Cyber threat information sharing
Article 45 encourages financial entities to voluntarily exchange cyber threat information and intelligence with other financial entities and trusted third parties. The objective is to enhance the collective resilience of the EU financial sector by sharing indicators of compromise, attack patterns, and mitigation strategies.
What it means
The intent of this requirement is to move from isolated defense to a collective defense model. Rather than each firm discovering threats independently, DORA promotes a framework where intelligence about emerging threats is shared across the industry to prevent systemic failures.
In practice, this involves establishing mechanisms to both send and receive technical intelligence. This includes sharing "Tactics, Techniques, and Procedures" (TTPs) used by attackers or specific indicators of compromise (IoCs), such as malicious IP addresses or file hashes.
Crucially, this information exchange must be conducted securely and in full compliance with data protection laws, specifically GDPR. The focus is on technical threat data, not the sharing of sensitive customer data or proprietary business secrets.
How to meet it
- Establish a formal internal policy defining what constitutes "shareable" cyber threat intelligence versus confidential corporate data.
- Join one or more recognized industry sharing communities, such as an Information Sharing and Analysis Center (ISAC) or a sectoral CERT.
- Implement technical standards for the exchange of intelligence to ensure interoperability, such as STIX (Structured Threat Information Expression) and TAXII (Trusted Automated Exchange of Intelligence Information).
- Define clear protocols for the anonymization and scrubbing of data to ensure no personally identifiable information (PII) is shared during threat exchanges.
- Create a workflow for "actioning" received intelligence, ensuring that alerts from peers are integrated into security monitoring tools (e.g., SIEM or Firewall blocklists).
Evidence an auditor asks for
- A written Cyber Threat Intelligence (CTI) policy or procedure document detailing the sharing framework.
- Proof of membership or active participation in threat-sharing forums or ISACs.
- Logs or records showing the transmission of threat data to peers and the receipt of intelligence feeds.
- Documentation demonstrating that received intelligence led to a specific security control update (e.g., a change request ticket linked to a peer's threat alert).
- A data privacy impact assessment or checklist proving that shared information is scrubbed of PII.
Common pitfalls
- Confusing voluntary "threat sharing" with the mandatory "major incident reporting" requirements found in other sections of DORA.
- Treating intelligence as a passive activity (only consuming feeds) rather than an active exchange (contributing back to the community).
- Failing to implement technical scrubbing, leading to accidental GDPR violations when sharing logs or headers that contain user data.