Economic impact


  1. For the purpose of determining the economic impact of the incident as referred to in Article 18(1), point (f), of Regulation (EU) 2022/2554, financial entitiesas defined in Article 2, points (a) to (t) shall, without accounting for financial recoveries, take into account the following types of direct and indirect costs and losses which they have incurred as a result of the incident:

    1. expropriated funds or financial assets for which they are liable, including assets lost to theft;

    2. costs for replacement or relocation of software, hardware or infrastructure;

    3. staff costs, including costs associated with replacement or relocation of staff, recruitment of extra staff, remuneration of overtime and recovery of lost or impaired skills;

    4. fees due to non-compliance with contractual obligations;

    5. costs for redress and compensation to customers;

    6. losses due to forgone revenues;

    7. costs associated with internal and external communication;

    8. advisory costs, including costs associated with legal counselling, forensic services and remediation services.

  2. Costs and losses referred to in paragraph 1 shall not include costs that are necessary for the day-to-day operation of the business, in particular the following:

    1. costs for general maintenance of infrastructure, equipment, hardware and software, and costs for keeping skills of staff up to date;

    2. internal or external costs to enhance the business after the incident, including upgrades, improvements and risk assessment initiatives;

    3. insurance premiums.

  3. Financial entitiesas defined in Article 2, points (a) to (t) shall calculate the amounts of costs and losses based on data available at the time of reporting. Where the actual amounts of costs and losses cannot be determined, financial entitiesas defined in Article 2, points (a) to (t) shall estimate those amounts.

  4. When assessing the economic impact of the incident, financial entitiesas defined in Article 2, points (a) to (t) shall sum up the costs and losses referred to in paragraph 1.