The First DORA Major ICT Incident Report: What Banks Can Learn | eBSI

The First DORA Major ICT Incident Report: What Banks Can Learn

The first DORA incident overview provides an early evidence base

In June 2026 the European Supervisory Authorities published the first annual overview of major ICT-related incidents under the Digital Operational Resilience Act. The report is important not because it provides a complete picture of operational risk after only one reporting cycle, but because it begins to establish a harmonised evidence base across the European financial sector. Technology incidents are increasingly interconnected, and a failure affecting one provider can spread across institutions, countries and sectors.

DORA's reporting framework is designed to improve this visibility. Consistent classification and notification allow supervisors to identify common dependencies and coordinate responses to borderless incidents. For banks, the practical value is a stronger basis for improving incident management internally.

Classification and escalation need to be clear

Not every technical problem is a major incident. Institutions therefore need criteria that allow staff to distinguish routine operational issues from events that require senior management and regulatory attention. Customer impact, duration, geographical spread, financial loss, data compromise and service criticality may all influence classification.

This requires coordination between technology, risk, compliance and business functions. Technology teams may identify the initial fault, but business areas understand the customer and operational impact. Compliance teams manage notification obligations, while communications functions may need to inform customers and other stakeholders. Responsibilities should be established before the event occurs.

Incident response should protect critical services

The purpose of resilience is not merely to restore technology. It is to maintain or recover critical business services. Banks may need to activate backup systems, use manual workarounds, reconcile transactions or change customer communication. Senior management must sometimes make decisions under significant uncertainty.

Preparedness therefore matters. Incident plans should be concise enough to use in a real crisis. Critical contacts, decision rights and fallback communication channels need to remain available even when normal systems are disrupted. Recovery targets should include data integrity and business correctness as well as technical uptime.

Post-incident review is equally important. Root cause, detection effectiveness, escalation, communication and remediation should be examined systematically. A bank that restores service without learning from the event has recovered operationally but not improved organisationally.

Third-party risk is increasingly systemic

The first DORA overview also reinforces the borderless nature of technology risk. Financial firms rely heavily on cloud providers, software vendors and other external services. A bank can maintain strong internal controls while remaining exposed to the failure of a supplier. Due diligence and contract management therefore need to include resilience, incident communication and recovery capability.

Concentration risk is particularly significant. If one critical provider supports a large number of institutions, an outage can become a sector-wide event. This is one reason European authorities are placing greater attention on critical third-party providers under DORA.

Artificial intelligence adds another dimension. The ESAs noted that increasingly capable AI-driven tools should encourage financial entities to strengthen cybersecurity. Banks should therefore include AI dependencies and AI-enhanced threats in resilience scenarios rather than treating them as separate innovation topics.

Management information should focus on patterns

Harmonised reporting also creates an opportunity for sector-wide learning. An individual bank sees only its own incidents, while supervisors can identify patterns across many firms. Institutions should reproduce this logic internally. Several minor incidents caused by the same weak process may be more informative than one dramatic but unusual event.

Management dashboards should therefore include recurring root causes, supplier dependencies, recovery performance and overdue remediation actions. The objective is not to produce more reporting for its own sake; it is to make operational weakness visible before several small issues combine into a serious failure.

Conclusion

The first DORA incident report marks the transition from a regulatory framework on paper to evidence from real events. Banks now have a clearer basis for comparing internal practice with sector-wide expectations. The central lesson is that technology failure is inevitable, but the quality of preparation determines whether disruption remains manageable or becomes a crisis.

The eBSI Banking Academy treats operational resilience as part of modern banking competence. Professionals across operations, risk, compliance and management need enough understanding to recognise how digital disruption affects their own role. DORA is most useful when it changes behaviour between incidents, not only during them.

Source

European Banking Authority, “ESAs publish the first report on DORA major ICT-related incidents”, 3 June 2026.

The value of incident reporting lies in collective learning

A harmonised reporting framework allows supervisors to identify patterns that no single institution can see. Repeated incidents involving a particular type of supplier, control weakness or attack method may indicate a sector-wide vulnerability. Over time, this evidence can influence supervisory priorities and help financial institutions direct investment toward the areas that matter most.

Banks should apply the same principle internally by analysing clusters rather than treating each incident as isolated. Several minor outages caused by one recurring configuration problem may deserve more attention than a single dramatic but unusual event. Trend analysis can reveal where controls are deteriorating gradually. This is why management information should include recurring root causes and unfinished remediation actions, not only the count of incidents reported during the period.

The quality of reporting also depends on organisational culture. Staff need to report near misses and emerging problems without fearing that transparency will be treated as failure. A culture that hides small incidents to protect performance metrics usually increases the probability of a larger incident later. DORA can provide the framework, but resilience ultimately depends on behaviour inside the institution.

Preparing for the next reporting cycle

Banks should use the first annual overview as a prompt to review the quality of their own incident data. If classifications are inconsistent or root causes are recorded superficially, the organisation loses much of the learning value that DORA is intended to create. Internal taxonomies should therefore be applied consistently enough to allow meaningful trend analysis over time.

Institutions should also test whether regulatory reporting can be completed without distracting key personnel from operational recovery. The best arrangements allow information required for notification to be captured as part of the response process rather than reconstructed later. This reduces duplication and improves accuracy.