Major ICT-Related Incident
Under the EU's Digital Operational Resilience Act (DORA), a major ICT-related incident is a technology-related disruption that seriously affects the systems supporting a financial entity's critical or important functions. When an incident meets this threshold, the financial entity is required to report it to its supervisory authority. It is a specific regulatory classification, not a general term for any IT problem.
Within the DORA framework, a major ICT-related incident is an ICT-related incident that has a high adverse impact on the network and information systems supporting critical or important functions of a financial entity. The classification as 'major' depends on the incident meeting defined thresholds, the detailed classification criteria and materiality thresholds are established separately in the framework rather than within a single provision, and triggers mandatory notification to the relevant competent authority. Financial entities are required to define, establish, and implement an ICT-related incident management process to detect, manage, and notify such incidents. This term applies specifically to financial entities within the EU regulatory scope under DORA; it is distinct from a general operational or security incident and from a 'significant cyber threat', which is a separate reportable category. Note that this definition reflects the DORA regime and does not necessarily correspond to incident classifications used in other jurisdictions or non-financial sectors.
Why it matters
The classification of an ICT-related incident as "major" is the trigger that converts an internal operational event into a regulatory reporting obligation. Under DORA, financial entities cannot treat every technology disruption the same way; they must assess whether an incident has a high adverse impact on the network and information systems supporting critical or important functions. Getting this classification right matters because it determines whether, when, and to what level of detail an entity must notify its competent authority, and misjudging the threshold can expose an entity to both under-reporting and unnecessary over-reporting.
Who it's relevant to
Inside Major ICT-Related Incident
Common questions
Answers to the questions practitioners most commonly ask about Major ICT-Related Incident.
