A year and a half after the European Dora Regulation on digital operational resilience came into force, the Luxembourg financial centre now has its first set of figures. In response to a parliamentary question from the MP Sven Clement (Piraten), the Minister for Finance,
Gilles Roth (CSV), reported on Monday 6 July that the CSSF had received 326 notifications of major incidents relating to information and communication technologies (ICT) between 17 January 2025 and 8 June 2026. At the European level, EU supervisory authorities had reported, in early June: 3,383 major ICT incidents across the entire financial sector by 2025 as part of the Dora system.
Credit institutions are by far the most affected, accounting for 40% of notifications. They are followed by investment fund managers (19%) and specialised financial service providers (10%). The remaining notifications came mainly from investment firms, payment institutions, support PSFs and electronic money institutions. Meanwhile, the CSSF received only one voluntary notification of a significant cyber threat.
The incidents recorded relate primarily to failures by third-party service providers (29.5%), followed by technical failures (26.3%), process issues (21.1%), human error (10.69%) and malicious acts (12.4%). According to the minister, the rise in the number of notifications is mainly due to the expansion of the scope covered by Dora and greater awareness amongst financial sector stakeholders, rather than a surge in cyberattacks.
Twenty officers responsible for “off-site” surveillance
The government considers that the new requirements are generally being met. The statutory notification deadlines are being met “in the vast majority of cases”, and the final report is submitted, on average, 26 days after the initial notification. Preparations by organisations are also progressing. Whilst only 54% of the entities concerned had created the mandatory “IT Incident Notifier” role on the eDesk platform in January 2025, this figure now stands at 85%.
Another finding: to date, no administrative sanctions have been imposed for failure to report, late reporting or inadequate reporting of a major incident. The CSSF states that it has not identified any cases where an incident should have been reported but was not. However, checks on ICT risk management are continuing as part of its supervisory duties and on-site inspections.
The response also provides several indicators regarding the operational implementation of Dora: 387 of the 389 entities required to submit their information registers did so on time, and 357 of these registers have already been accepted by the European supervisory authorities. Furthermore, a quarter of the major ICT incidents reported involve a third-party IT service provider, an issue that has become a strategic priority for European regulators. To carry out this monitoring, the CSSF relies, in particular, on a specialist team of 20 staff members responsible for the “off-site” supervision of ICT risks, supplemented by teams dedicated to on-site inspections.



