of Communications
  Customer notification           Head of Communications + CISO
  Regulatory notification         CISO + Legal
  Press statement                 CEO + Head of Communications
  Public disclosure               CEO + Board Chair
  Social media response           Head of Communications (pre-approved only)

━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━

5. PUBLIC DISCLOSURE CRITERIA

Public disclosure of an ICT incident is required when any of the following
criteria are met:

  Criterion                                          Disclosure Timeline
  ─────────────────────────────────────────────────────────────────────────────
  Personal data breach affecting >1,000 individuals  Within 72 hours (GDPR)
  Service disruption affecting >50% of customers     Within 24 hours
  Incident with potential systemic impact             As directed by regulator
  Incident attracting significant media attention     Proactive statement within
                                                     4 hours of media enquiry
  Vulnerability disclosure (coordinated)              Per coordinated disclosure
                                                     timeline (typically 90 days)

Disclosure decisions are made by the CEO in consultation with the CISO, Head of
Communications, and Legal Counsel. The Board Chair is informed before any public
disclosure.

━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━

6. MEDIA HANDLING

6.1 Media Spokesperson

  Primary spokesperson:   CEO (for major incidents)
  Secondary spokesperson: Head of Communications (for operational updates)
  Technical spokesperson: CISO (for technical briefings, with CEO approval)

  No other staff member is authorised to make public statements regarding
  ICT incidents without explicit approval from the Head of Communications.

6.2 Media Response Procedures

  — All media enquiries routed to the Communications team
  — Initial holding statement issued within 2 hours of media enquiry
  — Substantive statement issued within 4 hours (using pre-approved templates)
  — Regular updates provided every 4 hours during active incidents
  — Social media monitored continuously during incidents; responses limited
    to pre-approved messaging

━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━

7. POST-INCIDENT COMMUNICATION

Following resolution of a major ICT incident:

  — Customer follow-up communication within 5 business days
  — Regulatory follow-up per DORA Article 19 final report timeline
  — Internal lessons learned communication to all staff within 10 business days
  — Board briefing at next scheduled Board meeting (or extraordinary session
    if warranted)

━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━

COMMUNICATION SIMULATION

Last simulation date: 15 November 2024
Scenario: Simulated ransomware attack with customer data exposure
Participants: CISO, Head of Communications, Legal, CEO, Board Chair
Result: Regulatory notification template completed in 3.5 hours (within 4h target)
Findings: Customer notification template required update for GDPR-specific language
Next simulation: May 2025

━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━

Document History:
  v2.1  10 Jan 2025  Updated for DORA compliance; added regulatory notification
                     templates per Article 19
  v2.0  15 Jan 2024  Major revision; added social media handling
  v1.5  12 Jan 2023  Annual review; updated stakeholder contact lists

Approved by: CEO and CISO
Signatures:  [CEO] / [CISO]
Date:        10 January 2025

Expected Structured Facts

Example structured facts that Detrixa would extract from this evidence (synthetic data, deterministic seed).

ict_communication_plan_status — fs-ict-communication-plan
{
  "factId": "c1d2e3f4-a5b6-7890-cdef-100000000019",
  "evidenceId": "a0b1c2d3-e4f5-6789-abcd-100000000019",
  "evidenceClassId": "ict-communication-plan",
  "factType": "ict_communication_plan_status",
  "data": {
    "plan_version": "2.1",
    "approval_date": "2025-01-10",
    "has_notification_templates": true,
    "has_escalation_paths": true,
    "has_disclosure_criteria": true,
    "stakeholder_categories_count": 6,
    "last_simulation_date": "2024-11-15",
    "includes_regulatory_notification": true,
    "includes_media_handling": true
  },
  "provenance": "deterministic",
  "extractorVersion": "dora-test-generator/0.1.0",
  "extractedAt": "2025-01-15T09:00:00Z",
  "supersededBy": null
}

Fact Schemas

ict_communication_plan_status

Schema ID
fs-ict-communication-plan
Control
DORA-Art16-P1

Valid Ranges

approval_date
within last 18 months
stakeholder_categories_count
minimum 3 (clients, regulators, public)

JSON Schema

{
  "properties": {
    "approval_date": {
      "format": "date",
      "type": "string"
    },
    "has_disclosure_criteria": {
      "type": "boolean"
    },
    "has_escalation_paths": {
      "type": "boolean"
    },
    "has_notification_templates": {
      "type": "boolean"
    },
    "includes_media_handling": {
      "type": "boolean"
    },
    "includes_regulatory_notification": {
      "type": "boolean"
    },
    "last_simulation_date": {
      "format": "date",
      "type": "string"
    },
    "plan_version": {
      "type": "string"
    },
    "stakeholder_categories_count": {
      "minimum": 0,
      "type": "integer"
    }
  },
  "required": [
    "plan_version",
    "approval_date",
    "has_notification_templates",
    "has_escalation_paths",
    "has_disclosure_criteria"
  ],
  "type": "object"
}