Cloud Security Risks Heightened by DORA Compliance Challenges
Article Content
- •DORA imposes strict compliance requirements on financial organizations regarding third-party risks.
- •44% of organizations experienced cloud data breaches in 2025, costing an average of $5.17 million per incident.
- •The breach of Oracle Cloud in 2025 exposed 6 million records, highlighting vulnerabilities in cloud security.
The Digital Operational Resilience Act (DORA) has imposed stringent compliance requirements on financial organizations, particularly regarding third-party risk management. As a result, firms are now liable for the security of their cloud service providers, increasing the risk of significant data breaches. A notable incident in 2025 involved a breach of Oracle Cloud's systems, compromising 6 million records from over 140,000 tenants. With 44% of organizations reporting cloud data breaches in 2025, the average cost per incident reached $5.17 million. As organizations transition from compliance planning to operational execution, they face challenges in achieving measurable resilience against cyber threats. The ongoing shift towards cloud services, with 69% of businesses utilizing public cloud infrastructure, further exacerbates these risks. The situation is compounded by the emergence of additional regulations like CSA2, which will require further adaptation and vigilance.
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (2)
Following this threat?
Track Oracle in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.
Free account · no card needed
Continue Reading
Critical WSO2 API Manager Vulnerability Under Active Exploitation A critical vulnerability (CVE-2026-5430) in WSO2 API Manager is being actively exploited, allowing unauthenticated attackers to forge admin tokens via JWT authentication bypass. This flaw, which has a CVSS score of 10.0, affects multiple WSO2 products including API Manager, Universal Gateway, Traffic Manager, and API…
Critical Linux Kernel Vulnerability CVE-2025-39682 Under Active Exploitation A critical vulnerability (CVE-2025-39682) in the Linux kernel allows remote code execution through mishandling of zero-length TLS records. This flaw affects kTLS-enabled hosts running vulnerable kernel versions, exposing them to attackers without authentication. CISA added this vulnerability to its Known Exploited…