EU’s First DORA Review Finds One-Third of Financial ICT Incidents Spread Across Borders
§ 01 Executive Snapshot
- What: The European Supervisory Authorities published their first annual overview of major ICT-related incidents in the EU financial sector under DORA.
- Who: European Banking Authority, European Insurance and Occupational Pensions Authority, European Securities and Markets Authority.
- Why it matters: The report highlights the increasing cross-border nature of ICT risks in the financial sector, emphasizing the need for improved resilience and coordination among financial entities.
§ 02 Key Developments
- Financial firms in the EU reported 3,383 major ICT-related incidents in the last year.
- Approximately one third of these incidents had cross-border effects, indicating greater interconnectedness in financial systems.
- Cybersecurity-related incidents represented about 10% of the total reported incidents, underscoring the importance of maintaining strong cybersecurity standards.
§ 03 Strategic Context
- The Digital Operational Resilience Act (DORA) aims to standardize how financial entities manage and report ICT-related disruptions, reflecting a shift towards more systemic risk management in the financial sector.
- Shared digital infrastructure and outsourced services have contributed to the operational risk transmission across markets, highlighting vulnerabilities in interconnected financial systems.
§ 04 Strategic Implications
- Immediate implications include the need for financial firms to enhance their third-party risk management and incident response strategies to mitigate cross-border ICT risks.
- Long-term operational implications suggest a shift towards a more resilient framework for managing ICT-related incidents, necessitating stronger supervision and coordination among financial authorities.
§ 05 Risks & Constraints
- Potential risks include regulatory challenges in enforcing compliance with DORA and the complexities of managing outsourced services effectively during incidents.
- Increased reliance on digital infrastructure raises concerns about systemic risks, particularly with the introduction of AI-driven tools that may heighten future cyber risks.
§ 06 Watchlist / Forward Signals
- Future developments will signal the success or failure of this initiative, including the effectiveness of incident response coordination and improvements in cybersecurity standards among financial firms.
- Upcoming revisions or enhancements to DORA may reflect the evolving landscape of ICT risks and the need for stronger resilience measures across the sector.
Frequently Asked Questions
What is the purpose of DORA?
The Digital Operational Resilience Act (DORA) aims to standardize how financial entities manage and report ICT-related disruptions.
How many major ICT-related incidents were reported in the EU financial sector?
Financial firms in the EU reported 3,383 major ICT-related incidents in the last year.
Why is the cross-border nature of ICT risks important?
The report highlights the increasing interconnectedness in financial systems, emphasizing the need for improved resilience and coordination among financial entities.
What percentage of reported incidents were related to cybersecurity?
Cybersecurity-related incidents represented about 10% of the total reported incidents.
Related Articles
Zealand Pharma Announces Financial Results for the First Half of 2026
§ 01 Executive Snapshot What: Zealand Pharma announced its financial results for the first half of 2
Acorns acquires family investment app EarlyBird
§ 01 Executive Snapshot What: Acorns has acquired the family investment app EarlyBird. Who: Acorns a
POET Technologies Reports Second Quarter 2026 Results:
§ 01 Executive Snapshot What: POET Technologies reports strong financial results for Q2 2026, showca
Inside Balyasny’s $300m hiring push: ‘Anyone who says they don’t feel the pressure is lying’
§ 01 Executive Snapshot What: Balyasny Asset Management is initiating a significant hiring campaign