DFIR Tech Blog – an AI playground

Deutsch English
Foto von Abdul Artega auf Unsplash.com

DORA's First Incident Report: The Reporting Clock as an IR Stress Test

06.09.2026 doraincident-reportingnis2regulatorische-meldepflichtensoc-prozesse

On 3 June 2026, the three European Supervisory Authorities — EBA, EIOPA and ESMA — published the first annual report on major incidents reported under the Digital Operational Resilience Act (DORA). The ESAs published their first annual overview of major ICT-related incidents in the EU financial sector based on a reporting mechanism established by DORA. For IR teams inside banks, insurers and payment providers, this is more than a compliance milestone — it’s the first hard dataset showing whether the new reporting regime actually holds up under real-world pressure.

The Reporting Clock Is Live — And Unforgiving

A total of 3,383 major ICT-related incidents were reported across the EU financial sector in 2025 — an average of 282 a month, or 0.18 incidents per financial entity subject to DORA. Behind that number sits a brutally tight timeline: major ICT incidents must be reported to the relevant national competent authority in three stages — initial notification within four hours of classification, an intermediate report within 72 hours, and a final report within one month. A stricter ceiling applies on top: the initial notification is due within 4 hours after classification as major and no later than 24 hours after detection, with the first intermediate report due at the latest within 72 hours from the initial notification.

For SOC and IR workflows, this means the “major or not” classification call often has to be made before full impact data exists. A practitioner guide captures the core problem well: major incident classification is rarely obvious in the first hour — you may know something went wrong, but not yet know the full customer impact, duration, geographic spread, or whether a critical third party is involved. This exposes a weakness in many existing playbooks: they’re built for forensic completeness, not for defensible decisions made under a four-hour clock.

Third Parties and AI Threats Change the Threat Model

The report also surfaces structural findings with direct IR implications. Approximately 29% of major ICT-related incidents originated from failures attributable to third-party providers, highlighting the extent to which financial entities rely on external providers for delivery of critical services. Meanwhile, external events represented 27% of incidents, and the majority of major incidents originated from operational and technological failures rather than cybersecurity events. For IR teams, this broadens the scope well beyond classic security incidents — availability failures and vendor outages now run through the same classification and escalation path.

More urgent is a warning issued shortly after the report: on 7 July 2026, the European Systemic Risk Board issued a formal warning on systemic cyber risks posed by frontier AI models, upgrading its assessment from “elevated” to “severe” within a few months, driven by concern that frontier models can now identify vulnerabilities, develop working exploits, and execute attacks at a speed that leaves little time to respond. Regulators moved fast in response: the ESAs publicly endorsed the warning, and the ECB separately wrote to the CEOs of significant euro area banks requiring action plans by autumn 2026 on strengthening systems and managing AI-related risk.

What IR Teams Need to Do Now

Regulators themselves admit the practice is still inconsistent: divergent reporting practices across sectors and jurisdictions are still observed, reflecting the early stage of implementation of the new major incident reporting framework. Three concrete actions follow for IR leadership. First, build and rehearse a classification logic that produces a defensible decision within the four-hour window even with incomplete information. Second, evidence capture must run from minute one, since competent authorities ask for timestamps, impact, classification rationale and remediation — retrofitting this after the fact doesn’t work. Third, third-party failure scenarios belong explicitly in tabletop exercises, given that nearly a third of all reported incidents originate there.

Organizations that have treated DORA as a purely legal compliance exercise should read this first annual report as a wake-up call: the reporting clock is real, supervisors are now benchmarking performance — and the next audit won’t be a spot check, it will be a comparison against 3,383 reference cases.

← Back to overview