Law / Malta

Measures for a High Common Level of Cybersecurity across the European Union (Malta) Order, Significant-Incident Reporting to the National CSIRT

S.L. 460.41, art. 20, Measures for a High Common Level of Cybersecurity across the European Union (Malta) Order

In force since .

A vulnerability and incident reporting rule binding public and private bodies.

Obligation class
Reporting, Security

As of .

What it requires

  • This binds an essential or important entity under articles 3 and 4 of the Order, reached as on this jurisdiction's companion risk-management row: an entity of a type listed in the First or Second Schedule that is at least medium-sized, or that the Order names regardless of size, and that falls under Malta's jurisdiction under article 23, including a social networking services platform, online marketplace or online search engine provider.
  • Notify the national CSIRT, which article 8(1) establishes within the Malta Information Technology Agency, immediately of any incident that has a significant impact on the provision of your services; treat an incident as significant where it has caused or is capable of causing severe operational disruption of the service or financial loss for you, or considerable material or non-material damage to another person.
  • Submit an early warning to the national CSIRT, without undue delay and in any event within 24 hours of becoming aware of the significant incident, stating where applicable whether it is suspected of being caused by unlawful or malicious acts or could have a cross-border impact.
  • Follow with an incident notification within 72 hours of becoming aware of the incident, updating the early warning and giving an initial assessment of the incident's severity and impact and, where available, the indicators of compromise.
  • Submit an intermediate report on relevant status updates if the national CSIRT asks for one, and a final report not later than one month after the incident notification, covering a detailed description of the incident, its likely root cause, the mitigation applied and any cross-border impact; if the incident is still ongoing then, send a progress report at that point and a final report within one month of handling it.
  • Where appropriate, notify the recipients of your services without undue delay of a significant incident likely to adversely affect those services, and tell recipients potentially affected by a significant cyber threat any measures or remedies they can take in response.
  • If you are a trust service provider, notify a significant incident that affects your trust services within 24 hours of becoming aware of it, without the 72-hour stage that applies to other entities.

If you get it wrong

Criminal exposureNo

Private right of actionNo

Criminal exposure note

The Order's penalty regime for an infringement of articles 19 or 20 is administrative: fines imposed by the Enforcement Committee under articles 32 and 33, appealed to the Administrative Review Tribunal under article 41. No provision of the Order makes the infringement a criminal offence, although article 31(10)(b) lets the CIP Department ask the competent bodies to prohibit temporarily a chief executive or legal representative of an essential entity from exercising managerial functions until the entity complies.

Penalty structure

Article 32(3) sets the maximum administrative penalty for an essential entity that infringes article 19 or 20 at EUR 10,000,000 or 2 percent of the total worldwide annual turnover of the preceding financial year of the undertaking the entity belongs to, whichever is higher. Article 32(4) sets the important-entity tier at EUR 7,000,000 or 1.4 percent of that turnover, whichever is higher. Article 38 lets the Enforcement Committee, on the request of the CIP Department or the designated competent authority, impose a daily penalty payment of EUR 100 for each breach the entity repeatedly fails to cease or rectify, and the payment may be backdated to the date the breach was committed. A decision of the Committee can be appealed to the Administrative Review Tribunal within 20 days under article 41.

Rule
Higher of
As of
Currency
EUR
Fixed cap
10,000,000
Turnover percentage cap
2

Who enforces it

Enforcement body

The Critical Infrastructure Protection Department (CIP Department), the national supervisory authority under article 7 of the Order; the Malta Communications Authority is the competent authority the Schedules name for digital infrastructure, digital providers and postal services, and the Enforcement Committee imposes the administrative fines on the report of the CIP Department or the designated competent authority under article 33.

Settledness

As of
Open questions
Does regulation 56 of the Electronic Communications Networks and Services (General) Regulations (S.L. 399.28), which requires an undertaking providing a public network or service to notify the Malta Communications Authority of a breach of security with a significant impact, still apply beside article 20 of the Order to an electronic communications provider?

What this law does

Drafted with AI

Drafted with AI from the cited sources under the direction of UnGovr staff. UnGovr holds editorial responsibility for this page. How this site is made

Research summary

Legal information, not legal advice. This is LexLint's own research summary of a public legal source, and it creates no attorney-client relationship. For decisions that matter, consult qualified counsel in the relevant jurisdiction. About LexLint

Article 20 requires an essential entity or important entity to notify the national CSIRT immediately of any incident that has a significant impact on the provision of its services. A significant incident is one that has caused or is capable of causing severe operational disruption of the service or financial loss for the entity, or that has affected or is capable of affecting other natural or juridical persons by causing considerable material or non-material damage.

The entity must submit an early warning within 24 hours of becoming aware of the incident, an incident notification within 72 hours with an initial assessment of its severity and impact, an intermediate report if the national CSIRT asks for one, and a final report not later than one month after the 72-hour notification. A trust service provider notifies within 24 hours of becoming aware of a significant incident that affects its trust services.

Where appropriate the entity must also notify the recipients of its services, without undue delay, of significant incidents likely to adversely affect the provision of those services. Notifying does not itself subject the entity to increased liability. The national CSIRT is the team established within the Malta Information Technology Agency by article 8(1).

When LexLint raises it

When your app profile says your app handles health records, runs an essential service, operates a social platform, provides financial services or provides telecom services.

Back to the example  ·  Lint your app