Second ECB outage validates DORA’s resilience focus

ECB HQ in Frankfurt

The European Central Bank’s (ECB) wholesale payments infrastructure has suffered its second software outage in the space of a week, providing a timely reminder that even Europe’s most critical financial market infrastructure remains vulnerable to software risk.

The ECB confirmed that its T2 payment system experienced a disruption during the early hours of Monday, delaying the settlement of euro and Danish krone payments for around 40 minutes before normal service resumed.

The incident followed a similar disruption just days earlier, with an ECB spokesperson attributing both outages to a recent software update that had introduced an issue which has since been addressed.

While the disruption was resolved before the start of the business day for most participants, the incident is significant because T2 sits at the heart of Europe’s financial system, settling trillions of euros in payments every day. Even relatively short interruptions have the potential to ripple through banks, financial markets and payment providers.

For software quality, testing and operational resilience teams, however, the latest outage represents more than an isolated technical problem. It reinforces a broader message European supervisors have been delivering for months: software risk management is becoming a core regulatory priority.

ECB’s headquarters in Frankfurt, Germany

DORA supervision

The timing of the latest outage is notable because the disruption comes as European supervisors move beyond the implementation phase of the Digital Operational Resilience Act (DORA) and into active supervision.

2026 marks the first year in which regulators are beginning to assess not simply whether financial institutions have documented ICT risk frameworks, but whether they can demonstrate through testing, evidence and operational performance that critical services remain resilient when software, infrastructure or third-party services fail.

The ECB itself has been among the strongest advocates of that shift. Earlier this year, the central bank formally positioned its Threat Intelligence-Based Ethical Red Teaming (TIBER-EU) framework as the supervisory model for DORA’s mandatory threat-led penetration testing.

Rather than relying on isolated penetration tests or technical checklists, TIBER-EU assesses how technology, people, governance and recovery capabilities perform together during realistic cyber attacks.

That represents a significant evolution in supervisory expectations. Increasingly, regulators want evidence that institutions can detect, respond to and recover from incidents affecting critical services, rather than simply demonstrating compliance with security standards.

Significant shift

The latest T2 disruption illustrates why that shift matters. Software updates remain among the highest-risk activities within any financial institution.

Modern release pipelines allow banks to deliver new functionality more rapidly than ever, but accelerated delivery also places greater emphasis on regression testing, production validation, change governance and post-deployment monitoring.

As banks increasingly adopt AI-assisted software development and automation throughout the software delivery lifecycle, ensuring that software changes do not introduce operational risk is becoming even more important.

Frank Elderson

That concern has featured prominently in recent ECB messaging. Speaking at the Goldman Sachs European Financials Conference in Zurich last month, Frank Elderson, Member of the Executive Board of the ECB and Vice-Chair of the ECB Supervisory Board, warned that artificial intelligence is fundamentally changing the cyber threat landscape and compressing the time available for organisations to identify and remediate vulnerabilities.

“The direction of travel is unmistakable: the speed, scale and accessibility of advanced cyber capabilities are increasing, and the time available to defenders is shrinking,” Elderson declared.

He added: “Banks therefore need to prepare more quickly, more effectively and more consistently across the sector.”

“In musical terms, andante may have previously been good enough, but now we need to move to presto.”

Those comments are particularly relevant in light of the latest T2 incident. Elderson argued that DORA “provides a regulatory framework that requires banks to foster a culture of continuous improvement in IT and cyber risk management” and, crucially, “gave supervisors the task of testing whether a financial institution can detect, respond to and recover from sophisticated attacks that mirror real-world threats, thereby providing a more systemic and enforceable framework for resilience.”

The ECB official also warned that “frontier AI models are changing the cyber threat landscape”, lowering barriers for attackers while increasing the speed at which vulnerabilities can be identified and exploited.

That changing risk landscape is reflected in DORA itself. The regulation requires banks and other financial institutions to strengthen ICT risk management, oversee third-party technology providers, report major ICT incidents and conduct increasingly sophisticated resilience testing. For selected firms, that includes mandatory threat-led penetration testing under the TIBER-EU framework.

Incident reporting regime

At the same time, Europe’s supervisors are building an increasingly detailed picture of operational weaknesses through DORA’s new incident reporting regime.

The first annual report on major ICT-related incidents, published by the European Supervisory Authorities earlier this summer, demonstrated how operational failures are becoming an increasingly valuable source of supervisory intelligence.

Rather than viewing incidents purely as compliance events, regulators can now identify recurring weaknesses across software changes, third-party dependencies, recovery processes and operational controls.

That intelligence is likely to influence future supervisory expectations around testing. If incident reporting consistently highlights weaknesses associated with software releases, cloud services or change management, firms may increasingly be expected to demonstrate that those risks are reflected in regression testing, resilience exercises, recovery validation and remediation programmes.

Resilience testing is therefore becoming less about satisfying annual compliance exercises and more about continuously validating that critical business services can withstand real operational failures.

The latest ECB outage is unlikely to alter the direction of regulation. If anything, it reinforces it. Every significant operational incident provides supervisors with another real-world case study of how software failures can affect critical financial infrastructure and another opportunity to refine their expectations around resilience.

For banks, the message is becoming increasingly difficult to ignore. Software risk management is no longer simply an IT discipline.

Under DORA, it is rapidly becoming a board-level regulatory obligation, with software testing, quality engineering and operational resilience teams expected to provide the evidence that critical systems have been tested, challenged and can continue operating when technology inevitably fails.


16 SEPTEMBER IN LONDON

REGISTER TODAY – SIMPLY CLICK HERE


Why not become a QA Financial subscriber?

It’s entirely FREE

* Receive our weekly newsletter every Wednesday * Get priority invitations to our Forum events *

SIGN UP HERE TODAY


REGULATION & COMPLIANCE

Looking for more news on regulations and compliance requirements driving developments in software quality engineering at financial firms? Visit our dedicated Regulation & Compliance page here.


READ MORE


WATCH NOW


QA FINANCIAL PODCASTS

CLICK HERE TO LISTEN TO OUR EXCLUSIVE CONVERSATIONS