Skip to main content
Glossary termPublished inDORA

ICT-related incident

What does "ICT-related incident" mean under DORA?

A single event or series of linked unplanned events that compromises the security of network and information systems, having an adverse impact on system availability, authenticity, integrity, or confidentiality, or on financial operations.

Defined in / by

Last updated: 22 August 2026.

Regulations

  • Digital Operational Resilience Act (DORA)

    DORA is Regulation (EU) 2022/2554. It has applied since 17 January 2025 to 20 categories of licensed financial entity, from banks to crypto-asset service providers. It requires an ICT risk management framework, major incident reporting within 4 hours of classification, an annual register of ICT contracts, and threat-led penetration testing every three years.

    Next
    Next register of information cycle, reference date expected 31 December 2026

    Checked