38 Cyber Incident Classification in the OSCE Region Ensuring that relevant stakeholders and constituencies not only understand the categories and thresholds of a given classification system, but also report incidents when they are affected is a continuous challenge. Sometimes this may be due to reputational concerns. It may also be because the affected entity does not have an effective risk management model in place and may not have the capacity or resources to carry out proper assessments of the impact of the incident (on the service affected, the number of users affected, the area affected and the impact of the incident on other services or sectors). Finally, the absence of relevant guidance on category definitions, roles and responsibilities or what a response within a given category entails, constitutes a specific challenge to understanding how the system should be used. States are overcoming many of the challenges discussed above through the adoption of targeted regulation (for instance, by requiring critical infrastructure operators and owners to report cyber incidents and ransomware payments),; through the provision of more detailed guidance to stakeholders and constituents, and by regularly testing and reviewing their classification system, including through regular exercises and training. Some States are also introducing regulatory requirements where incident notification and reporting is concerned.

Select target paragraph3