DORA: The Reported Costs of Major IT Incidents in 2025 Are Questionable

Thanks to DORA, we now have the first public statistics on major IT incidents in the EU. However, the reported costs raise several questions.

“Based on the available information, it seems that major incidents had a very limited monetary impact: half of them did not report any direct or indirect costs (almost 40 %) or indicated to have suffered a negligible monetary impact, with direct and indirect costs amounting to less than EUR 1,000 (around 10 %)”, states the “Joint ESA Report pursuant to Article 22 DORA for the year 2025”1. A footnote explains that employee time spent on resolving the disruptions count as costs, which suggests the data may be flawed.

Since CEOs prioritize security measures based on potential losses for their organizations, I hope better real data will be published in the future.

0.18 major IT incidents were reported per financial institution regulated by DORA. This makes me wonder whether the criteria for a major IT incident need to be increased 2 or whether “near miss” incidents are also counted.

Finally, I wonder whether transparent and real statistics will speak for or against the interests of the financial industry. As an engineer, I need concrete data to diagnose and prioritize problems. However, missing data could also create the impression that no additional investments in IT security are necessary, and this money could be invested in other areas of the organization.

After reading the report, what conclusions do you reach?

essential