top of page
Search

DORA major ICT incidents 2025

  • Writer: Katarzyna  Celińska
    Katarzyna Celińska
  • Jun 23
  • 2 min read

The European Supervisory Authorities have published the 2025 Report on major ICT-related incidents under Article 22 of DORA.

 

For financial entities in scope of DORA, this is definitely a report worth reading carefully. But it is also important for regulators, because the data can help extrapolate trends for future periods, especially when combined with threat intelligence reports and predictions on how ICT and cyber risks may evolve.



The report covers major ICT-related incidents reported in 2025 across EU financial sectors. In total, 3,383 major incidents were reported, with the majority occurring in the credit and payments sectors. The ESAs are careful to explain that this concentration should not automatically be read as a sign of sector-specific weakness. It may also reflect market structure, previous reporting obligations and the highly digital, customer-facing nature of banking and payment services.

 

One of the key findings is that, despite the volume of incidents, the impact on clients, transactions and financial counterparties was often limited. The report notes that two thirds of major incidents resulted in no or only minor disruption to clients and transactions. This may suggest that timely detection, response and containment measures were effective in limiting operational harm and spillover effects.

 

The report shows the systemic nature of ICT risk. Around one third of major incidents had a cross-border impact, confirming that ICT risk in the financial sector is increasingly borderless. Shared infrastructure, common technology providers, outsourced services and cross-border business models mean that one incident can quickly affect multiple entities, sectors and jurisdictions.

 

System failures were reported for 51% of major incidents, external events for 27%, and payment-related incidents for 18%. Cybersecurity incidents represented 10% of total incidents. For cybersecurity incidents, the most frequent techniques were DDoS attacks and data exfiltration / manipulation, including identity theft.

 

The relatively low share of cybersecurity incidents may indicate effective safeguards, but it may also reflect classification, reporting maturity or the fact that many operational incidents are not “cyber” in the narrow sense, while still creating resilience risk.

 

Almost one third of major incidents originated from failures attributable to third parties, including ICT third party providers, other financial entities and infrastructure providers. This clearly confirms why DORA puts so much emphasis on ICT third-party risk management, contractual arrangements, oversight, exit planning and coordination during incidents.



 
 
 

Comments


Stay in touch

ITGRC ADVISORY LTD. 

590 Kingston Road, London, 

United Kingdom, SW20 8DN

​company  number: 12435469

Privacy policy

  • Facebook
  • Twitter
  • LinkedIn
  • Instagram
bottom of page