Cómo implementar la notificación de incidentes DORA utilizando IA
Aprenderás cómo implementar los requisitos de notificación de incidentes relacionados con las TIC de DORA según los Artículos 17-23 utilizando IA. Esta guía cubre los criterios de clasificación de incidentes…
Visión general
Aprenderás cómo implementar los requisitos de notificación de incidentes relacionados con las TIC de DORA según los Artículos 17-23 utilizando IA. Esta guía cubre los criterios de clasificación de incidentes, los plazos de notificación obligatorios de 4 horas/72 horas/1 mes, plantillas de notificación, procedimientos de análisis de causa raíz e integración con tus procesos existentes de gestión de incidentes, con indicaciones específicas de ISMS Copilot para generar cada componente.
A quién va dirigido
Esta guía es para:
- Gestores de respuesta a incidentes y líderes de SOC responsables de la detección y clasificación de incidentes relacionados con las TIC
- Oficiales de cumplimiento que gestionan notificaciones regulatorias de incidentes
- CISOs que supervisan programas de gestión de incidentes en entidades financieras
- Gestores de riesgos que evalúan el impacto de los incidentes y realizan seguimiento de la remediación
- Consultores que implementan la notificación de incidentes DORA para clientes de entidades financieras
Antes de comenzar
Necesitarás:
- Una cuenta de ISMS Copilot (prueba gratuita disponible)
- Tu marco de gestión de riesgos de las TIC establecido según How to build a DORA ICT risk management framework using AI
- Tu inventario de activos de las TIC con clasificaciones de criticidad (necesario para la evaluación del impacto de los incidentes)
- Tus procedimientos existentes de respuesta a incidentes y cualquier proceso actual de notificación regulatoria
- Conocimiento de los canales y formatos de notificación de tu autoridad competente
- Acceso a tu equipo de respuesta a incidentes, SOC y función de cumplimiento
Obligaciones críticas en tiempo: DORA requiere la notificación inicial de incidentes mayores relacionados con las TIC en un plazo de 4 horas desde su clasificación. Este es uno de los plazos de notificación más ajustados en la regulación financiera de la UE. Tus procedimientos de clasificación y notificación de incidentes deben estar preconstruidos, probados y comprendidos por todo el personal relevante antes de que ocurra un incidente.
Comprensión de los requisitos de notificación de incidentes de DORA
Desglose artículo por artículo
El Capítulo III de DORA (Artículos 17-23) establece un régimen integral de gestión y notificación de incidentes. Cada artículo aborda un aspecto específico del proceso:
Article
Title
Key requirements
Key deliverables
Art 17
ICT-related incident management process
Establish incident management process with early warning indicators, procedures, and roles
Incident management process document, roles matrix
Art 18
Classification of ICT-related incidents and cyber threats
Classify incidents using prescribed criteria (major vs non-major)
Classification matrix, severity criteria, decision flowchart
Art 19
Reporting of major ICT-related incidents
Three-stage reporting: initial (4h), intermediate (72h), final (1 month)
Report templates, escalation procedures, submission workflows
Art 20
Harmonisation of reporting content and templates
Standardized report formats per RTS
Completed report templates aligned with RTS formats
Art 21
Centralisation of reporting
Reporting through single EU Hub (future requirement)
Reporting channel procedures
Art 22
Supervisory feedback
Receive and act on supervisory feedback
Feedback integration process
Art 23
Notification of significant cyber threats
Voluntary notification of significant cyber threats
Threat notification procedures
El plazo de notificación en tres etapas
Comprender el plazo de notificación de DORA es crítico para construir tus procedimientos:
Report stage
Deadline
Trigger
Content required
Key challenge
Initial notification
Within 4 hours of classifying as major
Incident classified as major
Incident summary, classification rationale, initial impact assessment, affected services
Speed of classification and submission
Intermediate report
Within 72 hours of initial notification
Ongoing investigation
Updated impact, root cause analysis (initial), containment measures, recovery status
Providing meaningful analysis while incident may be ongoing
Final report
Within 1 month of initial notification
Incident resolution
Complete root cause, total impact (financial, operational, reputational), remediation actions, lessons learned
Comprehensive analysis and remediation evidence
El plazo de 4 horas comienza en el momento de la clasificación como incidente mayor, no desde el momento de la detección. Sin embargo, DORA también requiere procesos de detección y clasificación rápidos. Si tu clasificación se retrasa de manera irrazonable, los reguladores pueden considerarlo como incumplimiento del espíritu del requisito de notificación.
Paso 1: Establece tu proceso de gestión de incidentes (Artículo 17)
Proceso central de gestión de incidentes
El Artículo 17 requiere un proceso integral de gestión de incidentes relacionados con las TIC. Este proceso debe estar integrado con tus capacidades de detección (Artículo 10) y tu marco más amplio de gestión de riesgos de las TIC.
-
Abre tu espacio de trabajo de DORA en ISMS Copilot
-
Genera el proceso de gestión de incidentes:
"Create a comprehensive ICT-related incident management process for a [entity type] satisfying DORA Article 17. Include: purpose, scope, and process objectives, incident lifecycle phases (detection, triage, classification, containment, eradication, recovery, post-incident review), roles and responsibilities (incident commander, technical lead, communications lead, compliance/regulatory reporting, management body liaison), early warning indicators and detection triggers (linking to Article 10 monitoring), escalation matrix by incident severity, communication protocols (internal teams, management body, clients, competent authority), integration with existing IT service management (ITSM) processes, documentation and evidence preservation requirements, process activation criteria and decision trees, and process performance metrics. Provide the process in flowchart-ready format with clear decision points."
-
Define la estructura del equipo de respuesta a incidentes:
"Define the ICT incident response team (IRT) structure for a [entity type] with [number] employees. Include: team composition (core team, extended team, on-call roster), team leader selection criteria and authority levels, activation procedures (business hours and after hours), communication channels and tools, team member contact directory template, training and exercise requirements, and integration with external parties (regulators, law enforcement, forensic providers, third-party ICT providers). Address 24/7 coverage requirements for meeting the 4-hour notification deadline."
Consejo profesional: El reloj de notificación de 4 horas comienza en la clasificación, por lo que tu proceso de triaje a clasificación es crítico. Diseñalo para completarse en un máximo de 1-2 horas, dejando 2-3 horas para la preparación y envío del informe. Prepuebla las plantillas de informes con datos organizativos permanentes para reducir el tiempo de preparación bajo presión.
Paso 2: Construye tu matriz de clasificación de incidentes (Artículo 18)
Criterios de clasificación de incidentes mayores
El Artículo 18 establece criterios para clasificar los incidentes relacionados con las TIC como mayores. Los Estándares Técnicos Regulatorios (RTS) proporcionan umbrales de materialidad detallados. Tu matriz de clasificación debe operacionalizar estos criterios para una toma de decisiones rápida durante un incidente.
-
Genera la matriz de clasificación:
"Create an ICT-related incident classification matrix for a [entity type] that satisfies DORA Article 18. Include the following classification criteria from the regulation and RTS: number of clients/financial counterparties affected (provide specific thresholds for our entity type), duration of the incident, geographical spread of the incident, data losses (confidentiality, integrity, availability), criticality of services affected (mapped to our ICT asset classification), economic impact (direct and indirect financial losses), reputational impact assessment. For each criterion, define: specific quantitative thresholds that trigger 'major' classification, measurement methodology, data sources for rapid assessment, and examples. Create a scoring matrix that allows classification within 1-2 hours of incident detection. Include a decision flowchart: if any single criterion meets the major threshold, the incident is classified as major."
-
Crea el diagrama de flujo de decisión de clasificación:
"Design a step-by-step incident classification decision flowchart for DORA Article 18. The flowchart should be usable by on-call incident managers at 3 AM with limited information. Start with: initial incident details (what happened, when, what is affected). Then assess each major incident criterion sequentially: clients affected (threshold: [X]), duration (threshold: [X] hours), data impact (any confirmed data breach), critical services affected (any service on our critical list), economic impact (estimated above [X] EUR). If any criterion is met, classify as MAJOR and trigger 4-hour reporting. If borderline, escalate to [role] for classification decision. If no criteria met, classify as non-major and follow standard incident process. Provide guidance for situations with incomplete information."
Clasificación bajo incertidumbre: Durante las primeras horas de un incidente, rara vez se dispone de información completa. DORA espera que clasifiques basándote en la información disponible y actualices si la clasificación cambia. Diseña tu proceso para clasificar de manera conservadora (en caso de duda, clasifica como mayor) y degrada más tarde si es apropiado. La subnotificación es un riesgo regulatorio mayor que la sobrenotificación.
Seguimiento de incidentes no mayores
Aunque solo los incidentes mayores requieren notificación regulatoria, DORA exige que registres y analices todos los incidentes relacionados con las TIC:
"Create a non-major ICT incident tracking and analysis procedure for DORA compliance. Include: recording requirements for all ICT incidents (incident register template), trend analysis methodology (identify patterns that could indicate systemic issues), escalation criteria (when accumulation of non-major incidents suggests a major issue), periodic reporting to management (frequency, format, content), and integration with the continuous improvement process under Article 13. Provide a quarterly incident trend report template."
Paso 3: Crea plantillas de notificación regulatoria (Artículos 19-20)
Plantilla de notificación inicial (4 horas)
La notificación inicial debe enviarse a tu autoridad competente dentro de las 4 horas siguientes a la clasificación de un incidente como mayor. Construye plantillas prepobladas para cumplir con este plazo:
-
Genera la plantilla de notificación inicial:
"Create an initial incident notification template for DORA Article 19 (4-hour deadline). Pre-populate with standing organizational data. Include fields for: reporting entity identification (name, LEI, entity type, competent authority), incident identifier and classification date/time, incident description (what happened, initial timeline), classification rationale (which major criteria are met, with evidence), services affected and initial impact assessment, number of clients potentially affected (estimate if exact not known), geographical scope, initial containment actions taken, estimated duration if known, contact details for follow-up, and cross-border impact indicator. Design the template so it can be completed in under 60 minutes with the information available at classification time. Include guidance notes for each field."
-
Genera la plantilla de informe intermedio (72 horas):
"Create an intermediate incident report template for DORA Article 19 (72-hour deadline). Include fields for: reference to initial notification, updated incident timeline, updated impact assessment (clients affected, financial impact, data impact), root cause analysis (preliminary findings), containment and mitigation measures implemented, recovery status and estimated timeline, any changes to incident classification, communication actions taken (clients, counterparties, public), involvement of external parties (law enforcement, forensic providers), updated risk assessment, and any supervisory actions requested. Include guidance on providing meaningful root cause analysis even when investigation is ongoing."
-
Genera la plantilla de informe final (1 mes):
"Create a final incident report template for DORA Article 19 (1-month deadline). Include comprehensive sections for: complete incident timeline (detection through resolution), confirmed root cause analysis (technical and organizational), total impact assessment (financial losses quantified, clients affected, services disrupted, data compromised), full description of containment, eradication, and recovery actions, effectiveness assessment of existing controls, remediation plan (actions, owners, deadlines, status), lessons learned and framework improvements, management body notification and decisions, regulatory reporting timeline compliance, and cross-references to any related incidents. This report should be suitable for supervisory review and serve as input to the post-incident review process under Article 13."
Consejo profesional: Prepuebla la sección de identificación organizativa de las tres plantillas con tus datos permanentes (nombre de la entidad, LEI, detalles de la autoridad competente, contacto principal). Guarda estas plantillas prepobladas en un lugar accesible para tu equipo de respuesta a incidentes. Durante un incidente real, cada minuto ahorrado en campos administrativos es un minuto ganado para el análisis sustantivo.
Procedimientos de envío
Establece procedimientos claros para enviar informes a tu autoridad competente:
"Create an incident report submission procedure for DORA regulatory notifications. Include: identification of our competent authority and their reporting channel (portal, email, API), submission authorization (who can authorize submission and at what time of day), quality review checklist before submission (completeness, accuracy, consistency with previous reports), submission confirmation and tracking, procedures for submitting outside business hours (for the 4-hour deadline), backup submission methods if primary channel is unavailable, record-keeping requirements (copies of all submissions with timestamps), and procedures for handling supervisory feedback under Article 22. Address the scenario where the incident itself affects our ability to submit reports."
Paso 4: Construye procedimientos de escalada y comunicación
Matriz de escalada interna
Una escalada efectiva es crítica para cumplir con los plazos ajustados de DORA. Define rutas claras de escalada para cada escenario:
-
Genera la matriz de escalada:
"Create an ICT incident escalation matrix for a [entity type] covering DORA reporting requirements. Define escalation levels: Level 1 (SOC/IT Operations): initial detection and triage, Level 2 (Incident Response Team): investigation and containment, Level 3 (CISO/CRO): major incident classification decision, Level 4 (Management Body): notification of major incidents, regulatory communication approval. For each level, specify: escalation criteria (what triggers escalation to next level), escalation timeline (maximum time at each level before escalation), notification method and contact details, information to provide when escalating, and decision authority at each level. Include after-hours escalation procedures and backup contacts. Design to ensure classification can occur within 2 hours of detection."
-
Crea procedimientos de notificación a clientes:
"Develop client notification procedures for major ICT incidents under DORA. Include: criteria for when clients must be notified, notification timing relative to regulatory reporting, notification content (what to disclose, what to withhold during investigation), communication channels (email, portal, phone for critical clients), template client notifications for common incident types (service outage, data breach, system degradation), follow-up communication cadence, and record-keeping requirements. Address scenarios where the incident affects our ability to communicate with clients."
DORA Article 19(3) requiere que las entidades financieras informen a sus clientes sobre incidentes mayores relacionados con las TIC que afecten sus intereses financieros. También debes comunicar las medidas correctivas tomadas. Incorpora esta comunicación con los clientes en tu proceso de respuesta a incidentes desde el principio.
Notificación al órgano de dirección
El Artículo 5 requiere que el órgano de dirección sea informado sobre los incidentes relacionados con las TIC. Define cómo ocurre esto durante los incidentes:
"Create a management body incident notification procedure for DORA Article 5 compliance. Include: notification triggers (all major incidents, significant non-major incidents), notification timeline (within [X] hours of classification), notification format (structured briefing template), content (incident summary, impact assessment, response actions, regulatory reporting status, client impact, media risk), decision points requiring management body input (public communications, client compensation, regulatory engagement), follow-up reporting cadence during ongoing incidents, and post-incident briefing and lessons learned presentation. Provide the management body incident briefing template."
Paso 5: Integra con la gestión de incidentes existente
Mapeo de los requisitos de DORA a tus procesos actuales
La mayoría de las entidades financieras ya tienen procesos de gestión de incidentes. Utiliza ISMS Copilot para integrar los requisitos de DORA en tu marco existente en lugar de crear procesos paralelos:
"We currently use [ITIL/NIST/custom] incident management processes with [describe current tools: ServiceNow, Jira, PagerDuty, etc.]. Map DORA Article 17-23 requirements to our existing process. Identify: where our current process already satisfies DORA (detection, triage, containment, recovery), where we need to add DORA-specific steps (major incident classification, regulatory reporting, client notification), process modifications needed (timeline compression, escalation enhancements), tooling changes required (classification automation, report generation, submission tracking), and documentation updates needed. Provide a gap analysis with specific remediation actions."
Automatización de la clasificación y notificación
Dado el plazo de 4 horas, considera oportunidades de automatización:
"Identify opportunities to automate DORA incident classification and reporting for a [entity type]. Consider: automated collection of classification data points (number of affected clients from monitoring systems, service availability metrics, transaction volume impacts), automated pre-population of report templates from incident management tools, automated calculation of major incident criteria thresholds, workflow automation for escalation and notifications, integration between SIEM/incident platform and reporting workflow, automated deadline tracking and reminder alerts, and automated compilation of incident metrics for trend analysis. Provide implementation recommendations prioritized by impact on the 4-hour deadline."
Consejo profesional: Incluso si no puedes automatizar completamente la clasificación, automatiza la recopilación de datos que informan las decisiones de clasificación. Si tus sistemas pueden informar automáticamente cuántos clientes se ven afectados, qué servicios están degradados y durante cuánto tiempo, tu decisión de clasificación será mucho más rápida y defendible ante los reguladores.
Paso 6: Procedimientos de análisis de causa raíz
Metodología estructurada de análisis de causa raíz
DORA requiere un análisis de causa raíz como parte de los informes intermedios (72 horas) y finales (1 mes). Establece una metodología estandarizada:
-
Genera la metodología de RCA:
"Create a root cause analysis (RCA) methodology for DORA ICT incident reporting. Include: RCA initiation criteria and timing (start within 24 hours of major incident classification), investigation methods (5 Whys, fishbone/Ishikawa, fault tree analysis, timeline analysis), evidence collection and preservation procedures, technical investigation steps (log analysis, forensics, system examination), organizational investigation steps (process review, policy compliance, training adequacy), root cause categories (technical failure, human error, process gap, third-party failure, external attack, design flaw), preliminary RCA process for the 72-hour intermediate report (structured even with incomplete information), comprehensive RCA process for the 1-month final report, quality review of RCA findings before submission, and linkage between root causes and remediation actions. Provide an RCA report template with examples."
-
Crea procedimientos de seguimiento de remediación:
"Develop a post-incident remediation tracking procedure for DORA compliance. Include: how remediation actions are identified from RCA findings, action prioritization methodology (critical, high, medium based on risk), action assignment (owner, deadline, resources), progress tracking and reporting, management body oversight of remediation progress, verification of remediation effectiveness, closure criteria for remediation actions, and integration with the ICT risk register (updating risk assessments based on incident findings). Provide a remediation tracking register template."
Paso 7: Notificación de ciberamenazas (Artículo 23)
Notificación voluntaria de amenazas
El Artículo 23 alienta a las entidades financieras a notificar a las autoridades competentes sobre ciberamenazas significativas, incluso si aún no han resultado en incidentes. Establece procedimientos para esta notificación voluntaria:
"Create a significant cyber threat notification procedure for DORA Article 23. Include: criteria for what constitutes a 'significant cyber threat' warranting voluntary notification (targeted attacks detected but contained, intelligence on imminent threats, zero-day vulnerabilities affecting critical systems, threat patterns across the sector), internal assessment and decision process (who decides whether to notify), notification template for cyber threats (different from incident reports), timing expectations (not mandated but should be prompt), confidentiality considerations and information sharing limitations, and benefits of voluntary reporting (supervisory goodwill, sector-wide protection, intelligence sharing). Provide decision criteria and a notification template."
Paso 8: Prueba tu capacidad de notificación de incidentes
Ejercicios de simulación y mesas de trabajo
Tus procedimientos de clasificación y notificación de incidentes deben probarse antes de que ocurra un incidente real. Utiliza ISMS Copilot para diseñar ejercicios realistas:
-
Diseña escenarios de ejercicios de mesa:
"Design three tabletop exercise scenarios for testing our DORA incident classification and reporting procedures. Each scenario should: be realistic for a [entity type], unfold over multiple phases (initial detection, escalation, containment, reporting), test the major incident classification decision, test the 4-hour initial notification process end-to-end, include complications (incomplete information, after-hours detection, multiple simultaneous issues), test client communication triggers, and require management body notification. Scenarios should cover: (1) ransomware attack affecting critical banking/payment systems, (2) cloud provider outage affecting multiple services, (3) data breach discovered through external notification. For each scenario, provide an exercise facilitator guide with inject timeline, expected participant actions, and evaluation criteria."
-
Crea un marco de evaluación de ejercicios:
"Create an evaluation framework for DORA incident reporting tabletop exercises. Evaluate: time from detection to classification (target under 2 hours), time from classification to initial notification submission (target under 4 hours), accuracy of classification decision, completeness of initial notification, quality of escalation and communication, management body notification effectiveness, client communication appropriateness, documentation quality, and team coordination. Provide a scoring rubric and post-exercise report template."
Expectativa de auditoría: Las autoridades competentes esperan evidencia de que tus procedimientos de notificación de incidentes han sido probados. Realiza ejercicios de mesa al menos anualmente (con mayor frecuencia en el primer año de implementación) y documenta los resultados, lecciones aprendidas y mejoras realizadas. Esta evidencia demuestra a los reguladores que tu capacidad de notificación en 4 horas es genuina, no teórica.
Próximos pasos
Ahora tienes una capacidad integral de notificación de incidentes DORA:
- Proceso de gestión de incidentes integrado con capacidades de detección
- Matriz de clasificación con umbrales cuantitativos para incidentes mayores
- Plantillas de notificación regulatoria en tres etapas (4 horas, 72 horas, 1 mes)
- Matriz de escalada con autoridades de decisión y plazos claros
- Metodología de análisis de causa raíz con seguimiento de remediación
- Procedimientos de notificación de ciberamenazas
- Procedimientos probados mediante ejercicios de mesa
Continúa con las siguientes guías de esta serie DORA:
- How to plan DORA resilience testing using AI -- Diseña tu programa de pruebas, incluyendo escenarios que validen tus capacidades de respuesta y notificación de incidentes
- How to manage DORA third-party ICT risk using AI -- Asegúrate de que tus proveedores externos puedan apoyar tus obligaciones de notificación de incidentes con cláusulas de notificación y SLA adecuados
Para la configuración fundamental, consulta How to get started with DORA implementation using AI. Para el marco de gestión de riesgos de las TIC que sustenta la gestión de incidentes, consulta How to build a DORA ICT risk management framework using AI.
Para indicaciones listas para usar, consulta la DORA Compliance Prompt Library. Para una visión general regulatoria completa, consulta la DORA Compliance Guide for Financial Entities.
Obtener ayuda
Para obtener apoyo adicional en la implementación de la notificación de incidentes DORA:
- Pregunta a ISMS Copilot: Utiliza tu espacio de trabajo de DORA para generar orientación de clasificación específica para escenarios y personalizar plantillas de informes para tu tipo de entidad
- Sube procedimientos existentes: Obtén un análisis de brechas específico subiendo tu plan actual de respuesta a incidentes para compararlo con los Artículos 17-23 de DORA
- Simula notificaciones: Utiliza ISMS Copilot para recorrer escenarios de incidentes simulados y practicar la cumplimentación de plantillas de notificación bajo presión de tiempo
- Valida resultados: Revisa todos los criterios de clasificación y plantillas de informes frente al texto regulatorio de DORA y los Estándares Técnicos Regulatorios pertinentes antes de su adopción formal
Construye tu capacidad de notificación de incidentes hoy. Abre tu espacio de trabajo de DORA en chat.ismscopilot.com y comienza con tu matriz de clasificación. Cuando ocurra el próximo incidente relacionado con las TIC, estarás preparado para clasificar, notificar y responder dentro de los plazos estrictos de DORA.