Eighteen months after the Digital Operational Resilience Act became applicable, the three European Supervisory Authorities, the EBA, ESMA, and EIOPA, have published the first hard numbers behind it. Their joint report catalogues 3,383 major ICT-related incidents reported by EU financial entities across 2025, an average of 0.18 major incidents per firm subject to DORA, concentrated most heavily in the credit and payments sectors. Roughly a third of those incidents had cross-border impact. The headline finding, though, is what actually caused them.
The data does not match the narrative
Ask most boards what keeps their operational resilience team up at night, and the answer is usually a ransomware gang or a nation-state actor. The ESAs’ data says otherwise: cyber-related incidents accounted for only 10 percent of the 3,383 major incidents logged in 2025. System failures and, notably, third-party dependencies did far more damage. Almost a third of major incidents originated from a failure at an ICT provider, another financial entity, or shared infrastructure the reporting firm did not directly operate. Two thirds of incidents caused no or only minor disruption to clients, which is the encouraging part, but it also means roughly a third did not, and those are disproportionately the ones tracing back to a vendor.
That distribution should reshape how financial entities allocate resilience budget. A security programme built primarily around threat detection and incident response for cyberattacks is answering only one incident in ten. The bigger, more structural exposure, an outsourced payments processor, a shared data centre, a critical software vendor, a fellow financial entity your systems depend on, is where DORA’s Register of Information and third-party risk management provisions were always aimed, and where this data now confirms the real risk sits.
Enforcement is no longer theoretical
Supervisors have made clear that the 2026 supervisory cycle is when DORA enforcement for serious incident reporting failures and persistent gaps in the Register of Information moves from guidance to consequence. A firm whose incident classification process cannot distinguish a “major” incident from a routine one, or whose Register of Information still has gaps around critical third-party providers, is now working against a dataset regulators will use to benchmark what a properly functioning reporting regime looks like. The first annual report is also a preview of the second: expect next year’s edition to be read for whether reported incident volumes and root causes shift as enforcement pressure increases, and whether firms that under-reported in 2025 start showing up in the numbers.
If your organisation needs help auditing its DORA incident classification process, closing gaps in its Register of Information, or building genuine third-party resilience rather than a compliance document that only looks complete, contact Excello Digital. We help European financial entities and their critical suppliers turn DORA’s requirements into operational resilience that would survive an actual incident, not just a supervisory review.
