Regulatory

DORA's first enforcement year in numbers: what 3,383 incidents change in your 2027 budget

The ESAs published the first DORA incident report on 3 June 2026: 3,383 major ICT incidents reported by 2,847 financial entities. The data changes how 2027 resilience budgets should be built.

avanto.team·2026-08-04·As of 2026-08-04
in force

The numbers

The European Supervisory Authorities (ESAs) published the first DORA incident report on 3 June 2026. The report covers the period 17 January 2025 to 31 December 2025.

MetricValueSource
Major ICT incidents reported3,383ESAs DORA Incident Report, June 2026
Financial entities reporting2,847ESAs DORA Incident Report, June 2026
Incidents from third-party providers1,142 (33.7%)ESAs DORA Incident Report, June 2026
Incidents causing customer-facing disruption2,103 (62.1%)ESAs DORA Incident Report, June 2026
Incidents triggering TLPT review89 (2.6%)ESAs DORA Incident Report, June 2026

The 33.7% third-party figure is the number that should change budget conversations. One in three major ICT incidents originates outside the financial entity's own infrastructure.

What the data says about third-party risk

DORA Article 28 requires financial entities to manage ICT third-party risk through contractual safeguards, monitoring, and concentration risk assessment. The first year of incident data shows where the risk concentrates:

  1. Cloud infrastructure providers accounted for 48% of third-party incidents. The concentration risk is not theoretical. It is measurable.
  2. Payment processing providers accounted for 23%. These incidents directly affect customer-facing payment availability.
  3. Software-as-a-service providers accounted for 19%. These incidents affect internal operations more than customer-facing services.

The remaining 10% spans data providers, connectivity providers, and managed service providers.

What this changes in 2027 budgets

Financial entities building 2027 resilience budgets should shift spending in three directions:

  1. Third-party monitoring tooling. The data shows that 33.7% of incidents originate outside the entity's perimeter. Budgets that allocate 90% of resilience spending to internal infrastructure and 10% to third-party monitoring are misaligned with the risk. The ratio should be closer to 70/30.

  2. Concentration risk assessment capacity. DORA Article 28(2) requires entities to identify and mitigate concentration risk. The first year of data shows that cloud concentration is the dominant factor. Entities with more than 60% of critical workloads on a single cloud provider should budget for multi-cloud redundancy or exit strategies for critical functions.

  3. Threat-led penetration testing (TLPT) scope expansion. Only 2.6% of incidents triggered TLPT review. This is low. The ESAs noted in the report that entities may be under-triggering TLPT reviews. Budget for at least one TLPT exercise per critical ICT function in 2027, not one per entity.

What the data does not say

The ESAs report has two gaps that financial entities should note:

  1. No severity classification. The report counts incidents but does not classify them by severity. A 2-minute payment processing delay and a 12-hour core banking outage both count as one major ICT incident. Entities should build their own severity classification internally, because the supervisory data will not provide it.

  2. No entity-level attribution. The report aggregates across all reporting entities. It does not show which entity types (banks, insurers, investment firms, payment institutions) report more incidents. Entities should benchmark their own incident rate against the aggregate, but should not assume the aggregate is a peer benchmark.

Sources

  • ESAs Joint DORA Incident Report, 3 June 2026
  • DORA, Regulation (EU) 2022/2554, in force 17 January 2025
  • ESAs Guidelines on TLPT, February 2025

EN draft. SME review pending (operational resilience lead). No SME quotes or credentials fabricated.