ESAs publish the first report on DORA major ICT-related incidents
Tag: S-2026-06-03-esas-dora-incident-report Type: report (press release announcing publication of the ESAs 2025 report) Author(s): European Supervisory Authorities — EBA, EIOPA and ESMA (joint) Date of source: 2026-06-03 (press release / publication date) Date ingested: 2026-06-09 Authority weight: high — joint output of the three EU supervisory authorities, drawing on the mandatory DORA incident-reporting dataset (primary supervisory data). Raw file: S-2026-06-03-esas-dora-incident-report.md. External URLs: https://www.eba.europa.eu/publications-and-media/press-releases/esas-publish-first-report-dora-major-ict-related-incidents (press release); report PDF: https://www.eba.europa.eu/sites/default/files/2026-06/29b60c21-4ff3-4e1e-9308-7c8225d5cc01/ESAs%202025%20report%20on%20major%20ICT-related%20incidents.pdf
What it claims
On 3 June 2026 the three European Supervisory Authorities (EBA, EIOPA and ESMA) published their first annual overview of major ICT-related incidents in the EU financial sector, drawing on the reporting mechanism established by the Digital Operational Resilience Act (DORA). The report’s headline finding is that ICT risks are “increasingly borderless and interconnected.” In the reporting period financial entities reported 3,383 major ICT incidents — equivalent to 0.18 per entity subject to DORA — of which around one third had a cross-border impact, which the ESAs attribute to growing interconnectedness through shared infrastructures and services. The direct impact on clients and transactions was, by contrast, generally limited. System failures and external events were the main drivers of incidents, which the ESAs say underscores the need for robust third-party risk management, effective oversight of outsourced services, and close coordination with service providers during incident response and remediation. Only about 10% of reported incidents were cybersecurity-related, but the authorities stress that firms must uphold the highest cybersecurity standards to keep pace with the potential use of “highly capable AI-driven tools” — a forward-looking warning that AI-enabled threat capability should prompt firms to strengthen cyber resilience. The report is positioned as a supervisory transparency / monitoring product (it satisfies the Article 22(2) DORA mandate to report yearly on major ICT incidents), not as new binding requirements.
Notable quotes
“It shows that ICT risks are increasingly borderless and interconnected. The authorities also note that the recent evolution of highly capable AI-driven tools should encourage financial entities to strengthen cybersecurity measures to maintain their resilience going forward.” — ESAs press release (3 June 2026)
“around one third of the 3,383 major incidents reported by financial entities in the EU (i.e. 0.18 per entity subject to DORA) had a cross-border impact … System failures and external events were the main drivers, highlighting the need for robust third-party risk management, effective oversight of outsourced services and close coordination with service providers.” — ESAs press release (3 June 2026)
“While only 10% of the reported incidents were related to cybersecurity, it is key that financial entities uphold to the highest cybersecurity standards to be able to keep pace with the potential use of highly capable AI-driven tools.” — ESAs press release (3 June 2026)
What’s speculative vs. asserted
- Asserted (from the reported DORA dataset): publication on 3 June 2026; the 3,383 major-incident count and 0.18-per-entity ratio; ~one third cross-border impact; generally limited direct client/transaction impact; system failures and external events as main drivers; ~10% cybersecurity-related; the Article 22(2) DORA legal mandate.
- Forward-looking / interpretive (ESAs’ own framing): that highly capable AI-driven tools “should encourage” firms to strengthen cybersecurity — a recommendation/warning, not a measured finding; the characterisation of ICT risk as having a “growing systemic dimension.”
- Not retrieved this run: the report-body detail (breakdown by incident nature, remedial actions taken, costs incurred, per-sector or per-entity-type splits). Treat any such specifics as unconfirmed pending review of the 847 KB report PDF.
Topics this feeds
Open questions raised
- What the report-body breakdown by incident nature shows (system failure vs. process vs. third-party vs. cyber) and what remedial actions and costs were reported — none retrieved this run.
- Whether the high share of system-failure / external-event drivers (vs. cyber) will shift supervisory emphasis toward availability/continuity controls rather than purely cyber controls.
- How the cross-border-impact finding (one third of incidents) will feed the designation and oversight of Critical ICT Third-Party Providers (CTPPs) under DORA.
- How this EU dataset compares with the UK PS26/2 operational-incident reporting picture once that regime is live (18 March 2027), for cross-border firms.
Ingestion note
Press release fetched directly and in full from eba.europa.eu via WebFetch; all figures above are verbatim from that release. The underlying ESAs 2025 report PDF (847 KB) was linked but not downloaded or parsed this run — report-body specifics are therefore flagged as unconfirmed. This is a joint ESAs product (EBA, EIOPA, ESMA); it is filed against the EBA for entity-linking convenience but is not an EBA-only output, and the EIOPA/ESMA co-authorship is noted to avoid mis-attribution.