ESAs publish the first report on DORA major ICT-related incidents
The European Supervisory Authorities have released their first annual report on major ICT-related incidents in the EU financial sector, as mandated by the Digital Operational Resilience Act (DORA). This report reveals that ICT risks are increasingly borderless and interconnected across the European Union. Out of 3,383 major incidents reported, approximately one-third had a cross-border impact, highlighting reliance on shared infrastructures. System failures and external events were identified as the primary causes of these incidents. While the direct impact on clients and transactions was generally limited, the findings underscore the need for robust third-party risk management. The report emphasizes the growing systemic nature of ICT risk and the importance of resilience and supervision. Financial entities are urged to strengthen cybersecurity measures, especially given the rise of advanced AI-driven tools. Although only 10% of reported incidents were cybersecurity-related, maintaining high cybersecurity standards is crucial. DORA aims to harmonize incident reporting, enabling faster and more coordinated responses to major ICT-related events. This ultimately contributes to the overall resilience of the European financial system.