First DORA Incident Report Highlights Growing ICT Resilience Risks


Date: 12 June 2026

Featured Image

The European Supervisory Authorities (EBA, EIOPA and ESMA) have released the first annual report on major ICT-related incidents under the Digital Operational Resilience Act (DORA). While many organisations viewed DORA as another regulatory hurdle, the findings suggest something much bigger.

The report paints a picture of a financial sector operating in an environment where ICT disruptions are increasingly interconnected and cross-border. This shows that any disruption is capable of creating systemic consequences. For financial institutions, the takeaway is simple: resilience can no longer exist only on paper. It must be demonstrated in practice.

What Did the Report Reveal?

The report analysed 3,383 major ICT-related incidents reported across the EU financial sector during 2025. That averages approximately 282 major incidents every month. Credit institutions and payment providers accounted for the largest share of reported incidents.

Perhaps more importantly, around one-third of all major incidents had cross-border impacts. This highlights how interconnected financial services have become and how a disruption in one location can quickly affect customers, partners, and operations across multiple countries.

The report also found that major incidents were not driven exclusively by cyber attacks. System failures, technology outages, and third-party dependencies featured prominently. In other words, operational resilience is no longer just a cybersecurity challenge. It is a business resilience challenge.

This distinction matters because many organisations still focus most of their preparedness efforts on preventing cyber attacks. DORA’s first year of reporting demonstrates that resilience requires organisations to prepare for technology failures, supplier disruptions, cloud outages and other similar complex cascading events.

The Growing Systemic Nature of ICT Risk

One of the strongest messages from the report is that ICT risk is becoming increasingly systemic. Financial institutions rely on shared cloud platforms, outsourced service providers, software vendors, payment networks, and interconnected digital ecosystems. A failure affecting one critical provider can have consequences across multiple organisations and jurisdictions.

This is exactly why DORA places such a strong emphasis on ICT third-party risk management. Organisations are expected not only to understand their own systems but also their dependencies on external providers and the concentration risks those dependencies create.

The findings reinforce a reality that cybersecurity professionals have been discussing for years: organisations do not operate in isolation. Their resilience is increasingly tied to the resilience of their suppliers, technology partners, and service providers.

Why Incident Reporting Is Only the Beginning

Many organisations initially associated DORA with incident reporting requirements. While reporting remains important, the regulation is ultimately focused on something much broader.

DORA requires financial entities to identify, classify, escalate, manage, recover from, and learn from ICT-related incidents. Reporting is simply the visible outcome of those activities. The challenge is that organisations cannot meet reporting obligations if they struggle with internal decision-making during a crisis.

Questions such as:

  • Who declares a major incident?
  • Who owns regulatory communications?
  • Who approves customer notifications?
  • When should senior management be involved?
  • When does an operational issue become a regulatory event?

These decisions must be made quickly and consistently under pressure.

Without clearly defined processes and tested response procedures, reporting deadlines become difficult to achieve. DORA’s reporting framework is designed to encourage organisations to build operational maturity long before a major incident occurs.

DORA Is Shifting the Conversation from Prevention to Resilience

One of the most interesting findings in the ESAs’ first DORA incident report is the recognition that operational disruptions are no longer viewed as exceptional events that can always be prevented. The report explicitly acknowledges that the increasing digitalisation and interconnectedness of the financial sector make operational incidents “to some extent unavoidable.”

Rather than focusing solely on the number of incidents reported, the ESAs argue that resilience should be measured by how effectively organisations manage and contain those incidents once they occur.

This is a message that will be familiar to anyone who has attended CM-Alliance’s NCSC Assured Cyber Incident Planning and Response training. Since 2020, we have consistently emphasised that while prevention remains important, organisations must accept that not every incident can be stopped. The real measure of maturity is not whether an organisation experiences an incident, but how effectively it prepares for responding to and recovering from one.

In many ways, DORA is now formalising at a regulatory level what resilience practitioners have been advocating for years: resilience matters more than the unrealistic pursuit of complete prevention.

The data strongly supports this view. Despite 3,383 major ICT-related incidents being reported across the EU financial sector in 2025, the report found that two-thirds resulted in no or only minor disruption to clients and transactions.

According to the ESAs, this suggests that timely detection, effective incident response, and rapid containment measures were successful in limiting operational harm and preventing wider spillover effects.

The same conclusion is reinforced later in the report, which notes that the direct impact on clients and transactions was limited in most cases, likely because organisations were able to detect incidents quickly and implement remedial actions before they escalated into broader disruptions.

Why Playbooks Are Becoming Essential for DORA Compliance

This is where many financial institutions still have work to do. An operational resilience policy may explain what should happen during an incident. But a playbook explains exactly how it happens.

Well-designed incident response playbooks provide clear escalation paths and response actions tailored to specific scenarios. For example, the response to a ransomware attack differs significantly from the response to a cloud service outage or a major technology malfunction.

Yet many organisations still rely on generic incident response plans that provide limited operational guidance when a real crisis unfolds.

Under DORA, organisations are expected to demonstrate repeatable and effective response capabilities. Playbooks help transform high-level requirements into practical actions that teams can execute under pressure.

This is one reason why many financial institutions are now reviewing and modernising their incident response documentation to align with DORA expectations.

The Real Test: Can Your Teams Execute?

Having a playbook is important. Knowing whether it works is even more important. DORA places significant emphasis on digital operational resilience testing. Regulators want organisations to demonstrate that their plans, controls, processes, and teams can perform effectively during realistic disruption scenarios.

This is where tabletop exercises and cyber resilience testing become critical. A well-designed exercise can reveal:

  • Unclear ownership and accountability
  • Escalation bottlenecks
  • Communication breakdowns
  • Regulatory reporting gaps
  • Weaknesses in third-party coordination
  • Executive decision-making challenges

These are precisely the types of issues that often emerge during real incidents. The organisations that perform best during crises are rarely the ones with the thickest policies. They are the ones that have practised their response, challenged assumptions and refined their processes before an incident occurs.

What Financial Institutions Should Do Next

The first DORA incident report should serve as a wake-up call for organisations that still view resilience as a compliance exercise.The report confirms that major ICT incidents are frequent, interconnected, and increasingly capable of creating cross-border disruption. It also highlights that resilience requires much more than technical controls. Decision-making, communication and third-party risk management all play a crucial role.

Financial institutions should use these findings as an opportunity to assess whether they can confidently answer the following questions:

  • Are our incident response playbooks fit for modern threats?
  • Have we tested them recently?
  • Can executives make critical decisions under pressure?
  • Are regulatory reporting responsibilities clearly understood?
  • Can we effectively coordinate with key suppliers during a major disruption?
  • Have we validated our response capabilities through realistic exercises?

If the answer to any of these questions is uncertain, there is work to do.

How Cyber Management Alliance Helps Organisations Become DORA Compliant

Cyber Management Alliance helps financial institutions move beyond compliance and build genuine operational resilience. Our specialists work with organisations across the financial sector to develop and review incident response plans.

We also help you create scenario-specific cyber incident playbooks and conduct realistic cyber tabletop exercises that align with DORA requirements. Our NCSC-Assured training programmes, executive cyber crisis workshops, ransomware simulations, operational exercises, and technical cyber drills help organisations validate their readiness before regulators, customers, and stakeholders put it to the test.

The first DORA incident report confirms what many security leaders already suspected. Resilience is no longer measured by the controls you implement. It is measured by how effectively your organisation responds when those controls fail. The institutions that invest in preparation today will be the ones best positioned to withstand tomorrow’s disruptions.

If you’re still looking for a partner who can help you achieve DORA compliance and elevate your organisational operational resilience, reach out to us today. Our bespoke solutions are curated to address the exact needs of your business, its scale, size and sector. We help you achieve compliance and go beyond it so that you feel assured in the operational resilience capabilities of your business.  





Source link

Leave a Reply

Subscribe to Our Newsletter

Get our latest articles delivered straight to your inbox. No spam, we promise.

Recent Reviews


You’ve built your small business from the ground up. It’s your pride and joy, your financial security, and a potential legacy for your family. But what happens to your business interests after you’re gone? Without proper estate planning, your small business could face a chaotic future, disrupting operations, hurting employees, and jeopardizing your loved ones’ inheritance.

Business estate planning is your secret weapon. It’s not just for the ultra-wealthy with complex trusts and wills. For small business owners, it’s a crucial tool to ensure business continuity and protect your business value. Here’s how you can craft a comprehensive estate plan:

Know Your Business Inside and Out

The first step in your estate planning process is taking a deep dive into your business affairs. Make a list of all your business assets: equipment, inventory, intellectual property, and real estate.

Furthermore, don’t forget your business debts like loans and outstanding payments. This comprehensive list helps you understand what needs protecting and planning for in your estate planning documents.

Chart Your Business’s Future Course

What do you envision for your business after you’re gone? Should it stay in the family? Be sold to a trusted partner? Wind down entirely? This is where business succession planning comes in. It’s about deciding the future of your business in a way that honors your legacy and sets your team up for success.

Here are some questions to consider:

  • Family Business? Do you have a family member who shares your passion and has the skills to lead?
  • Trusted Partner? Is there a key employee you see as the ideal successor?
  • Time for a Change? Are you open to selling the business to ensure a smooth transition?

There’s no right or wrong answer. The key is to have open conversations with your loved ones and key employees to understand their goals and aspirations. This will guide you in crafting a business succession plan that feels right for everyone involved.

Develop a Rock-Solid Business Succession Plan

This plan outlines who will take over your business and how. You might identify a family member, a key employee, or even an outside buyer. The business succession plan should detail the transfer process, including training and timeline.

Here’s how to craft a plan as strong as your business itself:

  • Identify Your Successor: It could be a family member you’ve been mentoring, a trusted key employee, or even an outside buyer.
  • Groom Your Successor: Start by involving them in key decisions to give them opportunities to learn the ropes.
  • Plan for the Unexpected: Have a backup plan in place. Identifying another potential leader or outline a buy-out option for remaining partners.

An experienced estate planning attorney like Keele & Parke can help you draft a legally sound plan that considers state law and tax implications.

Avoid Conflict with Ironclad Sell Agreements

If you have co-owners, a sell agreement is vital. This agreement dictates what happens to a deceased or incapacitated owner’s share of the business. It prevents conflict among remaining partners and ensures a smooth ownership transition in your overall estate plan.

Wills vs. Trusts: Choosing the Right Tool

A will can designate who inherits your business assets. But the problem is it can be a slow and public process through probate court.

Here’s where a revocable living trust comes in. Think of it as a private vault that holds your business assets during your lifetime. You can name yourself as trustee, so you’re still in control.

Another thing, you can designate a successor trustee to seamlessly take over managing the business if you become disabled or pass away. This avoids probate and keeps things running smoothly for your loved ones and your employees.

Wills are still important for your overall estate plan, especially for personal assets outside the trust. But for your business, a revocable living trust offers flexibility, privacy, and peace of mind.

Minimize Estate Taxes Through Strategic Planning

Nobody wants a big chunk of their hard-earned business value going to the government after they’re gone. That’s where estate taxes come in, and they can be a real burden for your family. But don’t worry, there are smart estate planning strategies you can use to minimize the impact of these taxes.

  • Smart Business Structure: The legal entity you choose for your business can impact your estate taxes. Talk to your estate planning attorney about structuring your business as a limited liability company (LLC) or another entity that might offer tax advantages.
  • Explore Powerful Trusts: There are special types of trusts, like grantor retained annuity trusts (GRATs), that can be used to transfer ownership of your business interests to your heirs while minimizing the taxable value of those assets.

The right strategy for you will depend on your specific situation and goals. That’s why it’s crucial to work with an experienced estate planning attorney and financial advisor. They can help you create a personalized plan that minimizes your estate taxes and protects your legacy.

Don’t Neglect Your Personal Estate Plan

Your business is just one piece of the puzzle. You also need a personal estate plan that includes a will, power of attorney, and healthcare directives. Without it, your loved ones could face a legal mess during tough times. Bills might go unpaid, important decisions could be delayed, and family heirlooms could end up in the wrong hands.

An estate plan ensures your wishes are followed. It names guardians for your minor children, designates beneficiaries for your personal assets (like your home and savings), and appoints someone you trust to make healthcare decisions if you’re unable to. This gives your family peace of mind knowing they’re taken care of, even in your absence.

Life Insurance: A Lifeline for Your Loved Ones

A life insurance policy provides your beneficiaries with a lump sum of cash upon your death. This can be crucial for surviving family members or business partners, especially if they need to buy out another owner’s share through a sell agreement or pay estate taxes.

Regularly Review and Update Your Plan

Life circumstances change, and so should your estate plan. Regularly review your plan, especially after major life events like marriage, children, or changes in your business structure.

Seek Professional Guidance for a Comprehensive Plan

Business estate planning involves complex legal and financial considerations. Don’t try to go it alone. Consult with an experienced estate planning attorney specializing in business succession planning and a financial advisor with experience in small business matters. Their expertise can ensure your estate plan is comprehensive, legally sound, and achieves your goals for business continuity and protecting your loved ones.

Final Thoughts

Safeguarding your business is like protecting your family’s future. Take control. Schedule a consultation with an experienced estate planning attorney today. They’ll guide you through the process and ensure your legacy lives on.



Source link