ICT-Related Incident
An ICT-related incident is an event affecting an organization's information and communication technology systems, such as the networks and systems supporting its services. Under the EU's Digital Operational Resilience Act (DORA), financial entities must have a process to detect, manage, and notify such incidents. An incident may be classified as 'major' when it has a high adverse impact on the systems that support critical services.
Within the framework of the EU Digital Operational Resilience Act (DORA, Regulation (EU) 2022/2554), an ICT-related incident is an event or series of events affecting the network and information systems of a financial entity. Article 17 of DORA requires financial entities to define, establish, and implement an ICT-related incident management process to detect, manage, and notify such incidents. A 'major' ICT-related incident is one determined to have a high adverse impact on the network and information systems supporting critical services; the source evidence indicates that classification turns on adverse impact to the criticality of services, though practitioners should verify the precise classification criteria against the binding DORA text rather than rely on any single secondary summary. The specific article numbers governing classification criteria and reporting obligations should be confirmed directly against the primary Regulation, as secondary sources in this evidence set differ on citation. Applicability is limited to financial entities within DORA's scope and does not extend to sectors or jurisdictions outside the EU regime; legal interpretation of scope and thresholds should be confirmed with qualified counsel.
Why it matters
For financial entities operating within the EU, the ICT-related incident concept sits at the heart of the Digital Operational Resilience Act's supervisory regime. DORA reflects a policy judgment that disruptions to the technology underpinning financial services, whether from cyberattacks, system failures, or operational errors, can threaten not only individual firms but the stability of the wider financial system. Treating such events as a defined, managed category rather than routine IT problems is what allows firms and supervisors to respond in a coordinated way and to build an evidence base about where operational fragility concentrates.
The distinction between an ordinary ICT-related incident and a 'major' one carries particular weight, because classification typically triggers escalation and notification obligations. Under DORA, a major incident is one determined to have a high adverse impact on the network and information systems that support critical services. That threshold matters practically: it determines when a firm must move from internal handling to formal reporting, and it shapes the aggregate picture that the European Supervisory Authorities compile from firm submissions. Getting classification wrong, either over- or under-reporting, can expose a firm to supervisory criticism.
Because the precise criteria, thresholds, and article references are set out in the binding Regulation and its accompanying technical standards, firms should treat any secondary summary, including this one, as a starting point rather than a substitute for the primary text. Applicability is confined to entities within DORA's scope in the EU regime; scope, thresholds, and their legal interpretation should be confirmed with qualified counsel.
Who it's relevant to
Inside ICT-Related Incident
Common questions
Answers to the questions practitioners most commonly ask about ICT-Related Incident.

