Insights on Crypto Payments, Infrastructure, and Operations

Major ICT-Related Incident

Abbreviation: ICT

Pronunciation: MAY-jer I-C-T ree-LAY-tid IN-sih-dent

Also known as: Major technology incident, DORA major ICT incident, ICT

Definition

A major ICT-related incident is an ICT incident that meets defined materiality criteria because of its high adverse impact on technology systems, critical services, clients, data, geography, duration, or economic activity. Under DORA, the label is a regulatory classification with reporting consequences, not simply an internal synonym for a high-severity ticket. Operationally, teams should apply the current classification criteria, gather quantitative impact data, preserve decision evidence, and escalate to accountable management.

Overview

A major ICT-related incident is an ICT incident that meets defined materiality criteria because of its high adverse impact on technology systems, critical services, clients, data, geography, duration, or economic activity.

Major ICT-Related Incident is closely connected to ICT-Related Incident, Incident Severity, and ICT Response and Recovery Plan. Under DORA, the label is a regulatory classification with reporting consequences, not simply an internal synonym for a high-severity ticket.

Operational implementation should apply the current classification criteria, gather quantitative impact data, preserve decision evidence, escalate to accountable management, coordinate regulatory reports, update submissions as facts change, and complete final reporting.

The principal failure modes include late recognition, inconsistent client counts, missing duration or data-loss evidence, duplicated reports, incomplete third-party information, and confusing internal severity with legal materiality.

Useful measures include classification time, notification timeliness, report completeness, regulator follow-up, affected clients, and recurrence of similar major incidents.

Operationally, teams should apply the current classification criteria, gather quantitative impact data, preserve decision evidence, and escalate to accountable management. Key risks include late recognition, inconsistent client counts, missing duration or data-loss evidence, and duplicated reports.

A production treatment of Major ICT-Related Incident should test the use of of its high adverse impact on technology systems, critical services, clients, data, geography, duration, or economic activity within the relevant asset, decision, or service state. The Major ICT-Related Incident context record for critical services, clients, and data should preserve source data, configuration or policy version, responsible actor, exception, and outcome. Review of Major ICT-Related Incident should determine whether safeguards addressing critical services, clients, and data changed exposure in practice, not merely whether a document or setting existed.

Key Takeaway

A major ICT-related incident is an ICT incident that meets defined materiality criteria because of its high adverse impact on technology systems, critical services, clients, data, geography, duration, or economic activity.

Sources

  1. Regulation (EU) 2022/2554 on Digital Operational Resilience for the Financial Sector — European Union (2026-08-03)
  2. Commission Delegated Regulation (EU) 2024/1772 on ICT Incident Classification — European Union (2026-08-03)
  3. Incident Response Recommendations and Considerations, NIST SP 800-61 Rev. 3 — NIST (2026-08-03)