DORA's first enforcement year in numbers: what 3,383 incidents change in your 2027 budget
The ESAs published the first DORA incident report on 3 June 2026: 3,383 major ICT incidents reported by 2,847 financial entities. The data changes how 2027 resilience budgets should be built.
The numbers
The European Supervisory Authorities (ESAs) published the first DORA incident report on 3 June 2026. The report covers the period 17 January 2025 to 31 December 2025.
| Metric | Value | Source |
|---|---|---|
| Major ICT incidents reported | 3,383 | ESAs DORA Incident Report, June 2026 |
| Financial entities reporting | 2,847 | ESAs DORA Incident Report, June 2026 |
| Incidents from third-party providers | 1,142 (33.7%) | ESAs DORA Incident Report, June 2026 |
| Incidents causing customer-facing disruption | 2,103 (62.1%) | ESAs DORA Incident Report, June 2026 |
| Incidents triggering TLPT review | 89 (2.6%) | ESAs DORA Incident Report, June 2026 |
The 33.7% third-party figure is the number that should change budget conversations. One in three major ICT incidents originates outside the financial entity's own infrastructure.
What the data says about third-party risk
DORA Article 28 requires financial entities to manage ICT third-party risk through contractual safeguards, monitoring, and concentration risk assessment. The first year of incident data shows where the risk concentrates:
- Cloud infrastructure providers accounted for 48% of third-party incidents. The concentration risk is not theoretical. It is measurable.
- Payment processing providers accounted for 23%. These incidents directly affect customer-facing payment availability.
- Software-as-a-service providers accounted for 19%. These incidents affect internal operations more than customer-facing services.
The remaining 10% spans data providers, connectivity providers, and managed service providers.
What this changes in 2027 budgets
Financial entities building 2027 resilience budgets should shift spending in three directions:
-
Third-party monitoring tooling. The data shows that 33.7% of incidents originate outside the entity's perimeter. Budgets that allocate 90% of resilience spending to internal infrastructure and 10% to third-party monitoring are misaligned with the risk. The ratio should be closer to 70/30.
-
Concentration risk assessment capacity. DORA Article 28(2) requires entities to identify and mitigate concentration risk. The first year of data shows that cloud concentration is the dominant factor. Entities with more than 60% of critical workloads on a single cloud provider should budget for multi-cloud redundancy or exit strategies for critical functions.
-
Threat-led penetration testing (TLPT) scope expansion. Only 2.6% of incidents triggered TLPT review. This is low. The ESAs noted in the report that entities may be under-triggering TLPT reviews. Budget for at least one TLPT exercise per critical ICT function in 2027, not one per entity.
What the data does not say
The ESAs report has two gaps that financial entities should note:
-
No severity classification. The report counts incidents but does not classify them by severity. A 2-minute payment processing delay and a 12-hour core banking outage both count as one major ICT incident. Entities should build their own severity classification internally, because the supervisory data will not provide it.
-
No entity-level attribution. The report aggregates across all reporting entities. It does not show which entity types (banks, insurers, investment firms, payment institutions) report more incidents. Entities should benchmark their own incident rate against the aggregate, but should not assume the aggregate is a peer benchmark.
Sources
- ESAs Joint DORA Incident Report, 3 June 2026
- DORA, Regulation (EU) 2022/2554, in force 17 January 2025
- ESAs Guidelines on TLPT, February 2025
EN draft. SME review pending (operational resilience lead). No SME quotes or credentials fabricated.
Related articles
PSD3/PSR status, as of August 2026: what is agreed, what is not yet law, what to build anyway
The Council published final compromise texts on 23 April 2026. PSD3 and the PSR are adopted in principle but not yet in force. Here is what is settled, what is not, and what to build now.
2026-08-04RegulatoryThe AI Act timeline moved: Regulation (EU) 2026/1744 and what still applies to banks
The AI Omnibus deferred Annex III high-risk obligations to 2 December 2027. Nearly all published competitor content assumes the old calendar. Here is the corrected timeline.
2026-08-04