On 3 June 2026, the European Supervisory Authorities — the European Banking Authority, the European Insurance and Occupational Pensions Authority and the European Securities and Markets Authority (together, the "ESAs") — published their first annual report on major ICT-related incidents under Article 22 of the Digital Operational Resilience Act ("DORA").
The report establishes the first incident baseline for the EU financial system, giving regulators and market participants a common set of figures to work from. This alert sets out the report’s key findings and what they mean in practice for financial entities, their ICT third-party providers and the legal and compliance teams responsible for managing DORA obligations at in-scope organisations.
More Incidents, Not Less Resilience
A total of 3,383 major ICT-related incidents were reported across the EU financial sector in 2025 — an average of 282 a month, or 0.18 incidents per financial entity subject to DORA. Taken alone, these figures look alarming. But the ESAs are clear that incident volume is not, on its own, a risk indicator: rising digitalisation, complexity and interconnectedness make some incidents unavoidable, and resilience is better measured by how quickly entities detect, manage and contain them.
Two sectors accounted for more than three-quarters of all reported incidents. Over 60% occurred in the credit sector (0.57 incidents per entity on average), and payments firms accounted for a further 16% (0.23 per entity). This concentration reflects, at least in part, market structure, pre-existing PSD2 reporting obligations dating back to 2018 and the fact that these sectors sit at the most digital, customer-facing end of financial services.
Notably, two-thirds of major incidents caused no, or only minor, disruption to clients and transactions, and timely detection paired with effective incident response and containment measures generally limited operational harm and spillover. The point is not that incidents can be avoided — they can’t — but that they can be caught and contained before they cause serious damage.
Cross-Border Reach, But Relatively Limited Customer Impact
Almost 60% of major incidents left clients unaffected or affected fewer than 1,000 entities or individuals. Only a small number of incidents affected more than one million clients, these were concentrated overwhelmingly in the credit and payments sectors, with fewer in insurance and asset management. Transaction data tells the same story: 32% of incidents affected no transactions at all, and a further 26% affected fewer than 1,000. Only 30 incidents — roughly 1% of the total — impacted a million transactions or more, again concentrated in credit and payments sectors.
By contrast, a third of major incidents (1,056) had cross-border impact, extending beyond the country where they were first reported. Roughly a third of these affected one or two other EU Member States, and around 8% of all major incidents affected more than ten countries affected. Fewer than 18% of major incidents affected other financial counterparties, and more than two-thirds of those arose, again, in credit and payments.
System failures and external events drove most major incidents, accounting for 51% and 27% of incidents, respectively, with payment-related incidents making up a further 18%. Root causes followed a similar pattern: system failure or malfunction (around 50%), external events (32%), process failures (19%) and human error (12%). Human error was most prominent in the credit sector, while the ratings and benchmarks and pensions sectors reported no major incidents caused by human error.
Almost a third of major incidents originated from failures attributable to third parties — ICT providers, other financial entities and infrastructure providers. In other words, robust vendor risk management and oversight of outsourced services remain critical. But outsourcing infrastructure does not mean outsourcing resilience: operational continuity still depends on rigorous vendor oversight, contractual safeguards, third-party testing and escalation protocols that function beyond the entity’s own perimeter.
Cybersecurity: An Escalating Threat
Interestingly, cybersecurity-related incidents accounted for just 10% of all major incidents. That relatively low share suggests that existing safeguards and detection mechanisms have generally been effective — although, as we have written, financial services firms are running to keep pace with increasingly capable AI-driven attack tools.
DDoS attacks (33%) and data exfiltration or manipulation, including identity theft (31%), were the most common techniques, together accounting for the majority of cybersecurity incidents. Both occur significantly more often in the credit sector — likely a function of scale, the concentration of sensitive data, the sector’s role in payments processing, and monitoring frameworks mature enough to catch and report incidents consistently. Ransomware, by contrast, appears to target the insurance sector specifically — unsurprising, given the volume of sensitive health and financial data insurers hold.
On 7 July 2026, the European Systemic Risk Board ("ESRB") issued a formal warning on the systemic cyber risks posed by frontier AI models, having upgraded its assessment of systemic cyber risk from "elevated" to "severe" within a few months. The ESRB’s concern is that frontier models can now identify vulnerabilities, develop working exploits and execute cyberattacks at a speed and scale that leaves financial entities little time to respond.
The ESAs publicly endorsed the warning, and the ECB separately wrote to the CEOs of significant euro area banks requiring action plans by autumn 2026 on strengthening systems and managing AI-related risk. Together, these developments signal that supervisors expect board-level engagement with AI-enabled threats well before the next incident reporting cycle, not a restatement of existing cybersecurity policy.
Takeaways For In-Scope Organisations
The ESAs’ first annual report confirms several themes that should shape operational resilience strategies across the EU financial sector.
- Operational disruptions are increasingly both borderless and cross-sectoral, driven by interconnectedness and shared infrastructure. Accordingly, resilience frameworks should extend beyond national boundaries and sectoral silos.
- System failures and external events, including those originating with third parties, remain the dominant drivers of incidents, and in-scope entities should prioritise ICT governance, change management, testing and third-party risk management.
- Low cybersecurity incident numbers are reassuring, but that will not last if AI-enabled attacks develop as expected.
- Incident volume is not a proxy for risk. What actually limits harm is effective detection and containment — not the illusion that every incident can be prevented.
- With the first 19 CTPPs now designated, audit your register of ICT dependencies against the published list, and prioritise contractual and exit-planning safeguards for the concentrated providers that did not make the cut.
- Frontier AI has moved from theoretical worry to supervisory-grade concern. With systemic cyber risk now rated “severe” by the ESRB, expect AI-enabled attack scenarios to feature explicitly in examinations — and be ready to show that the board is genuinely engaged with the issue, not merely aware of it.
Subscribe to Ropes & Gray Viewpoints by topic here.
Authors
Stay Up To Date with Ropes & Gray
Ropes & Gray attorneys provide timely analysis on legal developments, court decisions and changes in legislation and regulations.
Stay in the loop with all things Ropes & Gray, and find out more about our people, culture, initiatives and everything that’s happening.
We regularly notify our clients and contacts of significant legal developments, news, webinars and teleconferences that affect their industries.
