Source: OJ L 333, 27.12.2022, p. 80–152
ENRecital 101 Multi-stage incident reporting approach
This Directive lays down a multiple-stage approach to the reporting of significant incidents means an incident as defined in Article 6, point (6), of Directive (EU) 2022/2555; in order to strike the right balance between, on the one hand, swift reporting that helps mitigate the potential spread of significant incidents means an incident as defined in Article 6, point (6), of Directive (EU) 2022/2555; and allows essential and important entities means a natural or legal person created and recognised as such under the national law of its place of establishment, which may, acting under its own name, exercise rights and be subject to obligations; to seek assistance, and, on the other, in-depth reporting that draws valuable lessons from individual incidents means an incident as defined in Article 6, point (6), of Directive (EU) 2022/2555; and improves over time the cyber resilience of individual entities means a natural or legal person created and recognised as such under the national law of its place of establishment, which may, acting under its own name, exercise rights and be subject to obligations; and entire sectors. In that regard, this Directive should include the reporting of incidents means an incident as defined in Article 6, point (6), of Directive (EU) 2022/2555; that, based on an initial assessment carried out by the entity means a natural or legal person created and recognised as such under the national law of its place of establishment, which may, acting under its own name, exercise rights and be subject to obligations; concerned, could cause severe operational disruption of the services or financial loss for that entity means a natural or legal person created and recognised as such under the national law of its place of establishment, which may, acting under its own name, exercise rights and be subject to obligations; or affect other natural or legal persons by causing considerable material or non-material damage. Such initial assessment should take into account, inter alia, the affected network and information systems means: an electronic communications network as defined in Article 2, point (1), of Directive (EU) 2018/1972; any device or group of interconnected or related devices, one or more of which, pursuant to a programme, carry out automatic processing of digital data; or digital data stored, processed, retrieved or transmitted by elements covered under points (a) and (b) for the purposes of their operation, use, protection and maintenance;, in particular their importance in the provision of the entity means a natural or legal person created and recognised as such under the national law of its place of establishment, which may, acting under its own name, exercise rights and be subject to obligations;’s services, the severity and technical characteristics of a cyber threat means a cyber threat as defined in Article 2, point (8), of Regulation (EU) 2019/881; and any underlying vulnerabilities means a weakness, susceptibility or flaw of a product with digital elements that can be exploited by a cyber threat; that are being exploited as well as the entity means a natural or legal person created and recognised as such under the national law of its place of establishment, which may, acting under its own name, exercise rights and be subject to obligations;’s experience with similar incidents means an incident as defined in Article 6, point (6), of Directive (EU) 2022/2555;. Indicators such as the extent to which the functioning of the service is affected, the duration of an incident means an incident as defined in Article 6, point (6), of Directive (EU) 2022/2555; or the number of affected recipients of services could play an important role in identifying whether the operational disruption of the service is severe.