On June 3, 2026, the European Supervisory Authorities (the EBA, EIOPA and ESMA, collectively, the ESAs) published their inaugural joint report on major ICT-related incidents under Article 22 of the Digital Operational Resilience Act (DORA). The report covers major incidents reported across the EU financial sector in 2025 by financial entities subject to DORA, including credit institutions, payment institutions, insurance undertakings, investment firms and other regulated entities. The report provides an anonymized and aggregated overview of 3,383 major incidents, offering the first comprehensive, cross-sectoral picture of how the industry is faring under DORA’s new operational resilience framework. For financial entities and their ICT third-party service providers (ICT Providers), the report carries several important messages about how the ESAs are approaching operational resilience—and where they expect continued improvement.