Glossary · DORA
Major ICT-Related Incident
An ICT incident meeting DORA's classification thresholds, triggering mandatory reporting to the financial supervisor.
Explained in depth: DORA overview
DORA requires financial entities to classify ICT-related incidents against criteria set out in regulatory technical standards: clients and counterparts affected, duration and service downtime, geographical spread, data losses, criticality of services affected, and economic impact. Incidents crossing the thresholds are "major" and must be reported to the competent authority in three stages: an initial notification, an intermediate report, and a final report, within deadlines specified in the technical standards. This is DORA's counterpart to NIS2's significant incident, but with its own thresholds, its own recipient (the financial supervisor, e.g. Finansinspektionen in Sweden, rather than the CSIRT), and its own templates. Significant cyber threats can additionally be reported voluntarily.
Why it matters
Financial entities need an incident classification procedure tuned to DORA's specific criteria, not a generic one. Groups subject to several regimes (DORA, GDPR, PSD2) should map which incident goes to which authority on which clock before the first real incident forces the question.
