A permission, not an obligation
Chapter VI of Regulation (EU) 2022/2554 consists of a single article. Article 45 does not oblige financial entities to share threat information; it establishes that they may, and on what conditions. That clarification exists for a practical reason. Before it, entities and their counsel were genuinely unsure whether exchanging attack indicators with competitors held up against data protection, confidentiality of business information and competition law. Where legal certainty is missing, information stops moving.
Paragraph 1 describes the subject matter: cyber threat information and intelligence, including indicators of compromise, tactics, techniques and procedures, cyber security alerts and configuration tools.
The three conditions
| Condition | What is required |
|---|---|
| Purpose | The sharing aims to enhance digital operational resilience: raising awareness of cyber threats, limiting or impeding their ability to spread, supporting defence capabilities, threat detection techniques, mitigation strategies or response and recovery stages |
| Community | It takes place within trusted communities of financial entities |
| Form | It is implemented through information-sharing arrangements that protect the potentially sensitive nature of the information and are governed by rules of conduct in full respect of business confidentiality, protection of personal data in accordance with Regulation (EU) 2016/679, and guidelines on competition policy |
The third condition is where the substance sits. An informal exchange between colleagues does not satisfy it. What is required is a written basis with rules of conduct that address those three areas of law explicitly.
What belongs in a sharing arrangement
Article 45(2) names the points the arrangements have to define: the conditions for participation; where appropriate, the details on the involvement of public authorities and the capacity in which they may be associated; the involvement of ICT third-party service providers; and operational elements, including the use of dedicated IT platforms.
A further set of rules is needed, which the Regulation does not spell out but without which a community does not function: a handling and distribution scheme for shared information, rules on anonymising or aggregating case references, requirements on retention and deletion, accountability for the quality assurance of shared indicators, and a procedure for removing a participant.
Notifying the supervisor
Paragraph 3 contains the only genuine obligation in the article: financial entities notify the competent authorities of their participation in such arrangements upon validation of their membership, and of the cessation of membership once it takes effect. Anyone joining a sharing community should plan that notification in from the start rather than discovering it afterwards.
Three channels that are easy to confuse
Information sharing under Article 45 is not the reporting route in Chapter III, and the two should not share a process.
- Article 19(1). Mandatory reporting of major ICT-related incidents to the competent authority. Not voluntary.
- Article 19(2). Voluntary notification of significant cyber threats to the competent authority, where the entity considers the threat relevant to the financial system, service users or clients. A route upwards, to the supervisor.
- Article 45. Horizontal exchange between market participants. A route sideways, to peers.
All three can be used alongside one another, and they serve different purposes.
Why the effort pays
Threat intelligence is the one raw material in ICT risk management that gains value when it is shared. An indicator that triggers an incident in one entity can prevent five elsewhere. Article 13(1) already requires capabilities and staff to gather information on vulnerabilities and cyber threats and to analyse the impact they are likely to have on the entity's digital operational resilience. A sharing community is one of the few sources that shows threat activity an entity has not yet been hit by.
The benefit only materialises, though, if the organisation is set up to receive. Shared indicators have to reach detection systems, shared tactics have to reach test and exercise scenarios, shared alerts have to reach the incident management process. An entity that takes information in and files it has paid the cost without collecting the return.
How Rizzqo connects intelligence to your own estate
Shared threat intelligence becomes valuable only once you can answer whether it touches your own estate, and that takes a maintained inventory. In Rizzqo, DORA is held as a requirement catalogue of 73 controls, and its requirements hang on the systems, services and providers they apply to. When a report about an exploited weakness arrives, the affected technology is findable in the inventory, together with the primary assets built on it and the named owners.
The consequence can be carried on in the same place: as a risk assessment with a likelihood and an impact, or as a task with a recorded risk reduction that can be worked in Jira.