
23 June 2026 • 6 minute read
EU report on major ICT incidents under DORA
Emerging Risks and Practical Implications for FirmsTwo new publications land at a critical moment for anyone negotiating technology contracts in the financial services sector within the EU. The first annual report from the European Supervisory Authorities (ESA) on ICT incidents under Digital Operational Resilience Act (DORA), alongside new findings from the Basel Committee, offers a clear message. Taken together, they paint a picture that those with responsibility for technology transactions, cyber incidents, operational resilience, regulatory engagement and corporate governance in the financial services sector, but also more broadly, should pause and consider.
Increasing incident rates and a clear pattern
The ESAs’ 2025 report is the first real dataset we have on how DORA’s incident reporting regime is functioning in practice. In its first full year of operation, financial entities reported 3,383 major IT-related incidents- roughly 282 per month across the sector. When considering all financial entities in the EU that are subject to DORA, this equates to roughly 0.18 incidents per entity.
Most of those incidents hit just two sectors: credit institutions (more than 60%) and payment services (16%). The ESAs note that this concentration may partly reflect the maturity of reporting culture in those sectors from PSD2; but, even allowing for that, the sheer volume underlines how banking and payment institutions are operationally exposed to such incidents.
What is the cause?
The most striking theme in the data is dependency on third parties. Almost one third of major incidents originate in failures linked to third parties, whether ICT providers, other financial institutions or infrastructure providers. The ESAs are blunt about the implications. Dependency on third-party providers is “an area for supervisory attention”" and underscores the need for financial entities to “further strengthen their third-party risk management frameworks ”.
These data points give a good indication of where regulatory focus is likely to be over the short to medium term. They also serve to further emphasise the key importance of financial services sector customers obtaining robust contractual commitments both around security but also reporting and assistance provision from their IT vendors.
We are already seeing this play out across technology deal negotiations in the market. The direction of travel is clear, and the data will only strengthen the resolve of customers pushing for firm and granular commitments here.
Cyber security remains under constant pressure
Cyber security incidents account for a smaller share (10%) of the total, but their impact is significant. The nature of those risks varies across sectors. Banks face concentrated threats such as denial-of-service attacks and data theft; while insurers are more exposed to ransomware, often because of the sensitivity of the data they hold.
What is changing is the pace and sophistication of those threats. The ESA highlights the growing risk posed by rapidly evolving AI tools, which have the potential to increase both the scale and precision of attacks.
The challenge posed by these cyber security threats means it is important that those leading deal teams (including the lawyers) are deeply familiar with and involved in the negotiation of dedicated security schedules - an area that may have historically been left to security subject matter experts.
A growing cross-border, cross-sector reality
The ESAs ’ territorial analysis highlights how interconnected the financial services system has become. Around one third of major incidents had cross-border impact and, in about 8% of cases, more than 10 countries were affected. The ESAs’ overarching conclusion is that operational disruptions are “increasingly borderless and cross-sector”, driven by shared infrastructures, common service providers and cross-border business models.
For Irish-regulated firms negotiating with global technology providers, this has practical implications. Contracts need to anticipate how incidents can cascade across systems, services and geographies. It also places greater emphasis on understanding what is accepted practice beyond a single market and taking a more holistic and multi-jurisdictional perspective. That translates to renewed emphasis on ensuring suppliers are committing to robust business continuity and disaster recovery and mitigation measures, such as commitments to have in place backup service sites.
In addition, we are seeing customers in the financial services sector respond to threats of this nature by building redundancy into core services. This includes measures such as source code, or evolving cloud and AI escrow arrangements, supported by experienced in-house talent or alternative suppliers ready to step in, with contractual rights to facilitate both.
Change control - “the silent killer”
Alongside the ESA findings, the Basel Committee’s report highlights a less visible but equally important issue. Surveying banks across 16 jurisdictions, it finds that the most frequently reported root cause of non-malicious IT incidents is change control gaps, followed by deficiencies in systems design, development and testing, system capacity and performance issues, and external dependency operational failure.
This should give pause to anyone drafting or reviewing change management provisions in technology contracts and points to the need for caution on renewal of longer-term critical outsourcing and other managed service arrangements. Continuing on the same terms may not be the best approach to address the current ICT landscape.
Change control clauses are often treated as operational boilerplate and something the project managers will resolve. But if change management failures are the single biggest driver of non-malicious IT incidents in banking, then the contractual architecture around change deserves the same scrutiny as your SLA regime or your termination rights.
What this means in practice
If you are a financial entity currently in the middle of a technology procurement or contemplating one, these publications reinforce a number of core priorities for your deal and contract. IT incidents are not theoretical - your contractual framework should be designed to reduce the likelihood of occurrence as far as possible. And when incidents do arise, it should position you to limit impact, avoid material damage and achieve a swift recovery with minimal or no disruption to customers.
For suppliers, there is a clear expectation that they will play a more active role. Customers will focus more closely on security commitments, risk allocation, and on what support will be available when incidents occur. Suppliers can use a thoughtful and comprehensive package of operational measures and contractual positions on these topics as a selling point in a sector that is only going to become increasingly focused on security and resilience.
A broader shift in accountability
Intensifying regulatory scrutiny and rising expectations on boards to demonstrate meaningful oversight of cyber security and operational resilience are driving the need for more coordinated, enterprise‑wide thinking across organisations.
At DLA Piper, we help clients to stay ahead of these challenges. We support boards and senior management teams through tailored sessions on cyber security and operational resilience, combining evolving regulatory expectations with practical, real-world governance approaches.
Our team advises daily on technology transactions, cyber incidents, operational resilience, financial services and insurance regulatory engagement, and corporate governance.
If you’d like to understand what these developments mean for your organisation, or how we can support, we’d be pleased to talk. For more information, please contact the authors.