Geteiltes Wissen, gestärkte Resilienz: Informationsaustausch über Cyberbedrohungen gemäß Art. 45 DORA
摘要
The escalating threat of cyberattacks poses significant challenges, particularly for the financial sector. The Digital Operational Resilience Act (DORA), which comes into force in the EU on January 17, 2025, therefore obliges financial entities to implement a comprehensive ICT risk management framework to bolster their digital operational resilience. The exchange of information and intelligence about cyber threats, in particular so-called threat intelligence, plays a central role in protecting against cyber attacks. DORA facilitates the Europe-wide exchange of information among financial entities by establishing a unified legal framework for the first time. Until now, this exchange has primarily occurred at the national level. This article explores the regulatory framework governing the exchange of cyber threat information and intelligence under DORA. Particular attention is paid to the interdependencies with trade secret protection law, data protection law, and competition law. Furthermore, existing cooperative frameworks are presented, including the Alliance for Cyber Security, the Cyber Security Sharing and Analytics Association, the European Cloud User Coalition, and the TIBER-DE Community.