• Sectors we work in banner(2)

    Quick Reads

European Supervisory Authorities publish first Joint Report on Major ICT incidents under DORA: Key lessons and practical recommendations for ICT contracting

min read

On 3 June 2026, the European Supervisory Authorities (the European Banking Authority, European Insurance and Occupational Pensions Authority and European Securities and Market Authority, together the "ESAs") published their first joint report on major ICT-related incidents under Article 22(2) of the Digital Operational Resilience Act ("DORA"). The report provides an aggregated overview of major ICT incidents that occurred across the European Union financial sector in 2025, which marks the first full year of reporting under DORA's harmonised incident reporting framework. This article summarises the report's key findings and sets out practical recommendations for legal teams operating in the financial sector negotiating and managing ICT contracts.

 

Scale and distribution of incidents

In 2025, a total of 3,383 major ICT incidents were reported across all EU financial sectors with an average of 282 major incidents reported per month. DORA casts a wide regulatory net which includes credit, insurance, payments, crypto, asset management, insurance and pensions institutions. Notably, the credit and payments sectors accounted for over 75% of all reported incidents, with more than 60% occurring in the credit sector and 16% affecting the payments sector. The ESAs stated that these numbers are not a sign of any sector-specific weaknesses but instead are linked to the digitalised and consumer-facing nature of banking and payment services, as well as the pre-existing incident reporting framework under the Payment Services Directives which has applied to these sectors since 2018. Surges in reporting mapped onto specific cross-border and cross-sectoral events in February, April and May 2025, including the TARGET2 outage and the Iberian Peninsula power blackout. 

Root causes and classification criteria 

System failures were reported as the cause of 51% of all major incidents, followed by external events (27%), payment-related incidents (18%) and human error (12%). Cybersecurity incidents accounted for only 10% of the total, with the report suggesting that existing safeguards and detection mechanisms were generally effective in limiting such incidents. Critically, 29% of all major incidents originated from a failure attributable to a third-party provider. The ESAs stated explicitly that dependencies on third-party providers (even those not designated as critical) constitute an area of supervisory attention. The report underscores the need for financial entities to further strengthen their third-party risk management frameworks. 

Most incidents were classified as major due to the duration of the incident and service downtime, or the impact on clients, financial counterparts and related transactions. Around 16% of incidents were classified as major due to associated reputational impact, particularly where the incident was reported in the media, resulted in repetitive complaints from customers and/or caused the organisation to lose customers. A third of major incidents (1,056 in total) had a cross-border impact, with around 8% of all incidents affecting more than 10 countries, highlighting the unique borderless nature of ICT risks and the interconnectedness of the financial sector. 

Direct impact and remediation

Despite the volume and broad geographical reach of some of the incidents, the direct impact of these incidents on clients and transactions was largely limited: approximately 60% of major incidents resulted in either no client impact or a minor impact affecting fewer than 1,000 clients, while 32% of incidents either did not affect any transactions or affected fewer than 1,000 transactions. The ESAs attributed this to the timely detection of incidents and the relatively swift implementation of remedial actions by financial entities. The incidents with a heavier impact on clients were largely concentrated in the credit and payment sectors, with a few occurring in the insurance and asset management sectors. The report indicates this is potentially due to the daily use of these services. 

In terms of costs, half of all major incidents reported no direct or indirect costs or costs of less than 1,000 euros. Most incidents followed a similar remedial pattern: (i) rapid technical intervention to restore service continuity and (ii) the implementation of longer-term corrective measures, including improvements to monitoring, alerting and testing, the correction or reconstruction of data, and coordination with external service providers. 

Supervisory outlook

The report sets out five key conclusions:

  1. Operational disruptions increasingly impact across borders and sectors, in part due to shared infrastructure;
  2. System failures and external events, often originating from third-party providers, are the main catalysts of major incidents, which emphasises the importance of effective third-party risk management and oversight;
  3. The relatively low occurrence of cybersecurity incidents indicates that existing security measures have been broadly effective in preventing the escalation of cybersecurity incidents;
  4. The limited direct impact on clients and transactions indicates that timely detection and incident response mechanisms are generally working; and
  5. Levering the harmonised DORA reporting framework is key to ensuring that supervisory authorities are aware of ICT risks and can effectively coordinate amongst competent authorities across the EU.

Looking ahead, the ESAs have indicated that a new IT tool for competent authorities' reporting of major incidents will be introduced in 2026, together with automated validation checks. The DORA Register of Information will be used alongside incident data to identify incidents which originate from critical ICT third-party providers and to improve authorities’ understanding of where risk concentrates systemically.

Practical recommendations for ICT contracts

In light of the report's findings, legal teams working in and/or advising the financial sector should consider the following practical steps in order to strengthen third-party ICT contracts:

  1. Ensure strict third-party incident response and notification obligations are embedded in your contracts: Given that almost one third of major incidents originated from third-party failures, ICT contracts should impose clear obligations on suppliers to detect, notify and remediate incidents within timeframes that will allow the financial entity to meet its own DORA reporting obligations. Under DORA, financial entities must submit an initial notification within four hours of classifying an incident as major and no later than 24 hours of becoming aware of it. This is then followed by a more detailed intermediate report within 72 hours and a final report within 1 month. The latter is expected to cover a complete post-incident review and a comprehensive root cause analysis. Contracts should therefore require ICT providers to notify the bank of any incident affecting their services immediately (and at the latest within one to two hours), followed by further cooperation as necessary at each phase of the DORA reporting timeline. Contracts should specify the exact information the provider must supply during each phase in line with the reporting requirements under DORA (including imposing a general obligation to cooperate with the financial entity on all incident reporting, such as the preparation of a root cause analysis). 
     
  2. Address concentration risk and potential cross-border impacts of ICT services: The report highlights that shared infrastructure and common ICT service providers can create a multiplier effect, where a single failure generates dozens of related major incidents across group entities. Awareness of the financial entity's dependencies on key providers is therefore essential. Robust contractual provisions which ensure resilience and business continuity across jurisdictions should be incorporated into ICT arrangements as a priority. This may include requiring providers to maintain geographically diverse infrastructure, to test failover procedures and to provide transparency regarding their own sub-contracting and concentration risks. This should additionally be supported by comprehensive audit and information rights which allow the regular assessment of a provider's resilience arrangements. 
     
  3. Embed service level requirements which align with DORA’s classification criteria: The report highlights that the vast majority of incidents were classified as major on the basis of duration and service downtime, and the number of clients, financial counterparts and transactions affected. Contractual service level commitments should reflect these classification thresholds. Such provisions may include maximum permissible downtime windows, recovery time and point objectives, which, if breached, would automatically trigger escalation, remediation and service credit or termination rights where appropriate. Financial entities may consider including cooperation provisions which address potential reputational impacts and require the parties to agree a communications strategy and media management process in the event an incident results in, or is likely to result in, adverse press coverage.
     
  4. Strengthen contractual provisions on change management and testing: In addition to comprehensive change management processes, financial entities should also consider including contractual requirements for providers to undertake regular scenario-based operational resilience testing (and as necessary, involving the financial entity in this process), as well as to report on the outcomes of such testing. 
     
  5. Ensure contracts allow for cost recovery and regulatory compliance: Financial entities are required under DORA to report direct and indirect costs and losses caused by major incidents, including foregone revenues, software replacement costs, staff overtime, customer compensation and amounts due for non-compliance with contractual obligations. However, the joint report notes that data quality on costs was poor, with many entities reporting no costs at all. ICT contracts should include comprehensive indemnity and liability provisions which cover these categories of loss. Contracts should also include obligations on providers to supply all data and information which enables the financial entity to accurately quantify and report incident-related costs to its competent authority, in support of its DORA reporting requirements.

Conclusion

In conclusion, the ESAs' first Joint Report under DORA provides valuable insight into the ICT risk landscape across the EU financial sector. The report makes clear that although increasing digitalisation may make operational incidents difficult to avoid entirely, the resilience and responsiveness of the financial sector remain paramount. This includes the ability to identify, manage and contain major incidents promptly so as to limit the impact on businesses, clients and transactions. Timely detection, combined with effective response and containment measures, should be deployed to limit both immediate and future operational disruption. As system failures have been identified as the leading driver of major incidents with a significant proportion of these failures linked to third-party arrangements, robust third-party risk management, oversight and coordination are essential to safeguarding business resilience and continuity.

For financial entities, these findings reinforce the importance of agreeing comprehensive contractual frameworks with ICT providers, particularly regarding incident notification, third-party resilience and business continuity processes. As we anticipate supervisory scrutiny will only intensify as DORA’s regulatory framework develops, financial entities should take the opportunity now to review and strengthen their ICT contractual arrangements as well as their risk management strategies and processes.

For further information or assistance in this regard, please contact our Commercial team.

Our thinking

  • IBA Annual Conference 2026

    Jean-Baptiste Beauvoir-Planson

    Events

  • Surveyors' Refresher Seminar

    Hope Barton

    Events

    min read
  • Building Safety Update Seminar

    David Savage

    Events

    min read
  • What Wadworth Tells Us About the Next Phase of PISCES

    Greg Stonefield

    Insights

    min read
  • Supply chain: social audits

    Kerry Stares

    Insights

    min read
  • Building Safety Levy: What Do the Proposed 2026 Amendments Mean?

    Mark Barley

    Insights

    min read
  • Autumn Budget 2026: possible CGT changes and pre-budget planning

    Julia Cox

    Insights

    min read
  • Family team successfully represent high-profile businessman in High Court jurisdiction dispute case

    Matt Foster

    Quick Reads

    min read
  • Can you terminate an “indefinite” trade mark licence even if there’s no express right to do so?

    Isabella Ross-Skinner

    Insights

    min read
  • Technology, AI and US Family Offices

    Hugh Dixon

    Quick Reads

    min read
  • Reaz Jafri quoted in CNBC on EU crackdown on Caribbean "golden passport" programmes

    In the Press

    min read
  • Shaping the Future of AIM: What the New AIM Rules Mean for Growth Companies, Founders and Advisers

    Paul Arathoon

    Insights

    min read
  • Charles Russell Speechlys named a ‘Firm to Watch’ by India Business Law Journal

    News

    min read
  • Kerry Stares, Rory Partridge, and Lyla Gilbert write in Packaging Europe about landmark reforms on packaging sustainability regulations in the UK and Europe

    Kerry Stares

    In the Press

    min read
  • Arbitrating Construction Disputes – Comparing the ICC, LCIA, SIAC and SCCA Rules

    Christopher O'Brien

    Insights

    min read
  • Simon Ridpath discusses Charles Russell Speechlys' strategic US expansion with Legal Business

    In the Press

    min read
  • What last week’s Bank of England decision means for private capital stakeholders

    Philip Withey

    Insights

    min read
  • Corporate Deal Highlights - A spotlight on H1 2026

    Sarah Wigington

    Insights

    min read
  • Anna Sowerby writes in City AM about the implications for sponsorship agreements when sporting events are cancelled

    Anna Sowerby

    In the Press

    min read
Back to top