Learning Objectives:
-
Understand the reporting and escalation requirements for cyber incidents.
-
Identify the key elements of effective incident reporting frameworks.
-
Recognise the role of escalation mechanisms in ensuring timely response.
-
Understand regulatory expectations for incident reporting.
6.1 The Importance of Incident Reporting
Effective incident reporting is essential for timely detection, response, and recovery from cyber incidents. The Central Bank of Nigeria’s Framework requires quarterly reports to the Board on the overall status of the cybersecurity programme, including “incidents recorded, status of losses and recoveries” .
The Central Bank of Eswatini’s Guidelines require that the cyber resilience framework include “timely communication to enable a financial institution to collaborate with relevant stakeholders to effectively respond to and recover from cyber attacks, whether on the financial institution or on the financial system as a whole” .
6.2 Key Elements of Incident Reporting Frameworks
Reporting Requirements: The Central Bank of Nigeria’s Framework requires quarterly reports to the Board on the overall status of the cybersecurity programme . The reports shall include cyber risk assessment reports, status of security initiatives, incidents recorded, vulnerability management reports, compliance status, and status of compliance with examination recommendations .
Escalation Procedures: The Central Bank of the UAE requires Open Finance Providers to establish a cybersecurity incident response and management plan to swiftly isolate and neutralise a cybersecurity threat and to resume affected services as soon as possible . The plan must describe the procedures to respond to plausible cyber threat scenarios .
Communication Protocols: The Central Bank of Eswatini’s Guidelines require timely communication to enable a financial institution to collaborate with relevant stakeholders to effectively respond to and recover from cyber attacks .
6.3 Escalation Mechanisms
Escalation mechanisms ensure that incidents are reported to the appropriate level of management in a timely manner. The Central Bank of Nigeria’s Framework requires Senior Management to provide periodic reports (at a minimum quarterly) to the Board on the overall status of the cybersecurity programme . The Board is also expected to receive information from the Audit function, which should be independent and staffed with skilled professionals .
The Saudi Central Bank’s Cybersecurity Framework requires entities to define, approve, implement, and communicate cyber security policies and procedures . This includes establishing clear escalation paths for cybersecurity incidents.
6.4 Regulatory Reporting
In addition to internal reporting, financial institutions may be required to report cyber incidents to regulators. The Central Bank of Nigeria’s Framework notes that incident reporting to the CBN is required, and the CBN’s Cybersecurity Self-Assessment Tool (CSAT) report must be submitted annually .
The ECB has announced that the annual IT Risk Questionnaire collection deadline will move from September 2026 to February 2027, reflecting the importance of comprehensive cyber risk reporting .