For the first time, the European Supervisory Authorities (EBA, EIOPA and ESMA) have published an annual overview of major ICT-related incidents in the EU financial sector. The report is more than a collection of statistics: it demonstrates which types of reportable ICT-related incidents are becoming particularly relevant under DORA, where the greatest operational dependencies exist, and what ICT risks can be derived from these findings for the financial sector.
Table of Contents
On 3 June 2026, the European Supervisory Authorities EBA, EIOPA and ESMA (together, the ESAs) published their first report on major ICT-related incidents in the EU financial sector. The report is based on the classification and reporting mechanism for major ICT-related incidents introduced by the Digital Operational Resilience Act (DORA). It provides the first Union-wide, cross-sector overview of reportable ICT-related incidents since DORA became applicable.
The report is based on Article 22(2) DORA. Under this provision, the ESAs are required to publish an annual report on major ICT-related incidents on an anonymised and aggregated basis. The report must include, at a minimum, information on the number and nature of incidents, their impact on financial entities or customers, the remedial actions taken and the costs incurred. The ESAs have now fulfilled this obligation for the first time with respect to the 2025 reporting year.
3,383 major ICT-related incidents in 2025
A total of 3,383 major ICT-related incidents were reported in the EU financial sector during 2025. According to the ESAs, this corresponds to an average of 0.18 major ICT-related incidents per financial entity subject to DORA, or approximately 282 incidents per month.
At first glance, this figure appears high. However, the ESAs expressly warn against interpreting the number of incidents alone as evidence of structural weaknesses within individual sectors. The financial sector is highly digitalised, technically complex and closely interconnected. Operational disruptions cannot be entirely avoided in such an environment. The decisive factor is therefore not whether incidents occur, but whether financial entities identify them at an early stage, contain them effectively, report them in an orderly manner and resolve them sustainably.
The largest number of incidents occurred in the banking sector and among payment institutions. More than 60% of all reported incidents concerned credit institutions, while a further 16% related to payment institutions, electronic money institutions and account information service providers. According to the ESAs, this concentration does not necessarily indicate sector-specific weaknesses but is primarily attributable to three factors:
- Comparable reporting obligations already existed in these sectors before DORA, particularly under PSD2. The relevant institutions therefore have greater experience in handling incidents and regulatory reporting requirements.
- Many institutions rely on the same ICT infrastructures or central ICT service providers, meaning that a single event may trigger multiple reports.
- Credit and payment services are typically highly digitalised, high-volume and customer-facing, making it more likely that the DORA classification criteria for major ICT-related incidents will be met.
DORA demonstrates that ICT risks are cross-border
One of the report’s key findings is the increasingly cross-border nature of ICT risks. Approximately one third of all reported major ICT-related incidents had cross-border effects. Around 8% of all incidents affected more than ten Member States.
This is of considerable regulatory significance. DORA is not merely a regulatory framework for individual institutions but is also intended to strengthen the systemic digital resilience of the European financial sector. The report demonstrates that financial entities increasingly rely on shared technical infrastructures, common ICT third-party service providers, cross-border platforms and group-wide operating models. As a result, a technical issue affecting an ICT service provider, a central infrastructure or a shared application can rapidly impact multiple institutions, sectors and Member States.
This finding is particularly relevant for payment service providers, electronic money institutions, crypto-asset service providers and banks. Institutions that assess ICT risk solely from their own organisational perspective no longer capture their actual risk profile. Under DORA, dependencies on third parties, concentration risks, substitution options and communication chains must all be systematically taken into account.
System outages and external events dominate – not cyberattacks
Particularly noteworthy is the breakdown of incidents by category. According to the ESA report, system outages accounted for 51% of all major ICT-related incidents. External events followed at 27%, while payment-related incidents represented 18%. By contrast, cybersecurity-related incidents accounted for only around 10% of all reported major ICT-related incidents.

This does not mean that cyber risks are becoming less significant. On the contrary, the ESAs continue to emphasise that financial entities must further strengthen their security measures in light of increasingly sophisticated AI-enabled attack tools.
At the same time, the report demonstrates that digital operational resilience under DORA is considerably broader than traditional IT security. DORA does not only address cyberattacks but all ICT-related events capable of impairing the availability, authenticity, integrity or confidentiality of data or the provision of services. These include, in particular, system failures, misconfigurations, process failures, service provider outages, power or telecommunications disruptions and other external events.
From a practical perspective, this represents an important clarification. DORA-compliant ICT risk management must not be limited to cybersecurity, penetration testing and security monitoring. Equally important are robust IT governance, change management, architecture management, capacity planning, business continuity arrangements, service provider management and regularly tested recovery procedures.
Third-party dependencies remain a key supervisory focus
According to the ESA report, almost one third of all major ICT-related incidents reported in 2025 were attributable to failures involving third parties. In this context, the ESAs refer to dependencies on third-party providers, including internal ICT third-party providers, other financial entities and infrastructure providers.
This is one of the report’s most significant findings. DORA already provides a highly sophisticated regulatory framework through its requirements on ICT third-party risk management, the Register of Information, mandatory contractual provisions and the Oversight Framework for Critical ICT Third-Party Providers (CTPPs). The report now provides empirical confirmation of why this topic has been given such regulatory importance.
For financial entities, this means that DORA implementation is not complete merely because contracts have been formally updated and service providers have been recorded in the Register of Information. What matters is whether an institution genuinely understands its operational dependencies and manages them on an ongoing basis. In particular, for cloud services, payment processors, core banking systems, card processors, KYC/AML service providers, communications providers and specialised FinTech infrastructures, the quality of ICT third-party risk management is increasingly becoming a key resilience factor.
Customer and transaction impacts were often limited
Despite the high number of reported incidents, the ESAs reach a differentiated conclusion: in many cases, the impact on customers, transactions and financial counterparties was limited. Almost 60% of all major ICT-related incidents had either no customer impact or only a limited impact, affecting fewer than 1,000 customers (or less than 10% of the total customer base). Two thirds of all ICT-related incidents affected either no transactions or fewer than 1,000 transactions. Only around 1% of incidents affected more than one million transactions.
This is also significant for the assessment of DORA. An incident may be reportable and relevant from a supervisory perspective without necessarily resulting in widespread customer harm. The ESAs interpret the limited impact of many major ICT-related incidents as an indication that timely detection, incident response and containment measures were often effective.
For financial institutions, this provides a strong argument for continuing to regard incident management as more than a purely formal reporting process. Effective incident management requires close coordination between detection, escalation, technical and business assessment, communication, stabilisation, recovery, root cause analysis and sustainable remediation. DORA does not merely require incidents to be reported. It requires institutions to learn from incidents and to continuously improve their digital operational resilience.
The two most significant events: TARGET2 and the Iberian Peninsula blackout
The report also provides an in-depth analysis of selected incidents with wide-ranging effects.
TARGET2 incident in February 2025
On 27 February 2025, a major ICT-related incident occurred within TARGET Services. T2 and T2S were unavailable for approximately ten and eight hours respectively, while TARGET Instant Payment Settlement (TIPS) experienced disruption for approximately one hour as a consequence of the T2 outage. This resulted in interruptions to securities settlement, payments, ancillary system processing and liquidity transfers. The underlying cause appears to have been an exceptional malfunction of a core storage system component. Recovery was achieved by means of a failover to the secondary site, followed by integrity checks.
The incident demonstrates that even highly professional central financial market infrastructures are not completely immune to technical failures. For connected institutions, it is therefore essential to reflect dependencies on central market infrastructures realistically within their business continuity and communication processes.
Blackout on the Iberian Peninsula in April 2025
Another example is the power outage affecting the Iberian Peninsula on 28 April 2025. The outage in Spain also affected Portugal and lasted for approximately ten hours. Although the data centres of larger banks and insurance undertakings remained operational thanks to emergency power supplies, significant disruption nevertheless occurred, particularly due to failures affecting branches, telecommunications providers, internet connectivity and point-of-sale terminals.
This example is particularly instructive because it demonstrates that resilience does not depend solely on an institution’s own data centre. An institution may remain technically operational while nevertheless being unable, or only partially able, to provide its services if electricity supply, telecommunications, customer access channels or physical infrastructure are disrupted.
Data quality remains a challenge
The report also notes that information relating to costs and financial recoveries remains subject to significant data quality limitations. According to the available information, around 40% of ICT-related incidents resulted in no reported direct or indirect costs, while a further 10% generated costs of less than EUR 1,000. In approximately 15% of cases, the relevant reporting field was left blank. The ESAs also point out that this may indicate deficiencies in reporting practices, particularly where staff costs associated with handling an incident have not been taken into account.
For financial entities, this provides an important practical lesson: the process of determining incident-related costs should not begin only when preparing the Final Report. Institutions should establish at an early stage how cost categories will be captured, who will provide the relevant input and how both direct and indirect costs will be documented. These may include internal staff costs, external consultancy and forensic expenses, technical recovery costs, compensation payments, SLA-related claims, contractual penalties, lost revenue and other consequential losses.
What does the report mean for DORA in practice?
The report provides important interpretative guidance and indicates supervisory expectations for future practice. Several practical conclusions can be drawn from its findings:
- Financial entities should carefully review their ICT incident classification processes. DORA requires incidents to be assessed against harmonised criteria and thresholds. At the same time, the ESAs point out that, during the first year of application, reporting practices still varied across sectors and jurisdictions. Institutions that classify incidents consistently, transparently and in a well-documented manner can significantly reduce supervisory risks.
- Third-party dependencies remain a key area of focus. The finding that almost one third of all major incidents were attributable to ICT third-party service providers demonstrates that continuous monitoring of ICT service providers is a central element of DORA compliance.
- Institutions should not treat incident response as an isolated IT function. Major ICT-related incidents frequently affect customer communications, regulatory reporting, data protection, outsourcing management, payment services, fraud prevention, legal, compliance, risk management and senior management.
- Business continuity and disaster recovery arrangements must realistically reflect external infrastructure events. The blackout on the Iberian Peninsula demonstrates that a fully operational data centre alone is insufficient if customer access channels, communications or payment acceptance infrastructures are disrupted.
- Institutions must improve the quality of their incident documentation. This includes not only timestamps and technical descriptions, but also the rationale for incident classification, the critical or important functions affected, impacts on customers and transactions, involvement of service providers, root cause analysis, remedial measures and a clear understanding of the costs associated with the incident.
Conclusion: DORA provides the first European overview of ICT-related incidents
The ESAs’ first report on major ICT-related incidents demonstrates that DORA is far more than a compliance exercise. Through its harmonised reporting framework, DORA provides, for the first time, a robust European overview of the ICT disruptions that actually affect the financial sector.
The key findings are clear: ICT risks are cross-border, highly interconnected and frequently linked to third-party dependencies. System outages and external events are at least as significant as traditional cyberattacks. At the same time, the limited impact of many ICT-related incidents demonstrates that effective detection, response and containment measures can make a substantial difference.
The report also illustrates that supervisory attention is increasingly shifting from purely formal compliance towards the actual resilience of financial entities. Robust governance structures, effective ICT third-party risk management, mature incident response capabilities and realistic business continuity planning are becoming decisive factors in assessing whether institutions are genuinely prepared for operational disruptions.
For financial entities, the report therefore offers much more than a statistical overview. It provides valuable guidance on how the ESAs interpret DORA in practice and where supervisory priorities are likely to lie in the years ahead. Institutions should use these findings to review and further develop their own ICT risk management and operational resilience frameworks.
