FastBull BrokersView
Sign In

CySEC Informs Investment Firms and Crypto Providers on ICT and Operational Compliance

3 hours ago BrokersView

The Cyprus Securities and Exchange Commission (CySEC) has issued guidance to regulated entities, including investment firms and crypto-asset providers, emphasizing the importance of digital operational resilience under the EU’s Digital Operational Resilience Act (DORA) (EU Regulation 2022/2554). Firms are reminded to classify and report major ICT-related incidents accurately, maintain a documented ICT risk management framework, and designate responsible personnel for oversight and internal audits.

 

Recent industry events illustrate the operational risks at stake. For instance, a major cloud service outage last October disrupted trading platforms and brokerages, affecting trading engines, payment systems, and portfolio tools. The incident caused transaction delays and operational disruptions, highlighting the need for robust redundancy and contingency planning to safeguard clients and markets. Such events demonstrate why DORA’s framework on ICT governance, incident management, and internal controls is critical for market stability.

 

CySEC has also observed misclassification and delayed reporting of ICT incidents among firms, underscoring gaps in operational oversight. Entities are urged to comply with DORA’s requirements for annual framework reviews, internal audits, and segregation of duties between control functions, ICT risk management, and internal audit. Proper documentation and timely reporting ensure that potential ICT risks are identified early and addressed effectively, reducing operational and regulatory exposure.

 

BrokersView reminds Investment firms and crypto providers need to designate responsible ICT auditors and control function officers within CySEC’s portal, maintain annual audit cycles, and implement follow-up procedures for critical findings. Regular reviews of ICT risk management frameworks, timely reporting of incidents, and adherence to supervisory guidance help firms meet both CySEC obligations and DORA standards. These measures provide a structured approach to managing ICT risks while maintaining operational resilience across financial services.

Share

Loading...