Source: OJ L, 2024/2690, 18.10.2024

Current language: EN

Article 4 Recurring incidents


Summary What does Article 4 of the Cybersecurity measures and significant incidents for relevant entities say?

This article establishes an important aggregation rule that directly extends the significance thresholds set out in Article 3.

Where individual incidents would not qualify as significant on their own, Article 4 provides that they can be treated collectively as a single significant incident if certain conditions are met together.

It is essentially a safeguard against repeated low-level incidents being overlooked simply because no single occurrence crosses the reporting threshold.

Important points:

  • Relevant entities must treat multiple individually non-significant incidents as one significant incident if all three cumulative conditions are satisfied simultaneously.
  • The three conditions are: the incidents occurred at least twice within 6 months, share the same apparent root cause, and collectively meet the financial impact threshold in Article 3(1)(a).
  • All three criteria must be met together — this is a conjunctive test, not a disjunctive one.

Springlex's summary of the article, a reading aid, not a substitute for the legal text.

Incidents that individually are not considered a significant incident within the meaning of Article 3, shall be considered collectively as one significant incident where they meet all of the following criteria:

  1. they have occurred at least twice within 6 months;

  2. they have the same apparent root cause;

  3. they collectively meet the criteria set out in Article 3(1)(a).

We're continuously improving our platform to serve you better.

Your feedback matters! Let us know how we can improve.

Found a bug?

Springflod is a Swedish boutique consultancy firm specialising in cyber security within the financial services sector.

We offer professional services concerning information security governance, risk and compliance.

Crafted with ❤️ by Springflod