Skip to content

30 June 2026 | 6 min

DORA Incident Reporting: Why Third Parties Are Becoming a Central Resilience Risk

DORA has moved from regulation into practice. The first assessment by the European supervisory authorities of major ICT-related incidents shows where operational resilience in the financial sector is particularly challenged: complex IT environments, cross-border dependencies and external service providers.

For GRC leaders, the message is clear. DORA compliance does not end with policies, control lists or reporting templates. What matters is whether organisations can actually manage their critical ICT service providers, outsourcing relationships, incident processes and business continuity measures. Third parties are therefore becoming a core digital resilience risk rather than just a procurement topic.

The first DORA assessment identifies 3,383 major ICT-related incidents in the EU financial sector for 2025. Around one third had cross-border effects. Particularly relevant for GRC teams is the high share of external causes: around 29 percent of major ICT incidents were attributed to third parties.

This shows that financial institutions need to manage ICT service providers, cloud providers, software partners and other critical vendors not only contractually, but also operationally and on a risk-based basis. Vendor Risk Management, Incident Management, BCM and the DORA Register of Information therefore need to be closely connected.

DORA Makes ICT Risks Measurable and Auditable

With the Digital Operational Resilience Act, the EU has created a common framework for digital operational resilience in the financial sector. Affected organisations need to demonstrate that they can identify, assess, monitor and control ICT risks.

The first incident data shows why this approach is necessary. ICT incidents are not just technical disruptions. They can affect payment processes, customer services, transactions, data availability, reporting obligations and critical business processes.

The more digital and interconnected financial institutions become, the more important robust risk management becomes. For GRC leaders, this means DORA should be treated as a management system rather than a one-time compliance project.

Third Parties Are Becoming a Central Risk Factor

One of the most important findings of the first assessment is the role of external providers. If almost one third of major ICT incidents can be traced back to third parties, a simple vendor list is no longer enough.

Financial institutions depend on cloud providers, SaaS vendors, payment service providers, data centres, IT outsourcing partners, managed service providers and data platforms. In many cases, additional dependencies exist through subcontractors or other technical components.

This makes digital supply chains more complex and harder to manage transparently. A single critical provider can affect multiple systems, processes and business areas at the same time.

Why Vendor Risk Management Is Becoming More Important Under DORA

DORA requires ICT third-party risks to be managed systematically. Organisations therefore need to understand which providers support critical or important functions, which risks are associated with them and which controls are in place.

This is not only about contracts or one-time assessments. Subcontractors, outage risks, reporting obligations, exit strategies, recurring reviews and the tracking of findings also need to be considered.

The real challenge is ongoing maintenance. Vendor information must remain connected with risks, controls, incidents, audits and business processes. Only then does an organisation gain a realistic view of its actual dependencies.

Incident Management Must Include Third Parties

Many incident management processes are well defined internally but do not sufficiently address external dependencies. Under DORA, this creates a significant risk.

If a critical ICT provider fails, an organisation needs to immediately understand which business processes and customer services are affected, which regulatory or contractual reporting obligations may apply and which workarounds or recovery plans are available.

Contacts, escalation paths and internal responsibilities also need to be defined in advance. DORA therefore increases the pressure to keep relevant information continuously up to date and auditable instead of searching for it during a crisis.

BCM and DORA Belong Together

Business Continuity Management is a central component of digital resilience. Operational disruptions often do not remain isolated but spread through systems, providers and cross-border dependencies.

A robust BCM approach under DORA should therefore also consider external dependencies, recovery times, alternative providers, escalation paths and communication processes.

The connection between Business Impact Analysis, ICT risks and Vendor Risk Management is particularly important. Only when organisations know which providers support which critical functions can realistic contingency and recovery plans be developed.

The Register of Information as a Management Tool

The DORA Register of Information is often seen primarily as a documentation requirement. Used correctly, however, it can become a central management tool for ICT third-party risks.

It creates transparency around service providers, contracts, services, critical functions, subcontractors, locations, risk assessments and responsibilities.

Its real value emerges when the register is not maintained in isolation. If it is linked with risks, controls, remediation actions, incidents and BCM scenarios, regulatory documentation becomes a practical GRC tool.

What Financial Institutions Should Do Now

The first DORA incident data shows that third-party management needs to be more closely integrated into operational resilience.

Organisations should first identify their critical ICT service providers and link them to critical or important functions. Vendor Risk Management, Incident Management and BCM should then be more closely connected.

Structured documentation of contractual and reporting obligations is equally important, as is the central management of risks, controls, actions and evidence.

Organisations that continue to manage this information across isolated Excel files, email inboxes and document folders are likely to reach their limits quickly during audits, incidents or regulatory requests.

Conclusion

The first DORA assessment makes one thing clear: ICT risks are interconnected, cross-border and heavily influenced by third parties.

For financial institutions, it is therefore not enough to document individual service providers or formally describe incident processes. What matters is the connection between Vendor Risk Management, Incident Management, BCM, the Register of Information, controls and evidence.

Organisations that manage these elements centrally can reduce regulatory complexity while improving their actual operational resilience.

Third parties are therefore not just a compliance topic. They are a central factor in digital operational resilience.

FAQ

What does the first DORA assessment show?

The assessment identifies 3,383 major ICT-related incidents in the EU financial sector for 2025. Around one third had cross-border effects, while approximately 29 percent were attributed to third parties.

Why are third parties so important under DORA?

Because many critical financial processes depend on external ICT service providers. Disruptions at cloud providers, software vendors or outsourcing partners can therefore directly affect critical business processes.

What does DORA mean for Vendor Risk Management?

Organisations need to classify ICT providers based on risk, understand critical dependencies, assess risks and continuously monitor controls and remediation actions. Subcontractors and exit strategies are also becoming more important.

What role does BCM play under DORA?

BCM needs to address external ICT dependencies more systematically. Business Impact Analysis, recovery planning and Vendor Risk Management should be connected so organisations can respond realistically to service disruptions.

What is the DORA Register of Information?

The register documents relevant ICT third-party relationships, contracts, services and dependencies. When linked with risks, controls, incidents and BCM processes, it can become an operational management tool rather than just a regulatory requirement.

What should financial institutions prioritise now?

They should focus on identifying critical ICT service providers, linking them to critical functions and integrating Vendor Risk Management, Incident Management and BCM.

Related posts