Perform a search on the site.

Your currency

DORA (Digital Operational Resilience Act): mastering digital resilience fundamentals

Digital resilience must be organised before an incident occurs. Understand DORA requirements and their implications for risk management, service providers and response arrangements. Strengthen your ability to connect compliance with continuity of digital operations.

Duration
2 days 14 hours
Code
GRC004FR Code

Presentation

As cyberattacks multiply, information system security has become critical for the financial sector. The European Digital Operational Resilience Act (DORA) now requires institutions to strengthen their digital operational resilience. You need to adapt your internal processes to meet these complex new regulatory requirements.

Throughout this intensive course, you will explore the overall compliance framework applicable to financial entities and ICT service providers. You will analyse the fundamental principles of technology risk management to map your critical processes. You will also discover good practices for organising digital resilience testing and structuring incident reporting.

By the end of these 2 days, you will have the skills needed to confidently lead DORA implementation within your organisation. In practical terms, you will be able to coordinate governance bodies and ensure continuity of essential activities.

Note: this programme can also be condensed into 1 day to provide an overview of the main obligations.

Objectives

By the end of this course, you will be able to:

  • understand digital resilience fundamentals and map ICT risks affecting your critical activities;
  • interpret key DORA requirements to structure your financial institution's overall compliance framework;
  • define the roles and responsibilities of governance bodies to effectively steer digital security strategy;
  • deploy robust processes for incident management, business continuity and communication with authorities;
  • plan and conduct advanced digital resilience tests, analysing results to implement corrective actions;
  • assess and control third-party service provider risks by incorporating rigorous contractual security clauses.
Last update: 24/09/2026