The ESAs’ first annual report on major ICT-related incidents under DORA covers 3,383 incidents reported across the EU financial sector in 2025, finding that risks are increasingly borderless and interconnected, although the direct impact on clients and transactions was generally limited. System failures and external events were the main drivers, while only 10% of reported incidents related to cybersecurity, prompting the authorities to stress stronger third-party risk management, oversight of outsourced services and resilience against emerging AI-enabled threats…