
Europe’s first annual report on major ICT-related incidents under the EU’s Digital Operational Resilience Act (DORA) gives banks and financial firms a new reason to treat incident data as a core input into software testing, quality engineering and operational resilience planning.
The European Supervisory Authorities published the first annual overview of major ICT-related incidents in the EU financial sector on June 3, based on DORA’s incident reporting mechanism. The ESAs said the report shows that “ICT risks are increasingly borderless and interconnected.”
That message is directly relevant as DORA has already forced financial firms to formalise how they manage ICT risk, report incidents, oversee third-party providers and test digital operational resilience.
But the first incident report marks a new phase. Regulators now have a growing evidence base showing where real operational failures are occurring across the European financial sector. That evidence is likely to influence supervisory expectations around software testing.
If incident reports reveal recurring weaknesses in outsourcing, software changes, cyber controls, third-party services or recovery processes, firms may increasingly be expected to demonstrate that those risks are reflected in testing programmes, resilience exercises and remediation strategies.
Therefore, resilience testing is becoming less theoretical and increasingly driven by actual incident patterns.
Rather than treating a serious outage or cyber incident as simply a regulatory reporting exercise, DORA increasingly encourages firms to feed operational failures directly back into regression testing, scenario design, failover testing, recovery validation and third-party control testing.
DORA philosophy
That feedback loop sits at the heart of DORA’s wider philosophy. As the regulation settled across Europe’s financial sector following its introduction in 2025, QA and software testing teams quickly emerged as key players in ensuring compliance with the regulation’s expanded scope.
Introduced in January 2025, DORA established uniform standards for ICT risk management, resilience testing and third-party oversight across banks, insurers and other financial institutions.
According to a note by law firm Morrison Foerster, “while financial institutions have previously had to comply with broad EU cybersecurity requirements, DORA raises the bar by introducing even more prescriptive management liability and additional ICT risk management and contracting elements.”
The firm added that this has caused “a downstream effect, with ICT service providers facing contract remediation and confusion regarding their classification under DORA.”
Therefore, resilience validation has consequently shifted from best practice to regulatory expectation.
The regulation requires financial entities to strengthen their ability to withstand, respond to and recover from ICT disruptions, while introducing mandatory digital operational resilience testing and threat-led penetration testing for selected firms.

The Dutch central bank summarises DORA as focusing on ICT risk management, ICT incidents, periodic testing of digital operational resilience, outsourcing risk and cyber threat information sharing.
Supporting those requirements, a suite of Regulatory Technical Standards came into force during 2025.
According to Morrison Foerster, the finalised RTS are “less rigorous” than previously anticipated, although the standards still “specify the conditions and the criteria to be taken into account by financial entities when subcontracting ICT services supporting CIF throughout the lifecycle of contractual arrangements between financial entities and ICT service providers.”
The regulation also “sets out criteria for identifying financial entities required to conduct TLPT, its methodology, scope and process, as well as how it will be supervised.”
The lawyers concluded: “Financial entities and ICT service providers have likely been digesting these RTS. Now, interested parties are watching carefully to see how the enforcement regime takes shape.”
Enforcement chapter
That enforcement phase is now beginning.
As the first full year of supervision unfolds, DORA is moving beyond implementation towards active supervisory scrutiny.
José Manuel de Araluce, Director at Promontory España, IBM Consulting, believes that transition will expose weaknesses many firms have yet to discover.

“For the supervised institutions, especially less mature ones, implementing the new requirements may serve to discover unsuspected issues requiring remediation in their strategies, governing processes, operations or risk management,” he explained.
He noted that 2025 largely served as a transition period for both regulators and industry.
“This marked the first anniversary of DORA’s application. While DORA was applied on day one, 2025 was essentially a transition year for both financial entities and supervisors.”
Now, however, expectations are changing rapidly. “With the ‘training wheels’ now off, 2026 marks the first true test of DORA,” de Araluce said.
That shift is particularly important for QA teams because supervisors are moving away from assessing policies towards assessing operational evidence.
DORA’s supervisory phase increasingly requires organisations to document, test and report digital risks with greater precision, embed resilience into software development lifecycles and demonstrate that third-party dependencies do not undermine operational stability.
As supervisors collect evidence from incident reporting, testing exercises and inspections, software testing functions are becoming an increasingly important source of that evidence.
That trend is reinforced by the European Central Bank’s decision to formally embed its Threat Intelligence-Based Ethical Red Teaming framework, TIBER-EU, into DORA’s threat-led penetration testing regime.
The ECB has adopted TIBER-EU as the operational model for mandatory threat-led penetration testing, further shifting supervisory attention away from isolated penetration testing towards intelligence-led exercises designed to replicate genuine attacks.
“With the ‘training wheels’ now off, 2026 marks the first true test of DORA.”
– José Manuel de Araluce
Unlike conventional penetration testing, TIBER-EU assesses how technology, people, governance and operational processes perform together during realistic cyber attacks.
Blue teams continue normal operations without knowing exercises are under way, allowing supervisors to observe genuine detection and response capabilities while external threat intelligence providers and red teams simulate sophisticated adversaries.
This means resilience testing increasingly extends well beyond application security into end-to-end validation of detection, response, recovery and operational governance.
Findings from those exercises feed directly into remediation programmes, development pipelines, testing strategies and operational controls.
The urgency behind those changes is only increasing as artificial intelligence reshapes cyber risk.

Speaking recently at the Goldman Sachs European Financials Conference in Zurich, Frank Elderson, Member of the Executive Board of the European Central Bank and Vice-Chair of the ECB Supervisory Board, warned that advanced AI models are fundamentally changing the economics of cyber attacks.
“The direction of travel is unmistakable: the speed, scale and accessibility of advanced cyber capabilities are increasing, and the time available to defenders is shrinking,” Elderson said.
“Banks therefore need to prepare more quickly, more effectively and more consistently across the sector. In musical terms, andante may have previously been good enough, but now we need to move to presto,” he declared.
According to Elderson, DORA “provides a regulatory framework that requires banks to foster a culture of continuous improvement in IT and cyber risk management.”
More importantly for testing teams, DORA “gave supervisors the task of testing whether a financial institution can detect, respond to and recover from sophisticated attacks that mirror real-world threats, thereby providing a more systemic and enforceable framework for resilience.”
He warned that “Frontier AI models are changing the cyber threat landscape.”
“They are lowering barriers for attackers, increasing the speed of exploitation and exposing weaknesses that were too often tolerated for too long.”
The ECB official also cautioned that “cyberattacks that previously required significant expertise, time and resources may in future be achieved more quickly, at scale, and by a much broader set of potentially malicious actors.”
That reinforces one of the central messages emerging from the ESAs’ first DORA incident report.
Modern banking infrastructure depends on cloud providers, payment networks, software vendors, fintech partners, data providers and shared digital infrastructure. Failures in one organisation increasingly cascade across multiple firms.
Incident reporting therefore provides regulators with a growing picture of where resilience controls are failing across that interconnected ecosystem. This means testing strategies will need to become increasingly dynamic.
The strongest testing organisations will not simply satisfy annual compliance exercises. They will continuously use incident intelligence, supervisory findings, threat-led penetration testing and AI-driven threat intelligence to refine risk-based testing priorities, strengthen automation coverage, validate recovery capabilities, test third-party dependencies and verify that remediation efforts genuinely reduce operational risk.
DORA is no longer simply asking firms whether they have resilience controls.
It is increasingly asking them to produce evidence that those controls have been tested, challenged and proven under conditions that closely resemble the real operational failures regulators are now collecting across Europe’s financial sector.
16 SEPTEMBER IN LONDON

REGISTER TODAY – SIMPLY CLICK HERE
Why not become a QA Financial subscriber?
It’s entirely FREE
* Receive our weekly newsletter every Wednesday * Get priority invitations to our Forum events *
REGULATION & COMPLIANCE
Looking for more news on regulations and compliance requirements driving developments in software quality engineering at financial firms? Visit our dedicated Regulation & Compliance page here.
READ MORE
- Inside Rabobank: Engineering resilience by design
- Can AI agents finally automate data testing?
- Continuous testing drives DORA compliance
- Why software testing may face a major rethink
- Buy or build? AI rewrites software testing for banks
WATCH NOW


QA FINANCIAL PODCASTS

CLICK HERE TO LISTEN TO OUR EXCLUSIVE CONVERSATIONS



