ESAs publish first report on DORA major ICT-related incidents

The European Supervisory Authorities released their first annual overview of major ICT-related incidents in the EU financial sector, highlighting increasing interconnectedness and cybersecurity challenges under DORA.

Logo of European Banking Authority
Published on:

The European Supervisory Authorities (EBA, EIOPA, and ESMA) have published their first annual report on major ICT-related incidents in the EU financial sector, based on the reporting mechanism established by the Digital Operational Resilience Act (DORA).

The report shows that ICT risks are increasingly borderless and interconnected. It emphasizes the need for financial entities to strengthen cybersecurity measures, especially with the evolution of AI-driven tools, to maintain resilience.

DORA aims to harmonize and streamline the reporting of major ICT-related incidents by establishing consistent requirements for management, classification, and reporting. Proper notification to all involved Competent Authorities enables faster, coordinated responses, enhancing the resilience of the European financial system.

The report indicates that approximately one-third of the 3,383 major incidents reported involved cross-border impact, underscoring the interconnectedness of shared infrastructures and services. The direct impact on clients and transactions was generally limited. System failures and external events were the main causes, highlighting the importance of third-party risk management and effective oversight of outsourced services.

Only 10% of incidents were related to cybersecurity, but maintaining high cybersecurity standards remains crucial, especially with the potential use of advanced AI tools. These findings reflect the increasing systemic nature of ICT risks and the importance of resilience and supervision in safeguarding the financial sector against future incidents.

Legal basis: Article 22(2) of DORA requires ESAs to report annually on major ICT-related incidents, including their number, nature, impact, remedial actions, and costs.

Definition: An ICT-related incident is an unplanned event or series of events that compromise network security and adversely affect data or services. A major ICT incident significantly impacts critical functions of a financial entity.

Read the Original: European Banking Authority on June 03, 2026
News & Articles