France's Financial Markets Authority has published its first assessment of major information and communication technology incidents reported under the EU Digital Operational Resilience Act in 2025. Portfolio management companies submitted 47 initial notifications, of which 31 were confirmed as major incidents. Third party service providers caused 27, or 87%, while cyberattacks accounted for 22, or 71%, including 15 incidents involving data exfiltration and seven involving compromised company tools. The incidents disrupted critical activities including portfolio monitoring, order transmission, access to internal data and know your customer procedures. They affected portfolio managers of all sizes, ownership structures and investment strategies, underscoring the sector's reliance on interconnected technology providers. Implementation weaknesses also persisted during DORA's first year of application. Although reporting quality improved in the second half of 2025, a November self-assessment found that 23% of portfolio management companies had not established a DORA-compliant major incident reporting system. The authority expects third party technology risk to receive particular attention in firms' governance and internal controls and to remain a key supervisory theme. Portfolio managers reported difficulties securing DORA-compliant contractual terms from providers, particularly audit, testing and regulatory cooperation rights. The authority also expects more reports from crypto-asset service providers in 2026 as the number of authorized firms has increased following the end of France's transitional regime.
2026-09-23France Autorite des marches financiers
France's Financial Markets Authority finds third parties caused 87% of portfolio managers' major DORA incidents in 2025
France's Financial Markets Authority found that third party providers caused 87% of the 31 major DORA incidents confirmed for portfolio management companies in 2025, while cyberattacks accounted for 71%. The incidents disrupted critical investment management, trading, data and compliance functions across firms of all sizes. Reporting arrangements also remain incomplete, with 23% of portfolio managers lacking a DORA-compliant major incident reporting system in a November 2025 self-assessment.