Auditen
Home / Frameworks / DORA / Cyber threat information sharing
DORA · Art. 45

Cyber threat information sharing

Article 45 encourages financial entities to voluntarily exchange cyber threat information and intelligence with other financial entities and trusted third parties. The objective is to enhance the collective resilience of the EU financial sector by sharing indicators of compromise, attack patterns, and mitigation strategies.

What it means

The intent of this requirement is to move from isolated defense to a collective defense model. Rather than each firm discovering threats independently, DORA promotes a framework where intelligence about emerging threats is shared across the industry to prevent systemic failures.

In practice, this involves establishing mechanisms to both send and receive technical intelligence. This includes sharing "Tactics, Techniques, and Procedures" (TTPs) used by attackers or specific indicators of compromise (IoCs), such as malicious IP addresses or file hashes.

Crucially, this information exchange must be conducted securely and in full compliance with data protection laws, specifically GDPR. The focus is on technical threat data, not the sharing of sensitive customer data or proprietary business secrets.

How to meet it

Evidence an auditor asks for

  • A written Cyber Threat Intelligence (CTI) policy or procedure document detailing the sharing framework.
  • Proof of membership or active participation in threat-sharing forums or ISACs.
  • Logs or records showing the transmission of threat data to peers and the receipt of intelligence feeds.
  • Documentation demonstrating that received intelligence led to a specific security control update (e.g., a change request ticket linked to a peer's threat alert).
  • A data privacy impact assessment or checklist proving that shared information is scrubbed of PII.

Common pitfalls

  • Confusing voluntary "threat sharing" with the mandatory "major incident reporting" requirements found in other sections of DORA.
  • Treating intelligence as a passive activity (only consuming feeds) rather than an active exchange (contributing back to the community).
  • Failing to implement technical scrubbing, leading to accidental GDPR violations when sharing logs or headers that contain user data.