Financial entities shall have in place communication plans enabling a responsible disclosure of ICT-related incidents or major vulnerabilities to clients and counterparts as well as to the public, as appropriate.
Plan defining communication procedures for ICT-related incidents and vulnerabilities, including stakeholder notification templates, escalation paths, and public disclosure criteria as required by DORA Article 16.
ict-communication-planGenerated example artifact using the default institution profile (COMMON availability, synthetic data only).
ICT INCIDENT COMMUNICATION PLAN
Nordvik Bank AG
Plan Reference: PLAN-COMM-2025-001
Version 2.1 | Approved: 10 January 2025 | Next Review: 10 January 2026
Plan Owner: Head of Communications
Classification: Confidential
━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━
1. COMMUNICATION OBJECTIVES
This plan defines the communication procedures for ICT-related incidents and
vulnerabilities at Nordvik Bank AG ("the Bank"), in accordance with DORA Article 16.
The plan ensures responsible, timely, and accurate disclosure to all relevant
stakeholders while protecting the Bank's interests and maintaining public trust.
Objectives:
(a) Ensure timely notification of affected stakeholders
(b) Maintain transparency while protecting sensitive investigation details
(c) Comply with regulatory notification requirements (DORA Article 19)
(d) Minimise reputational damage through proactive communication
(e) Coordinate internal and external messaging for consistency
━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━
2. STAKEHOLDER IDENTIFICATION
Category Stakeholders Notification Priority
─────────────────────────────────────────────────────────────────────────────
Internal Board of Directors P1 (within 4 hours)
Executive Management P1 (within 2 hours)
All Staff P2 (within 8 hours)
Affected Business Units P1 (within 1 hour)
Regulatory FINMA P1 (per DORA Art. 19)
ECB/SSM (if applicable) P1 (per DORA Art. 19)
National CSIRT P1 (within 24 hours)
Clients Affected retail customers P2 (within 24 hours)
Affected corporate clients P1 (within 12 hours)
All customers (if systemic) P2 (within 48 hours)
Counterparties Correspondent banks P2 (within 24 hours)
Payment scheme operators P1 (within 12 hours)
Public Media P3 (as determined)
General public P3 (as determined)
Third Parties Affected ICT providers P1 (within 4 hours)
Cyber insurance provider P2 (within 24 hours)
Stakeholder categories: 6
Contact lists maintained in secure document CONT-COMM-2025-001, updated quarterly.
━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━
3. NOTIFICATION TEMPLATES
The following pre-approved notification templates are maintained and tested:
Template ID Purpose Approval Level
─────────────────────────────────────────────────────────────────────────────
TMPL-REG-001 Initial regulatory notification CISO + Legal
(DORA Article 19 — within 4h)
TMPL-REG-002 Intermediate regulatory report CISO + Legal
(DORA Article 19 — within 72h)
TMPL-REG-003 Final regulatory report CISO + CRO + Legal
(DORA Article 19 — within 1 month)
TMPL-CUS-001 Customer notification — service Head of Communications
disruption
TMPL-CUS-002 Customer notification — data Head of Communications + Legal
breach
TMPL-INT-001 Internal staff notification Head of Communications
TMPL-MED-001 Press statement — service CEO + Head of Communications
disruption
TMPL-MED-002 Press statement — security CEO + Head of Communications
incident + Legal
TMPL-CPT-001 Counterparty notification CIO + Head of Communications
All templates are reviewed semi-annually and updated following lessons learned
from incident communication exercises.
━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━
4. ESCALATION PATHS
4.1 Communication Escalation Chain
SOC / Incident Manager
→ CISO (all Severity 1-2 incidents, within 1 hour)
→ Head of Communications (if external communication required, within 2 hours)
→ CEO (if media statement required or public disclosure, within 4 hours)
→ Board Chair (if systemic impact or regulatory escalation, within 4 hours)
4.2 Regulatory Notification Escalation (DORA Article 19)
Major ICT Incident Detected
→ CISO classifies as major incident (within 2 hours)
→ Legal reviews notification content (within 3 hours)
→ Initial notification submitted to competent authority (within 4 hours)
→ Intermediate report submitted (within 72 hours)
→ Final report submitted (within 1 month)
4.3 Decision Authority
Communication Type Decision Authority
─────────────────────────────────────────────────────────────────────────────
Internal staff notification Head of Communications
Customer notification Head of Communications + CISO
Regulatory notification CISO + Legal
Press statement CEO + Head of Communications
Public disclosure CEO + Board Chair
Social media response Head of Communications (pre-approved only)
━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━
5. PUBLIC DISCLOSURE CRITERIA
Public disclosure of an ICT incident is required when any of the following
criteria are met:
Criterion Disclosure Timeline
─────────────────────────────────────────────────────────────────────────────
Personal data breach affecting >1,000 individuals Within 72 hours (GDPR)
Service disruption affecting >50% of customers Within 24 hours
Incident with potential systemic impact As directed by regulator
Incident attracting significant media attention Proactive statement within
4 hours of media enquiry
Vulnerability disclosure (coordinated) Per coordinated disclosure
timeline (typically 90 days)
Disclosure decisions are made by the CEO in consultation with the CISO, Head of
Communications, and Legal Counsel. The Board Chair is informed before any public
disclosure.
━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━
6. MEDIA HANDLING
6.1 Media Spokesperson
Primary spokesperson: CEO (for major incidents)
Secondary spokesperson: Head of Communications (for operational updates)
Technical spokesperson: CISO (for technical briefings, with CEO approval)
No other staff member is authorised to make public statements regarding
ICT incidents without explicit approval from the Head of Communications.
6.2 Media Response Procedures
— All media enquiries routed to the Communications team
— Initial holding statement issued within 2 hours of media enquiry
— Substantive statement issued within 4 hours (using pre-approved templates)
— Regular updates provided every 4 hours during active incidents
— Social media monitored continuously during incidents; responses limited
to pre-approved messaging
━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━
7. POST-INCIDENT COMMUNICATION
Following resolution of a major ICT incident:
— Customer follow-up communication within 5 business days
— Regulatory follow-up per DORA Article 19 final report timeline
— Internal lessons learned communication to all staff within 10 business days
— Board briefing at next scheduled Board meeting (or extraordinary session
if warranted)
━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━
COMMUNICATION SIMULATION
Last simulation date: 15 November 2024
Scenario: Simulated ransomware attack with customer data exposure
Participants: CISO, Head of Communications, Legal, CEO, Board Chair
Result: Regulatory notification template completed in 3.5 hours (within 4h target)
Findings: Customer notification template required update for GDPR-specific language
Next simulation: May 2025
━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━
Document History:
v2.1 10 Jan 2025 Updated for DORA compliance; added regulatory notification
templates per Article 19
v2.0 15 Jan 2024 Major revision; added social media handling
v1.5 12 Jan 2023 Annual review; updated stakeholder contact lists
Approved by: CEO and CISO
Signatures: [CEO] / [CISO]
Date: 10 January 2025
Example structured facts that Detrixa would extract from this evidence (synthetic data, deterministic seed).
ict_communication_plan_status — fs-ict-communication-plan
{
"factId": "c1d2e3f4-a5b6-7890-cdef-100000000019",
"evidenceId": "a0b1c2d3-e4f5-6789-abcd-100000000019",
"evidenceClassId": "ict-communication-plan",
"factType": "ict_communication_plan_status",
"data": {
"plan_version": "2.1",
"approval_date": "2025-01-10",
"has_notification_templates": true,
"has_escalation_paths": true,
"has_disclosure_criteria": true,
"stakeholder_categories_count": 6,
"last_simulation_date": "2024-11-15",
"includes_regulatory_notification": true,
"includes_media_handling": true
},
"provenance": "deterministic",
"extractorVersion": "dora-test-generator/0.1.0",
"extractedAt": "2025-01-15T09:00:00Z",
"supersededBy": null
}
fs-ict-communication-planDORA-Art16-P1approval_datestakeholder_categories_count{
"properties": {
"approval_date": {
"format": "date",
"type": "string"
},
"has_disclosure_criteria": {
"type": "boolean"
},
"has_escalation_paths": {
"type": "boolean"
},
"has_notification_templates": {
"type": "boolean"
},
"includes_media_handling": {
"type": "boolean"
},
"includes_regulatory_notification": {
"type": "boolean"
},
"last_simulation_date": {
"format": "date",
"type": "string"
},
"plan_version": {
"type": "string"
},
"stakeholder_categories_count": {
"minimum": 0,
"type": "integer"
}
},
"required": [
"plan_version",
"approval_date",
"has_notification_templates",
"has_escalation_paths",
"has_disclosure_criteria"
],
"type": "object"
}