ESMA Publishes First Report on DORA Implementation, Emphasizing Financial ICT Resilience The European Securities and Markets Authority (ESMA) announced on June 3, 2026, the publication of its first report on major information and communication technology (ICT)-related incidents under the European Union's (EU) Digital Operational Resilience Act (DORA). DORA is a comprehensive regulatory framework introduced to strengthen the digital operational resilience of the EU financial sector and protect the financial system from cyberattacks and ICT disruptions. This report analyzes major ICT incident cases reported by financial entities since DORA came into effect, delving into the causes, impacts, and response methods of these incidents. Through the report, ESMA emphasizes the need for financial entities to comply with DORA regulations and further strengthen their ICT resilience.

Why It Matters DORA regulation signifies a proactive response by European authorities to the increasing cybersecurity threats as the digitalization of the EU financial market accelerates. Financial services are highly interconnected, harboring the potential risk that an ICT incident at a single financial entity could propagate throughout the entire financial system. ESMA's first report illustrates these risks through concrete examples, highlighting the importance for financial entities to further invest in and collaborate on securing digital operational resilience. This will serve as a reminder of the importance of DORA compliance and strengthening ICT resilience not only for financial entities within the EU but also for global financial institutions and technology service providers operating in the EU market or transacting with EU financial entities.

Impact on the Korean Market ESMA's DORA report publication could have an indirect impact on domestic financial entities and financial IT service companies. The Korean Financial Services Commission is also striving to enhance digital security, including establishing AI security threat response guidelines for financial entities, and the EU's DORA regulation could serve as a reference for the policy direction of domestic financial authorities. If domestic financial entities operate in the EU market or have close relationships with EU financial entities, strengthening their ICT systems and security frameworks to comply with DORA regulations will be essential. This could provide new business opportunities for domestic information security and financial IT solution companies. Furthermore, as the importance of ICT resilience becomes more prominent in the global financial market, domestic financial entities are also expected to invest more in strengthening their own digital operational resilience.

Future Scenarios ESMA is expected to continuously issue reports and update guidelines for the effective implementation of DORA regulations. EU financial entities will address the vulnerabilities identified in the report and expand investments to strengthen ICT resilience. This will stimulate the growth of related technology markets, including cybersecurity solutions, cloud services, and data recovery and backup systems. Domestic companies should closely monitor EU DORA regulatory trends and develop ICT resilience and security solutions that align with global standards to explore opportunities for overseas market expansion. In the long term, the overall digital operational resilience level of the financial industry is expected to improve, and international cooperation on cybersecurity threats will further strengthen.