ESAs publish the first report on DORA major ICT-related incidents
Executive Summary
The ESAs (EBA, EIOPA and ESMA) have published their first annual report under Article 22(2) DORA, aggregating 3,383 **major ICT‑related incidents** reported by EU financial entities and highlighting that roughly one third had a cross‑border impact. This is an early supervisory “heat map” of DORA incident reporting and sends a clear signal that competent authorities will focus on cross‑border ICT risk, third‑party/outsourcing failures and the adequacy of firms’ incident classification and reporting frameworks.
What Changed
- - The ESAs have operationalised Article 22(2) DORA by issuing the first annual overview of major ICT‑related incidents, confirming that yearly ESA‑level aggregation and analysis of incident data is now part of the standard supervisory cycle.
- Incident reporting under DORA is now demonstrably harmonised and centralised, with major ICT‑related incidents being notified to all competent authorities involved and then aggregated by the ESAs for EU‑wide analysis.
- The report confirms that cross‑border incidents are prevalent (around one third of major incidents), reinforcing that the “borderless and interconnected” nature of ICT risk is a key supervisory concern, especially where shared infrastructures and ser
- System failures and external events, rather than pure cyber‑attacks, are identified as the main drivers of major incidents, placing regulatory emphasis on ICT change management, resilience of core infrastructure, and non‑cyber operational risk.
- The ESAs highlight third‑party and outsourcing risk as a core theme, stressing the need for robust oversight of ICT service providers and close coordination with them during incident response and remediation.
- The report notes that only about 10% of major incidents are cybersecurity‑related, but calls out the need to maintain “highest cybersecurity standards” in light of highly capable AI‑driven tools, signalling heightened expectations on AI‑related cyber
Suggested Considerations
- Review and, where necessary, recalibrate internal incident classification criteria against the DORA definition of “ICT‑related incident” and “major ICT‑related incident”, ensuring consistency with applicable RTS on classification and materiality thresholds.
- Validate that your firm’s incident management and escalation processes can identify, assess and classify incidents “without undue delay” and trigger major‑incident reporting within the prescribed timelines (initial, intermediate and final reports).
- Conduct a gap analysis of cross‑border incident handling, ensuring that governance, communication and coordination arrangements adequately address incidents affecting multiple Member States or shared cross‑border infrastructures.
- Strengthen third‑party and outsourcing risk management by mapping critical and important functions to their supporting ICT service providers, and ensuring contracts, SLAs and incident‑response clauses support DORA reporting and cooperation obligations.
- Test and, if needed, enhance incident response runbooks to ensure close coordination with ICT service providers during incident containment, remediation and recovery, including clear roles for data provision required for regulatory reporting.
- Implement or refine metrics and logging to capture the data points highlighted by the ESAs (e.g. number of incidents, cross‑border impact, client and transaction impact, remedial actions, and costs), so you can evidence accurate and complete reporting and answer supervisory follow‑up questions.
Key Dates
Compliance Impact
Non‑compliance with DORA incident management and reporting obligations can lead to supervisory findings, administrative sanctions, and heightened intrusive supervision, especially where cross‑border incidents or third‑party failures are not properly reported or managed. Given the ESAs are now publicly benchmarking the sector, firms whose reporting patterns appear inconsistent with peers face incre
Who is Affected
References
AI-generated analysis. May contain errors or omissions — verify with the original ESMA source before acting. Full disclaimer.
Summary
ESAs publish the first report on DORA major ICT-related incidents 03 June 2026 Digital Finance and Innovation Joint Committee The European Supervisory Authorities (EBA, EIOPA and ESMA) today published their first annual overview of major ICT-related incidents in the EU financial sector based on a reporting mechanism established by the Digital Operational Resilience Act (DORA). It shows that ICT risks are increasingly borderless and interconnected. The authorities also note that the recent evo...