FRANCE Law and Practice Contributed by: Jérôme Philippe, Laéna Bouafy, Thomas Retière and Annabelle Hamelin, Freshfields
Indirect Provisions Affecting International Data Transfers Supervisory expectations for cloud and ICT provider oversight The ACPR and AMF expect French financial institu - tions to demonstrate robust due diligence when rely - ing on non-EU cloud and ICT providers: • if a cloud provider in a third country cannot con - tractually guarantee full compliance with DORA’s audit and access requirements, the French supervi - sors expect the financial entity to either renegotiate the terms or implement an exit strategy; and • DORA’s extraterritorial oversight framework means that non-EU CTPPs are indirectly incentivised to align their global operations with EU standards to avoid compliance issues. Supply chain due diligence and data flow vetting Financial entities remain fully accountable for risks introduced by their supply chain: • regulators expect firms to perform thorough due diligence on third-country providers, assessing their legal environment and potential obstacles to data access or contract enforcement; and • contracts must explicitly detail the jurisdictions in which data will be stored and processed, and the financial entity must approve any changes to these locations. Incident reporting Under DORA, when reporting a major ICT incident, a financial entity must specify whether the incident origi - nated with or impacted a third-party provider locat - ed outside the EU. This gives French and European supervisors critical insights into the risks posed by third-country dependencies, enabling them to identify concentration risks or jurisdiction-specific threats. 3.6 Threat-Led Penetration Testing Mandatory TLPT for the financial sector is governed by DORA, which is based on the national TIBER-FR initiative and is aligned with the TIBER-EU framework. The French regulators, the ACPR and AMF, conduct oversight.
TLPT Scope TLPT is an advanced, intelligence-led testing regime designed to rigorously assess the resilience of signifi - cant financial entities against sophisticated, real-world cyber-attacks. Entities in scope The obligation applies to financial entities identified as “significant” by the ACPR and AMF based on their size, business profile and systemic importance. This includes major banks, certain insurance undertakings, and key financial market infrastructures. Systems in scope The tests must cover the “live critical production sys - tems” that underpin an entity’s critical or important functions. ICT third-party providers Although the obligation lies with the financial entity, critical ICT providers (such as major cloud service pro - viders) are inherently part of the scope. DORA allows for “pooled tests”, whereby multiple financial entities can collectively test a shared provider, co-ordinated by the provider itself. Eligible financial entities must conduct a full TLPT at least every three years. The frequency may be adjust - ed by national authorities based on the entity’s risk profile or new threats emerging. Scenario selection and threat intelligence The entire test must be driven by specific, tailored threat intelligence. Scenarios must realistically mim - ic the tactics, techniques and procedures (TTPs) of advanced threat actors who are deemed to pose a genuine threat to the entity. In France, threat intelli - gence may be sourced from internal teams, specialist external providers, and national authorities such as ANSSI. Red team qualifications The testers (the “red team”) must have a high level of expertise and be functionally independent from the defence and response teams (the “blue team”). DORA mandates that testers hold relevant certifications and Key TLPT obligations Under DORA Frequency and risk-based approach
133 CHAMBERS.COM
Powered by FlippingBook