First DORA Incident Report Highlights Growing ICT Resilience Risks


Date: 12 June 2026

Featured Image

The European Supervisory Authorities (EBA, EIOPA and ESMA) have released the first annual report on major ICT-related incidents under the Digital Operational Resilience Act (DORA). While many organisations viewed DORA as another regulatory hurdle, the findings suggest something much bigger.

The report paints a picture of a financial sector operating in an environment where ICT disruptions are increasingly interconnected and cross-border. This shows that any disruption is capable of creating systemic consequences. For financial institutions, the takeaway is simple: resilience can no longer exist only on paper. It must be demonstrated in practice.

What Did the Report Reveal?

The report analysed 3,383 major ICT-related incidents reported across the EU financial sector during 2025. That averages approximately 282 major incidents every month. Credit institutions and payment providers accounted for the largest share of reported incidents.

Perhaps more importantly, around one-third of all major incidents had cross-border impacts. This highlights how interconnected financial services have become and how a disruption in one location can quickly affect customers, partners, and operations across multiple countries.

The report also found that major incidents were not driven exclusively by cyber attacks. System failures, technology outages, and third-party dependencies featured prominently. In other words, operational resilience is no longer just a cybersecurity challenge. It is a business resilience challenge.

This distinction matters because many organisations still focus most of their preparedness efforts on preventing cyber attacks. DORA’s first year of reporting demonstrates that resilience requires organisations to prepare for technology failures, supplier disruptions, cloud outages and other similar complex cascading events.

The Growing Systemic Nature of ICT Risk

One of the strongest messages from the report is that ICT risk is becoming increasingly systemic. Financial institutions rely on shared cloud platforms, outsourced service providers, software vendors, payment networks, and interconnected digital ecosystems. A failure affecting one critical provider can have consequences across multiple organisations and jurisdictions.

This is exactly why DORA places such a strong emphasis on ICT third-party risk management. Organisations are expected not only to understand their own systems but also their dependencies on external providers and the concentration risks those dependencies create.

The findings reinforce a reality that cybersecurity professionals have been discussing for years: organisations do not operate in isolation. Their resilience is increasingly tied to the resilience of their suppliers, technology partners, and service providers.

Why Incident Reporting Is Only the Beginning

Many organisations initially associated DORA with incident reporting requirements. While reporting remains important, the regulation is ultimately focused on something much broader.

DORA requires financial entities to identify, classify, escalate, manage, recover from, and learn from ICT-related incidents. Reporting is simply the visible outcome of those activities. The challenge is that organisations cannot meet reporting obligations if they struggle with internal decision-making during a crisis.

Questions such as:

  • Who declares a major incident?
  • Who owns regulatory communications?
  • Who approves customer notifications?
  • When should senior management be involved?
  • When does an operational issue become a regulatory event?

These decisions must be made quickly and consistently under pressure.

Without clearly defined processes and tested response procedures, reporting deadlines become difficult to achieve. DORA’s reporting framework is designed to encourage organisations to build operational maturity long before a major incident occurs.

DORA Is Shifting the Conversation from Prevention to Resilience

One of the most interesting findings in the ESAs’ first DORA incident report is the recognition that operational disruptions are no longer viewed as exceptional events that can always be prevented. The report explicitly acknowledges that the increasing digitalisation and interconnectedness of the financial sector make operational incidents “to some extent unavoidable.”

Rather than focusing solely on the number of incidents reported, the ESAs argue that resilience should be measured by how effectively organisations manage and contain those incidents once they occur.

This is a message that will be familiar to anyone who has attended CM-Alliance’s NCSC Assured Cyber Incident Planning and Response training. Since 2020, we have consistently emphasised that while prevention remains important, organisations must accept that not every incident can be stopped. The real measure of maturity is not whether an organisation experiences an incident, but how effectively it prepares for responding to and recovering from one.

In many ways, DORA is now formalising at a regulatory level what resilience practitioners have been advocating for years: resilience matters more than the unrealistic pursuit of complete prevention.

The data strongly supports this view. Despite 3,383 major ICT-related incidents being reported across the EU financial sector in 2025, the report found that two-thirds resulted in no or only minor disruption to clients and transactions.

According to the ESAs, this suggests that timely detection, effective incident response, and rapid containment measures were successful in limiting operational harm and preventing wider spillover effects.

The same conclusion is reinforced later in the report, which notes that the direct impact on clients and transactions was limited in most cases, likely because organisations were able to detect incidents quickly and implement remedial actions before they escalated into broader disruptions.

Why Playbooks Are Becoming Essential for DORA Compliance

This is where many financial institutions still have work to do. An operational resilience policy may explain what should happen during an incident. But a playbook explains exactly how it happens.

Well-designed incident response playbooks provide clear escalation paths and response actions tailored to specific scenarios. For example, the response to a ransomware attack differs significantly from the response to a cloud service outage or a major technology malfunction.

Yet many organisations still rely on generic incident response plans that provide limited operational guidance when a real crisis unfolds.

Under DORA, organisations are expected to demonstrate repeatable and effective response capabilities. Playbooks help transform high-level requirements into practical actions that teams can execute under pressure.

This is one reason why many financial institutions are now reviewing and modernising their incident response documentation to align with DORA expectations.

The Real Test: Can Your Teams Execute?

Having a playbook is important. Knowing whether it works is even more important. DORA places significant emphasis on digital operational resilience testing. Regulators want organisations to demonstrate that their plans, controls, processes, and teams can perform effectively during realistic disruption scenarios.

This is where tabletop exercises and cyber resilience testing become critical. A well-designed exercise can reveal:

  • Unclear ownership and accountability
  • Escalation bottlenecks
  • Communication breakdowns
  • Regulatory reporting gaps
  • Weaknesses in third-party coordination
  • Executive decision-making challenges

These are precisely the types of issues that often emerge during real incidents. The organisations that perform best during crises are rarely the ones with the thickest policies. They are the ones that have practised their response, challenged assumptions and refined their processes before an incident occurs.

What Financial Institutions Should Do Next

The first DORA incident report should serve as a wake-up call for organisations that still view resilience as a compliance exercise.The report confirms that major ICT incidents are frequent, interconnected, and increasingly capable of creating cross-border disruption. It also highlights that resilience requires much more than technical controls. Decision-making, communication and third-party risk management all play a crucial role.

Financial institutions should use these findings as an opportunity to assess whether they can confidently answer the following questions:

  • Are our incident response playbooks fit for modern threats?
  • Have we tested them recently?
  • Can executives make critical decisions under pressure?
  • Are regulatory reporting responsibilities clearly understood?
  • Can we effectively coordinate with key suppliers during a major disruption?
  • Have we validated our response capabilities through realistic exercises?

If the answer to any of these questions is uncertain, there is work to do.

How Cyber Management Alliance Helps Organisations Become DORA Compliant

Cyber Management Alliance helps financial institutions move beyond compliance and build genuine operational resilience. Our specialists work with organisations across the financial sector to develop and review incident response plans.

We also help you create scenario-specific cyber incident playbooks and conduct realistic cyber tabletop exercises that align with DORA requirements. Our NCSC-Assured training programmes, executive cyber crisis workshops, ransomware simulations, operational exercises, and technical cyber drills help organisations validate their readiness before regulators, customers, and stakeholders put it to the test.

The first DORA incident report confirms what many security leaders already suspected. Resilience is no longer measured by the controls you implement. It is measured by how effectively your organisation responds when those controls fail. The institutions that invest in preparation today will be the ones best positioned to withstand tomorrow’s disruptions.

If you’re still looking for a partner who can help you achieve DORA compliance and elevate your organisational operational resilience, reach out to us today. Our bespoke solutions are curated to address the exact needs of your business, its scale, size and sector. We help you achieve compliance and go beyond it so that you feel assured in the operational resilience capabilities of your business.  





Source link

Leave a Reply

Subscribe to Our Newsletter

Get our latest articles delivered straight to your inbox. No spam, we promise.

Recent Reviews


Digital marketing changes fast. One minute a platform is hot, the next it’s outdated. Consumer habits shift quickly, and the strategies that worked last year might not work today. If you’re trying to stay relevant in this ever-evolving field, the big question is: how can you level up your skills without going back to school?

Whether you’re brand-new to marketing or a traditional marketer moving into digital, here are seven practical (and proven) ways to sharpen your skills, no formal degree required.

1. Take Online Courses That Actually Teach You Something

Not all online courses are equal. The best ones are built by marketers who actually do this stuff every day not just teach theory. These courses blend hands-on learning with real-world projects that help you build skills employers care about.

What to look for:

  • Instructors with real industry experience
  • Projects based on actual campaigns
  • Updated content that reflects current tools and platforms
  • Certifications that carry weight on your resume

Recommended platforms: Google Skillshop, HubSpot Academy, and LinkedIn Learning are all great places to start.

2. Learn from the Pros in the Industry

Want to know what’s working in digital marketing right now? Follow the experts who are already doing it. They share not just tactics but also insights into the strategy behind successful campaigns. If your goal is to become an SEO expert in Nepal, seek out local professionals who are ranking well or leading agencies you’ll gain insights that are specific to your market.

How to get the most from them:

  • Follow a mix of global and local thought leaders
  • Subscribe to their newsletters and podcasts
  • Ask questions and engage with their content
  • Join their webinars or virtual events

Tip: Pick experts in areas you want to master—SEO, social media, email marketing, or AI tools.

3. Use Free Resources to Explore and Learn

You don’t always have to pay to learn. There’s a ton of free, high-quality content online that covers everything from the basics to advanced strategies.

Top free resources to check out:

  • Coursera & edX: Free courses from top universities
  • Google Digital Garage: Solid fundamentals in digital marketing
  • YouTube: Tutorials, breakdowns, and real case studies
  • Blogs: Keep up with Moz, Search Engine Journal, and Content Marketing Institute

4. Get Hands-On with Personal Projects

Reading is helpful, but doing is where the real learning happens. Try testing strategies on a personal blog, passion project, or fictional brand.

Simple project ideas:

  • Start a blog and learn SEO by optimizing your posts
  • Run a small Instagram or Facebook campaign
  • Build an email list for a hobby or passion project
  • Try a basic Google Ads campaign with a tiny budget

5. Join Online Communities and Connect with Others

One of the best parts of digital marketing is the community. There are countless online (and offline) spaces where marketers help each other grow.

Where to find them:

  • LinkedIn groups: Look for niche-focused communities
  • Reddit: r/digitalmarketing, r/SEO, and r/PPC are packed with advice
  • Slack groups: Many cities and marketing niches have active ones
  • Local events: Don’t underestimate the power of in-person networking

6. Get Certified (It’s Worth It)

Certifications show that you’ve taken the time to learn and understand the tools. They’re especially helpful if you’re transitioning from another field or just getting started.

Top certifications to consider:

  • Google Ads & Google Analytics
  • HubSpot Inbound Marketing
  • Meta (Facebook) Social Media Marketing
  • Salesforce Marketing Cloud (for advanced roles)

7. Analyze Real Marketing Data

Looking at real-world data helps you understand what works—and what doesn’t. Try working with small businesses or nonprofits to get your hands on real campaign results.

Where to find real data opportunities:

  • Help a local business improve their online presence
  • Volunteer for a nonprofit’s marketing team
  • Freelance on small gigs to build a portfolio
  • Ask your employer to let you assist on a digital campaign

The Skills That Will Make You Stand Out

To be great at digital marketing, you need a mix of creative and analytical abilities. The top marketers are flexible, data-savvy, and constantly learning.

Here’s what to focus on:

  • Analytics: Know how to read and act on data
  • Writing and content: Craft messages that get attention and convert
  • Tech skills: A basic understanding of HTML, email tools, and CRMs
  • Strategy: Know how to align marketing goals with business objectives
  • Adaptability: Be ready to pivot with new trends and tools

Start Small, Learn Fast

You don’t need a fancy degree to break into or level up in digital marketing. What you need is consistency, curiosity, and a bit of creativity. Pick one or two of the strategies above that fit your style, and commit to them for the next month.

Most importantly, don’t just learn—apply. Watch a course, then launch a mini-campaign. Read a blog, then try out the strategy on your own site. Digital marketing rewards action, not just knowledge.



Source link