When does a cybersecurity incident become inside information?
- Nina Siedler
- 4 days ago
- 1 min read

A custody outage may trigger more than one regulatory process. Under DORA, it may have to be reported to the competent authority. Under MiCA, the same event may also constitute inside information - requiring public disclosure, trading restrictions, enhanced market surveillance or other market-abuse controls.
The analysis becomes particularly complex where roles overlap: Some CASPs also issue their own tokens. Others may only hold price-sensitive information concerning third-party assets traded on their platforms, in which case the Article 88 MIiCAR disclosure obligation rests with such third party while market abuse controls still apply.
In this webinar, we discussed i.a. why MiCAR disclosure compliance is still significantly less developed than DORA incident reporting - and what institutions should build before the first price-relevant security event occurs.
The key requirement is an integrated incident-to-market process that determines:
– whether the information is precise, non-public and price-sensitive
– which asset and legal entity it concerns
– whether must communicate it
– whether trading restrictions and enhanced surveillance are required
– how a complete, timely and verifiable disclosure record is created
Inside information issues may arise unexpectedly from a cybersecurity incident.
The first practical step is therefore a cross-functional trigger-mapping exercise involving security, legal, compliance, market operations and communications - with named decision-makers and tested escalation paths.

👉 MiCAR’s Fine Print: The Cybersecurity Obligations Most Institutions Are Not Ready For - we will add a link to the recording here once it is published.


