ECB sanctions ABANCA for failing to report cyber incident within deadline

Europe

ECB sanctions ABANCA for failing to report cyber incident within deadline.

  • ECB-supervised banks must report significant cyber incidents within two hours of detection
  • Bank knowingly breached its reporting obligation in February 2019
  • ECB imposes €3,145,000 penalty on ABANCA

The European Central Bank (ECB) has imposed an administrative penalty of €3,145,000 on ABANCA Corporación Bancaria, S.A. (ABANCA) after it knowingly failed to report a significant cyber incident to the ECB within the prescribed two-hour deadline outlined in the cyber-incident reporting framework implemented in 2017.

In February 2019 ABANCA became the target of a cyber-attack when its IT systems were infected with malicious software. ABANCA responded by temporarily suspending internet and mobile banking services, ATM services and SWIFT payment services, among other measures.

Despite being aware of its reporting obligation and the significance of the cyber incident as early as 26 February 2019, the bank submitted the required report on the incident46 hours after the prescribed deadline. The bank’s omission hindered the ECB’s ability to properly assess ABANCA’s prudential situation and to react in a timely manner to potential threats to other banks, what could have had potential consequences on the reputation and the stability of the banking sector as a whole.

The entity promptly addressed the effects of the cyber-incident at the time it occurred. The ECB notes that the penalty relates solely to the breach of a reporting obligation in February 2019 and does not entail any assessment of the soundness of the bank’s existing IT systems.

When deciding on the level of a penalty, the ECB applies its guide to the method of setting administrative pecuniary penalties. Out of the severity categories “minor”, “moderately severe”, “severe”, “very severe” and “extremely severe”, the ECB classified the breach as severe. More details are available on the supervisory sanctions page.

The bank has the right to challenge the ECB’s decision before the Court of Justice of the European Union

 

ecb.europa.eu

pixabay

Leave a Reply

Your email address will not be published. Required fields are marked *