DORA and operational resilience: Credential management as a financial risk control
ID: c8d1122d-9e68-5e7f-aeb5-010048d50358
STIX ID: report--c8d1122d-9e68-5e7f-aeb5-010048d50358
Feed Name: Bleeping Computer
Threat Score
This article explains how stolen credentials are a dominant initial access vector for financial-sector breaches, outlines DORA Article 9 requirements for strong authentication and least-privilege access, cites high-impact examples (a 1.2M-account registry breach and the Snowflake/Santander incident), and recommends controls—phishing-resistant MFA, JIT least-privilege, vaulting of credentials, and continuous monitoring—to meet regulatory and operational resilience obligations.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
