The European Supervisory Authorities (EBA, EIOPA and ESMA – the ESAs) have published their first annual overview of major ICT-related incidents in the EU financial sector, based on the reporting framework established under the Digital Operational Resilience Act (DORA). The report highlights that ICT risks are increasingly cross-border and interconnected, and that rapid advances in AI necessitate financial entities to strengthen cybersecurity to maintain resilience going forward.
The report indicates that around one third of the 3,383 major incidents reported by financial entities in the EU (i.e. 0.18 per entity subject to DORA) had a cross-border impact, underscoring the growing interconnectedness through shared infrastructures and services, however, the direct impact on clients and transactions was generally limited. Most incidents stemmed from system failures and external events, underscoring the importance of third party risk management and coordination with service providers. Although only 10% of the reported incidents were cyber-related, rising AI capabilities mean firms must continue strengthening cybersecurity. Overall, the findings highlight the increasing systemic nature of ICT risk and the importance of resilience and supervision in strengthening the financial sector’s ability to prevent, absorb, and recover from future incidents.
Insurance Europe