The financial sector’s systems failures

New EU reporting finds that industry faced thousands of security incidents in 2025

cybersecurity

European financial firms faced thousands of technology-related security incidents last year, most of them driven by systems failures, according to a report from the sector’s regulators.

On Wednesday, the European Supervisory Authorities — including securities, banking, insurance and pension regulators — published the first annual review of major tech-related incidents, which were required to be reported to regulators under new legislation that took effect last year, the Digital Operational Resilience Act (DORA). 

Among other things, the regulators’ analysis of the industry’s reporting shows that these technology risks “are increasingly borderless and interconnected.”

The report indicated that there were 3,383 major incidents reported by financial firms during the year, and that one third of those incidents “had a cross-border impact, underscoring the growing interconnectedness through shared infrastructures and services.” 

Under the legislation, major tech incidents refer to incidents that have “a high adverse impact on the network and information systems that support critical or important functions of a financial entity.”

The main drivers of these incidents were systems failures and other “external events,” the report said, “highlighting the need for robust third-party risk management, effective oversight of outsourced services and close coordination with service providers during incident response and remediation.”

Only 10% of the reported incidents involved cyber breaches, the data showed, which the regulators said “seems to suggest that existing safeguards and detection mechanisms were generally effective in limiting the occurrence of such incidents.” 

Even so, they warned that “the recent evolution of highly capable AI-driven tools should encourage financial entities to strengthen cybersecurity measures to maintain their resilience.”

As for the prevalence of major tech incidents overall, the report said this shouldn’t necessarily be seen as a weaknesses for the financial industry.

“… the increased digitalization, complexity and interconnection of the financial sector make operational incidents to some extent unavoidable,” the report said.

At the same time, most of these incidents had “limited” impacts on clients, transactions and firms’ counterparties, it said.

And, the regulators suggested that the limited fallout for clients indicates that the industry’s efforts to detect and remediate these kinds of incidents “were often successful in limiting operational harm and spillover effects.”

Indeed, the report said the results of the first year of industry reporting “illustrate the growing systemic dimension of [information and communication technology] risk as well as the importance of resilience and supervision in strengthening the financial sector’s ability to prevent, absorb and recover from future incidents.”