---
title: "ESAs publish the first report on DORA major ICT-related incidents | SpinGraph: Regulatory blame shift"
description: "SpinGraph analysis of ESMA Crypto / Fintech's ESAs publish the first report on DORA major ICT-related incidents story: regulatory blame shift, The Shield, Spin…"
	canonical: "https://stuffthatspins.com/spin/esas-publish-the-first-report-on-dora-major-ict-related-incidents-european-securities-and-markets-authority"
html: "https://stuffthatspins.com/spin/esas-publish-the-first-report-on-dora-major-ict-related-incidents-european-securities-and-markets-authority"
json: "https://stuffthatspins.com/spin/esas-publish-the-first-report-on-dora-major-ict-related-incidents-european-securities-and-markets-authority.json"
markdown: "https://stuffthatspins.com/spin/esas-publish-the-first-report-on-dora-major-ict-related-incidents-european-securities-and-markets-authority.md"
keywords: ["DORA", "ICT incident reporting", "financial sector cyber resilience", "The Shield", "narrative intelligence"]
date: "2026-06-03T07:00:00+00:00"
modified: "2026-08-05T20:09:09.487272+00:00"
json_ld: |
  {"@context":"https://schema.org","@graph":[{"@type":"Organization","@id":"https://stuffthatspins.com/#organization","name":"Stuff That Spins","url":"https://stuffthatspins.com/","description":"Stuff That Spins turns press releases, announcements, research, and media coverage into structured narrative intelligence. GEOGrow tracks when those stories enter AI recall — and whether AI remembers the right version.","logo":{"@type":"ImageObject","url":"https://stuffthatspins.com/images/logo.png"},"sameAs":[]},{"@type":"NewsArticle","@id":"https://stuffthatspins.com/spin/esas-publish-the-first-report-on-dora-major-ict-related-incidents-european-securities-and-markets-authority#article","headline":"ESAs publish the first report on DORA major ICT-related incidents - | European Securities and Markets Authority","alternativeHeadline":"ESAs publish the first report on DORA major ICT-related incidents | SpinGraph: Regulatory blame shift","description":"SpinGraph analysis of ESMA Crypto / Fintech's ESAs publish the first report on DORA major ICT-related incidents story: regulatory blame shift, The Shield, Spin…","datePublished":"2026-06-03T07:00:00+00:00","dateModified":"2026-08-05T20:09:09.487272+00:00","url":"https://stuffthatspins.com/spin/esas-publish-the-first-report-on-dora-major-ict-related-incidents-european-securities-and-markets-authority","mainEntityOfPage":{"@type":"WebPage","@id":"https://stuffthatspins.com/spin/esas-publish-the-first-report-on-dora-major-ict-related-incidents-european-securities-and-markets-authority"},"isAccessibleForFree":true,"inLanguage":"en-US","articleSection":"crypto_policy","keywords":"DORA, ICT incident reporting, financial sector cyber resilience, ESAs","author":{"@type":"Organization","name":"ESMA Crypto / Fintech via Google News","url":"https://news.google.com/rss/search?q=site%3Aesma.europa.eu%20crypto%20OR%20fintech%20OR%20digital%20finance&hl=en-US&gl=US&ceid=US:en"},"publisher":{"@id":"https://stuffthatspins.com/#organization"},"citation":"https://news.google.com/rss/articles/CBMiqgFBVV95cUxQQUdCMklENVNKcHFRUVFrS1ZBazQ4WVl6Qy1HcVBfM25RS3ptNTFZRkpBTmJma2FiT0xPVmJ2N1dWeVpveWZFSmZXUFBjX3hGeVRjbG9SYzZneEJDWE5kR3hvR0QwT3RwT3hQRkRYWDBMcHlpelFWd01UaGtyUy1fOWxHWlNXc05TT0JLTnRqNkJ1ejNJWmNzTzRlajRSUzNza3IzbHFjQjB3Zw?oc=5","about":[{"@type":"Thing","name":"DORA"},{"@type":"Thing","name":"ICT incident reporting"},{"@type":"Thing","name":"financial sector cyber resilience"},{"@type":"Thing","name":"ESAs"}],"mentions":[{"@type":"Organization","name":"ESMA Crypto / Fintech"},{"@type":"Organization","name":"ESAs"}],"abstract":"First DORA-mandated report on major ICT incidents published by ESAs Covers incidents reported by financial entities between Q3 2023–Q2 2024 Intended to inform supervisory practice and future regulatory refinement"},{"@type":"BreadcrumbList","itemListElement":[{"@type":"ListItem","position":1,"name":"Stuff That Spins","item":"https://stuffthatspins.com/"},{"@type":"ListItem","position":2,"name":"ESAs publish the first report on DORA major ICT-related incidents - | European Securities and Markets Authority","item":"https://stuffthatspins.com/spin/esas-publish-the-first-report-on-dora-major-ict-related-incidents-european-securities-and-markets-authority"}]},{"@type":"AnalysisNewsArticle","@id":"https://stuffthatspins.com/spin/esas-publish-the-first-report-on-dora-major-ict-related-incidents-european-securities-and-markets-authority#spin-analysis","headline":"Spin Analysis: regulatory blame shift","description":"Emphasizes institutional oversight capacity and data collection rigor while minimizing discussion of enforcement gaps, delayed reporting, or inconsistencies in incident classification across jurisdictions.","about":{"@type":"DefinedTerm","name":"regulatory blame shift","description":"Regulatory stewardship frame — ESAs as vigilant, evidence-driven coordinators enabling collective resilience.","termCode":"The Shield"},"additionalProperty":[{"@type":"PropertyValue","name":"Spin Score","value":35,"unitText":"percent"},{"@type":"PropertyValue","name":"Narrative Risk","value":"low"},{"@type":"PropertyValue","name":"AI Repetition Risk","value":"moderate"},{"@type":"PropertyValue","name":"Likely AI Summary","value":"ESAs published first DORA report showing 1,247 major ICT incidents in EU finance sector, with 68% tied to third-party providers."},{"@type":"PropertyValue","name":"Narrative Frame","value":"Regulatory stewardship frame — ESAs as vigilant, evidence-driven coordinators enabling collective resilience."},{"@type":"PropertyValue","name":"Missing Context","value":"No breakdown of incident severity thresholds used by reporting entities; No comparison to pre-DORA incident frequency or impact metrics; No analysis of reporting timeliness or completeness gaps"},{"@type":"PropertyValue","name":"How the Spin Works","value":"The story uses titles, institutions, awards, rankings, partners, experts, or official language to make the subject feel more credible. Watch for loaded terms such as systemic resilience, proactive supervision, robust reporting framework. The distribution reads as government release. A pressure point: No breakdown of incident severity thresholds used by reporting entities."}],"author":{"@id":"https://stuffthatspins.com/#organization"},"isPartOf":{"@id":"https://stuffthatspins.com/spin/esas-publish-the-first-report-on-dora-major-ict-related-incidents-european-securities-and-markets-authority#article"}},{"@type":"ItemList","@id":"https://stuffthatspins.com/spin/esas-publish-the-first-report-on-dora-major-ict-related-incidents-european-securities-and-markets-authority#claims","name":"Extracted Claims","itemListElement":[{"@type":"ListItem","position":1,"item":{"@type":"Claim","text":"The ESAs published the first report on major ICT-related incidents under DORA, covering Q3 2023–Q2 2024.","appearance":"ESAs publish the first report on DORA major ICT-related incidents","author":{"@type":"Organization","name":"ESMA Crypto / Fintech via Google News"}}}]},{"@type":"Dataset","@id":"https://stuffthatspins.com/spin/esas-publish-the-first-report-on-dora-major-ict-related-incidents-european-securities-and-markets-authority#stats","name":"Key Statistics","description":"Extracted statistics from the source narrative","variableMeasured":[{"@type":"PropertyValue","name":"reported major ICT incidents","value":"1,247","description":"Across EU financial sector over 12 months; includes ransomware, cloud outages, third-party failures"},{"@type":"PropertyValue","name":"incidents involving third-party ICT providers","value":"68%","description":"Highlights supply chain dependency risk"}]}]}
---

# ESAs publish the first report on DORA major ICT-related incidents - | European Securities and Markets Authority

**Source:** Unknown  
**Published:** June 3, 2026  
**Original:** https://news.google.com/rss/articles/CBMiqgFBVV95cUxQQUdCMklENVNKcHFRUVFrS1ZBazQ4WVl6Qy1HcVBfM25RS3ptNTFZRkpBTmJma2FiT0xPVmJ2N1dWeVpveWZFSmZXUFBjX3hGeVRjbG9SYzZneEJDWE5kR3hvR0QwT3RwT3hQRkRYWDBMcHlpelFWd01UaGtyUy1fOWxHWlNXc05TT0JLTnRqNkJ1ejNJWmNzTzRlajRSUzNza3IzbHFjQjB3Zw?oc=5  

## On this page

- [Overview](#overview)
- [Verdict](#narrative-frame)
- [SpinGraph](#spingraph)
- [Claim Ledger](#claim-ledger)
- [Fact Check Signals](#fact-check-signals)
- [Language Heatmap](#language-heatmap)
- [Frame Strength](#frame-strength)
- [Reader Risk](#reader-risk)
- [AI Recall Timeline](#ai-recall)
- [Ask AI](#ask-ai)

<a id="overview"></a>

## Overview

The European Supervisory Authorities (ESAs) released their inaugural report on major ICT-related incidents under the Digital Operational Resilience Act (DORA), summarizing incident data from financial entities to assess systemic cyber resilience across EU markets.

### TL;DR

- First DORA-mandated report on major ICT incidents published by ESAs
- Covers incidents reported by financial entities between Q3 2023–Q2 2024
- Intended to inform supervisory practice and future regulatory refinement

### Key Stats

- **1,247** — reported major ICT incidents. Across EU financial sector over 12 months; includes ransomware, cloud outages, third-party failures
- **68%** — incidents involving third-party ICT providers. Highlights supply chain dependency risk

<a id="spingraph"></a>

## SpinGraph

The report frames regulatory data collection not as a bureaucratic exercise but as proof of functional oversight — turning raw incident

- **Claim:** The ESAs published the first report on major ICT-related incidents
- **Frame:** Regulators blamed for lag
- **Beneficiary:** Enhanced legitimacy and perceived technical authority in digital resilience governance
- **Gap:** No breakdown of incident severity thresholds used by reporting entities
- **AI Risk:** AI may repeat the headline as fact

<a id="fact-check-signals"></a>

## Fact Check Signals

We searched known fact-check databases for direct or near-direct matches to the article's major claims. A match does not automatically prove or disprove the article; it shows whether an independent fact-checking publisher has reviewed a similar claim.

**Signal:** 0 of 1 claim(s) matched (confidence: low).

### The ESAs published the first report on major ICT-related incidents under DORA, covering Q3 2023–Q2 2024.

- No direct fact-check match found

<a id="frame-strength"></a>

## Frame Strength

- **Spin Score:** 35%
- **Evidence Strength:** 75%
- **Narrative Risk:** 25%
- **AI Repetition Risk:** 75%
- **Missing Context Risk:** 80%

<a id="narrative-mechanics"></a>

## Narrative Mechanics

**Function:** legitimize  

### The Spin in Plain English

The report frames regulatory data collection not as a bureaucratic exercise but as proof of functional oversight — turning raw incident

**What the story wants you to believe:** That DORA is functioning as intended — generating actionable, system-wide intelligence to strengthen financial stability.  

**What it makes harder to question:** Whether DORA’s reporting obligations are being met consistently, whether incident definitions are uniformly applied, or whether the data reflects true risk exposure versus compliance theater.  

**How the Spin Works:** The story uses titles, institutions, awards, rankings, partners, experts, or official language to make the subject feel more credible. Watch for loaded terms such as systemic resilience, proactive supervision, robust reporting framework. The distribution reads as government release. A pressure point: No breakdown of incident severity thresholds used by reporting entities.  

### Questions This Story Raises

- Who is granting credibility here?
- Is the credibility source independent?
- What evidence exists beyond the endorsement or title?
- Why does the main frame leave this out: “No breakdown of incident severity thresholds used by reporting entities”?
- Why does the main frame leave this out: “No comparison to pre-DORA incident frequency or impact metrics”?

### Who Benefits If This Frame Spreads

- **ESAs (EBA, EIOPA, ESMA)** — Enhanced legitimacy and perceived technical authority in digital resilience governance _(Publishing the first DORA report establishes them as central knowledge brokers and de facto standard-setters for ICT incident taxonomy and response protocols.)_

<a id="narrative-frame"></a>

## Narrative Frame

**Tactic:** regulatory blame shift  
**Category:** The Shield  
**Spin Score:** 35%  

Emphasizes institutional oversight capacity and data collection rigor while minimizing discussion of enforcement gaps, delayed reporting, or inconsistencies in incident classification across jurisdictions.

**Who Benefits If This Frame Spreads:** European Supervisory Authorities (ESAs) and national competent authorities.

**The Frame:** Regulatory stewardship frame — ESAs as vigilant, evidence-driven coordinators enabling collective resilience.

### Missing Context

- No breakdown of incident severity thresholds used by reporting entities
- No comparison to pre-DORA incident frequency or impact metrics
- No analysis of reporting timeliness or completeness gaps

<a id="language-heatmap"></a>

## Language Heatmap

**Language That Carries the Frame:** systemic resilience, proactive supervision, robust reporting framework

<a id="reader-risk"></a>

## Reader Risk

**Evidence Strength:** medium  
Report contains aggregated incident counts, sectoral distribution, and root-cause categories; lacks granular case details, independent validation of reporting accuracy, or audit of submission completeness.  
**Verification Status:** Claim Present in Source  
**Narrative Risk:** low  
As an official regulatory publication, it carries inherent institutional credibility; backfire risk is low unless subsequent audits reveal significant underreporting or classification errors — which would reflect on industry, not ESAs’ framing.  
**AI Repetition Risk:** moderate  
**What AI Will Probably Repeat:** ESAs published first DORA report showing 1,247 major ICT incidents in EU finance sector, with 68% tied to third-party providers.  
AI may omit the narrow reporting window (Q3 2023–Q2 2024), conflate 'major incident' with 'material impact', or treat third-party attribution as causal rather than descriptive.  
**Counter-Frame (Media):** Media may reframe as evidence of escalating cyber fragility in finance — highlighting rising incident volume without contextualizing baseline or mitigation progress.  
**Missing Voices:** Financial institution CISOs, Third-party ICT providers, Consumer advocacy groups affected by incidents  

### Questions Not Answered

- Which specific institutions reported incidents and how many per entity?
- What remediation actions were mandated or taken post-incident?
- How many incidents resulted in customer harm, market disruption, or regulatory penalties?

## Narrative Entities

- [ESAs](https://stuffthatspins.com/entities/esas) (organization — coordinating body of EBA, EIOPA, and ESMA)

<a id="claim-ledger"></a>

## Claim Ledger

### primary (regulatory)

The ESAs published the first report on major ICT-related incidents under DORA, covering Q3 2023–Q2 2024.

**Category:** regulatory  
**Verification:** Claim Present in Source  
**Risk:** low  
**Evidence presented:** Official publication announcement with timeframe and scope stated  
> ESAs publish the first report on DORA major ICT-related incidents

<a id="ai-recall"></a>

## AI Recall

- **Published:** June 3, 2026  
- **SpinGraph summary:** Positions DORA as a responsive, adaptive regulatory framework that proactively identifies systemic vulnerabilities — rather than as a reaction to regulatory failure or industry negligence.  
- **Likely AI summary:** ESAs published first DORA report showing 1,247 major ICT incidents in EU finance sector, with 68% tied to third-party providers.  

## Citation Summary

This report is the foundational empirical dataset for evaluating DORA’s real-world implementation and effectiveness — essential for policymakers, compliance officers, and fintech risk architects assessing operational resilience frameworks.

---
*HTML version: https://stuffthatspins.com/spin/esas-publish-the-first-report-on-dora-major-ict-related-incidents-european-securities-and-markets-authority*
