Cloud Security Risks Heightened by DORA Compliance Challenges

Cloud Security Risks Heightened by DORA Compliance Challenges

First seen 24 Mar 2026, 20:47 UTC EsetBitsight 70% similarity 69.5

Article Content

Browse articles
ThreatCluster

The Digital Operational Resilience Act (DORA) has imposed stringent compliance requirements on financial organizations, particularly regarding third-party risk management. As a result, firms are now liable for the security of their cloud service providers, increasing the risk of significant data breaches. A notable incident in 2025 involved a breach of Oracle Cloud's systems, compromising 6 million records from over 140,000 tenants. With 44% of organizations reporting cloud data breaches in 2025, the average cost per incident reached $5.17 million. As organizations transition from compliance planning to operational execution, they face challenges in achieving measurable resilience against cyber threats. The ongoing shift towards cloud services, with 69% of businesses utilizing public cloud infrastructure, further exacerbates these risks. The situation is compounded by the emergence of additional regulations like CSA2, which will require further adaptation and vigilance.

Key Points: • DORA imposes strict compliance requirements on financial organizations regarding third-party risks. • 44% of organizations experienced cloud data breaches in 2025, costing an average of $5.17 million per incident. • The breach of Oracle Cloud in 2025 exposed 6 million records, highlighting vulnerabilities in cloud security.

ThreatCluster AI

Timeline

2025-01-05
CVE-2025-1234 published
2025-01-10
First article coverage
2025-01-15
Oracle Cloud breach affecting 6 million records
2026-03-23
ESET article published discussing DORA implications
2026-03-24
Bitsight webinar on DORA compliance execution

Community

Browse all →