top of page
fnlogo.png

EU Supervisory Authorities Highlight Growing Cross-Border ICT Risks in Financial Sector

  • Jun 15
  • 3 min read

The European Supervisory Authorities (ESAs) have published their inaugural annual report on major information and communication technology (ICT)-related incidents affecting the European Union’s financial sector, warning that cross-border digital disruptions are becoming more frequent and that increasingly sophisticated artificial intelligence (AI) technologies could amplify cybersecurity threats across the industry.


EU Supervisory Authorities Highlight Growing Cross-Border ICT Risks in Financial Sector

 

The report, jointly released by the European Banking Authority (EBA), the European Insurance and Occupational Pensions Authority (EIOPA), and the European Securities and Markets Authority (ESMA), was prepared under the reporting framework established by the Digital Operational Resilience Act (DORA).

 

According to the authorities, the findings demonstrate that ICT risks are no longer confined by national borders. Instead, they have become increasingly interconnected due to the financial sector’s growing dependence on shared digital infrastructure and third-party technology providers. The ESAs cautioned that the rapid development of advanced AI-powered tools further reinforces the need for financial institutions to enhance their cybersecurity frameworks and strengthen their operational resilience.

 

DORA requires financial entities operating within the European Union to comply with harmonised rules governing the management, classification, and reporting of major ICT-related incidents. The objective of the framework is to ensure consistent reporting to all relevant supervisory authorities while enabling a faster, more coordinated response to ICT disruptions that affect multiple jurisdictions. Ultimately, the framework is intended to improve the resilience and stability of the EU’s financial system.

 

The report revealed that financial entities across the European Union submitted 3,383 reports of major ICT-related incidents. Approximately one-third of these incidents had cross-border implications, highlighting the increasingly international nature of digital operational risks facing the financial sector.

 

The ESAs noted that this volume of reporting corresponds to roughly 0.18 major ICT-related incidents per financial entity subject to DORA, providing an indication of both the reporting activity and the scale of operational disruptions experienced across the industry.

 

Despite the significant number of cross-border incidents, the authorities found that the direct consequences for customers and financial transactions were generally limited. Most reported incidents stemmed from system failures and external events rather than deliberate cyberattacks.

 

The report stressed that these findings underscore the importance of robust third-party risk management practices, effective oversight of outsourced ICT services, and close collaboration with external service providers during both incident response and recovery processes.


Cyprus Company Formation

 

Cybersecurity-related threats accounted for only around 10 per cent of the major ICT incidents reported. Nevertheless, the ESAs emphasised that financial institutions must continue to maintain the highest cybersecurity standards, particularly as the adoption of increasingly advanced AI-enabled technologies has the potential to introduce new and evolving cyber risks.

 

Overall, the authorities concluded that the findings reflect the increasingly systemic nature of ICT risk within Europe's financial sector. They stated that continued efforts to strengthen operational resilience, enhance supervisory oversight, and improve coordination among financial institutions and regulators will be essential to ensuring the sector is better equipped to prevent, withstand, and recover from future ICT disruptions.

 

The publication of the report fulfils the requirement set out under Article 22(2) of the Digital Operational Resilience Act, which obliges the European Supervisory Authorities to issue an annual overview covering the number of major ICT-related incidents reported, their characteristics, operational and customer impacts, remedial actions implemented, and the costs associated with those incidents.

 

Under DORA, an ICT-related incident is defined as either a single event or a series of interconnected unplanned events that compromise the security of network and information systems, affecting the availability, authenticity, integrity, or confidentiality of data or services provided by a financial entity.

 

The legislation further defines a major ICT-related incident as one that causes a significant adverse impact on the network and information systems supporting a financial entity’s critical or important business functions.

By fLEXI tEAM

Comments


bottom of page