• news-banner

    Expert Insights

Cyber Co-ordination 2024 - new MOU on co-operation between EBA, ESMA, EIOPA and ENISA

min read

The wave of legislation from the European Union in relation to cyber, operational resilience and ICT risk continues to demand unprecedented co-operation between European authorities.  

Our previous paper from March 2024 highlighted the European Systemic Risk Board’s (ESRB) review of macroprudential frameworks for cyber resilience (16 April 2024).   

Four authorities, the European Banking Authority (EBA), European Insurance and Occupational Pensions Authority (EIOPA), European Securities and Markets Authority (ESMA) and European Union Agency for Cyber Security (ENISA) have issued a Memorandum of Understanding to co-ordinate further their activities in this area. While the MOU is not binding, it sets out clear guides for strategic co-operation between authorities.  

The MOU sets out a framework for co-operation and exchange of information between these European supervisory authorities, including in the areas covered by the NIS2 Directive, DORA and other areas of mutual interest. This is important, as regulated firms require consistency between their respective obligations in order to manage the increasing complex and hostile cyber environment.  

The MOU is very short consisting of six articles. The key substance is the ten points in article 2 which emphasises that the parties will co-operate to implement “the tasks of common interest stemming from the NIS Directive and DORA”. In particular this relates to:

  • reporting of major ICT-related incidents;
  • development of draft technical standards;
  • mechanisms to share effective practices across sectors or the provision of technical advice and sharing of “hands on” experience on oversight activities. 

ENISA will facilitate the participation of the various supervisory authorities in this context in order to collaborate on the implementation of efficient instant reporting processes for the EU financial sector. In this regard ENISA will support in the implementation of an IT tool for instant reporting based on ENISAs cyber incident reporting and analysis system (CIRAS) tool. As further undertaking of the parties to collaborate on the development of the Pan-European systemic cyber incident co-ordination framework (EU-SCICF). This resulted from the recommendation of the ESRB from 2021 and follow-on operational policy review from April 2024.

Of course, these obligations will require co-ordination and development of capability consistently across the authorities and exchange of information and views in relation to cyber risk, emerging technologies of mutual consent and common strategic interests. This does not explicitly include AI, but the risks from AI are implicitly covered within cyber. 

The parties will establish a single contact point organisation for monitoring the MOU, including a work plan which will be reported on at least once a year to specify the initiatives and actions and appropriate allocation of tasks between the parties. 

Whilst the MOU is high level at present, the parties can agree to establish joint or bi-lateral service level agreements on instant reporting, cyber security audits trainings or other topics within their fields of competence. As such it will be necessary for firms to continue to monitor each of the ESAs’ own releases in order to establish the co-ordination. 

In terms of reporting frameworks, the indication of the reporting tool is a useful insight, and firms should keep their contractual contracts, contractual obligations and reporting procedures up to date to cover the co-ordinated approach and ensure its supply chain is fully appraised of the consolidated reporting obligations and multi regulator coordination.

Our thinking

  • IBA Annual Conference 2026

    Jean-Baptiste Beauvoir-Planson

    Events

  • A practical guide to choosing the right AI tools for your law firm: How to Choose the Right AI Vendor

    Tessa Bartley

    Quick Reads

    min read
  • Swiss executors dealing with UK assets – what do I do? Part two

    Sophie Hart

    Quick Reads

    min read
  • Costs, Conduct & Counter-Offers – Key Takeaways from the Bankside rights of light costs decision

    Georgina Muskett

    Insights

    min read
  • Update: Objectivity in section 172 Companies Act 2006: Re-examining the Current Position after Saxon Woods Investments Ltd v Costa

    Andrew Collins

    Insights

    min read
  • 9fin quotes Jamie Rhodes and Tom Smitham on the growing role of private capital in football finance

    Jamie Rhodes

    In the Press

    min read
  • The National Security and Investment Act, Five Years On: What the 2025-26 Annual Report Tells Foreign Buyers

    Greg Stonefield

    Insights

    min read
  • Jersey Trade Mark Reform: What the New Regime Means for You

    Dewdney William Drew

    Quick Reads

    min read
  • The Telegraph quotes Julia Cox on the growing use of Family Investment Companies for inheritance planning

    Julia Cox

    In the Press

    min read
  • Tessa Bartley comments in Legal Futures about our framework for choosing the right legal AI tools

    Tessa Bartley

    In the Press

    min read
  • Investors’ Chronicle quotes Katie Talbot on the risks and responsibilities of undertaking a trustee position

    Katie Talbot

    In the Press

    min read
  • Chiara Muston comments in Employee Benefits on minimum wage enforcement changes

    Chiara Muston

    In the Press

    min read
  • Retail Collection: Reputation management for brand founders

    Claudine Morgan

    Podcasts

  • Charlie Ring and Mike Barrington write for Professional Adviser on how best to prepare for the sale of a financial services business

    Charlie Ring

    In the Press

    min read
  • EU Packaging and Packaging Waste Regulation (PPWR)

    Kerry Stares

    Insights

    min read
  • A practical guide to choosing the right AI tools for your law firm: Five Insights that surprised us the most

    Tessa Bartley

    Quick Reads

    min read
  • Beware the “late invoice” clause: TCC confirms the final date for payment must be fixed to the due date

    William Turner

    Insights

    min read
  • Fraudsters in the Inbox: The Limits of Contractual Causation in Logix Aero v Siam Aero

    Natalya Stone

    Insights

    min read
  • Light Bites, expert nuggets for the seasoned developer: bonus episode

    James Souter

    Podcasts

  • Mace Construct Ltd v Baltic Investment Holdings Ltd: A case highlighting the risk of including tender clarifications and schedules of derogations in building contracts

    Henry Dalton

    Insights

    min read
Back to top