Major ICT-Related Incident Reporting
Under the EU's Digital Operational Resilience Act (DORA), financial entities must tell their supervisory authority when a serious technology-related incident occurs. An incident counts as 'major' when it has a high adverse impact on the network and information systems that support the entity's important business functions. This is a mandatory reporting duty, separate from any insurance obligation, and does not by itself reduce the likelihood or cost of an incident.
A regulatory notification obligation established under DORA whereby financial entities must detect, classify, manage, and notify ICT-related incidents to the relevant competent authority. A 'major ICT-related incident' is defined as an ICT incident that has a high adverse impact on the network and information systems supporting critical or important functions of the financial entity. DORA Article 17 requires entities to define, establish, and implement an ICT-related incident management process to detect, manage, and notify such incidents; incidents meeting the 'major' classification threshold trigger the reporting duty to the supervisory authority, which may act on the basis of the notification. This is a supervisory reporting and operational-resilience requirement, distinct from insurance coverage triggers, sublimits, or claims-notification conditions under a cyber policy; the specific classification thresholds, timelines, and templates are governed by DORA and its implementing measures rather than by any insurer's policy wording.
Why it matters
Major ICT-Related Incident Reporting is a mandatory supervisory obligation, not a form of protection. Under DORA, financial entities operating in the EU must notify their competent authority when an ICT-related incident is classified as major, meaning it has a high adverse impact on the network and information systems supporting critical or important functions. This duty exists to give supervisory authorities visibility into operational disruptions across the financial sector so they can act on the basis of the notification. It does not reduce the likelihood of an incident occurring, nor does it lessen the resulting loss.
For risk and resilience professionals, the significance lies in the interaction between this regulatory duty and other obligations that arise from the same incident. A single technology event may simultaneously trigger a DORA notification to a supervisory authority, a claims-notification condition under a cyber insurance policy, and potentially other regulatory reporting duties. These are distinct obligations with distinct recipients, thresholds, and timelines. Meeting the DORA reporting threshold does not establish that a loss is covered under a cyber policy, and satisfying an insurer's notification condition does not discharge the supervisory reporting duty.
Because the classification thresholds, timelines, and templates are set by DORA and its implementing measures rather than by any insurer, entities must maintain an internal capability to detect and classify incidents against the regulatory criteria. Failure to report a major incident, or to report it correctly and on time, is a supervisory compliance matter that is generally not remedied by insurance. This distinction, between a regulatory reporting failure and an insurable loss, is where firms most often need clear internal ownership and process.
Who it's relevant to
Inside Major ICT-Related Incident Reporting
Common questions
Answers to the questions practitioners most commonly ask about Major ICT-Related Incident Reporting.
