Art. 28 Supports
ICT third-party risk
Manage ICT third-party risk: identify, assess, and monitor risks stemming from ICT service providers, including concentration and critical providers.
Continuous deep and dark web monitoring of named ICT providers — supports the ongoing monitoring component of Art. 28 third-party risk management.
Arts. 10–11 Supports
Detection & response
Detect anomalous activities and respond to ICT-related incidents.
Early external signal when credentials or documents appear underground. Not internal anomaly detection or containment tooling.
Art. 17 Supports
ICT-related incident management
Detect, manage, and notify ICT-related incidents through defined processes.
Alerts and Investigation mode for underground scoping; process ownership stays with the entity.
Art. 19 Supports
Major ICT-related incident reporting
Report major ICT-related incidents to competent authorities within mandated timelines.
Timestamped artefacts for timeline and narrative. Does not file reports.
Arts. 6 & 8 Supports
ICT risk management framework
Maintain an ICT risk management framework covering identification of ICT risks (and related analysis inputs).
Objective exposure evidence for the entity and providers as input to risk analysis — beyond self-attestation.
Art. 13 Supports
Learning & evolving
Learn from ICT-related incidents and cyber threats and improve measures accordingly.
Investigation outputs feed post-incident lessons. Not a full learning-management system.
Art. 45 Supports
Information sharing
Voluntary arrangements to share cyber threat information and intelligence among trusted communities.
Entity-scoped underground intelligence that can feed sharing. Does not operate ISACs or legal sharing vehicles.