DORA (Digital Operational Resilience Act): mastering digital resilience fundamentals
Digital resilience must be organised before an incident occurs. Understand DORA requirements and their implications for risk management, service providers and response arrangements. Strengthen your ability to connect compliance with continuity of digital operations.
- Duration
- 2 days 14 hours
- Code
- GRC004FR Code
Presentation
As cyberattacks multiply, information system security has become critical for the financial sector. The European Digital Operational Resilience Act (DORA) now requires institutions to strengthen their digital operational resilience. You need to adapt your internal processes to meet these complex new regulatory requirements.
Throughout this intensive course, you will explore the overall compliance framework applicable to financial entities and ICT service providers. You will analyse the fundamental principles of technology risk management to map your critical processes. You will also discover good practices for organising digital resilience testing and structuring incident reporting.
By the end of these 2 days, you will have the skills needed to confidently lead DORA implementation within your organisation. In practical terms, you will be able to coordinate governance bodies and ensure continuity of essential activities.
Note: this programme can also be condensed into 1 day to provide an overview of the main obligations.
Objectives
By the end of this course, you will be able to:
- understand digital resilience fundamentals and map ICT risks affecting your critical activities;
- interpret key DORA requirements to structure your financial institution's overall compliance framework;
- define the roles and responsibilities of governance bodies to effectively steer digital security strategy;
- deploy robust processes for incident management, business continuity and communication with authorities;
- plan and conduct advanced digital resilience tests, analysing results to implement corrective actions;
- assess and control third-party service provider risks by incorporating rigorous contractual security clauses.
Program
Module 1: understanding DORA's regulatory framework and key concepts
- Origins, European regulatory context and main objectives.
- Detailed scope covering financial institutions and ICT providers.
- An in-depth definition of digital resilience and the categories of technology risk.
- Analysing the potential impact of a security incident on critical financial operations.
Module 2: structuring governance and ICT risk oversight
- Identifying critical business processes and comprehensively mapping ICT assets.
- Defining roles, responsibilities and the internal governance structure.
- Methodology for identifying, assessing and prioritising cyber threats.
- Implementing appropriate mitigation measures and planning overall compliance.
Module 3: mastering incident management and resilience testing
- Deploying the process for reporting, investigating and tracking security incidents.
- Emergency communication protocols with competent authorities and stakeholders.
- Designing digital resilience test scenarios and defining an appropriate frequency.
- Critical analysis of test results and implementation of targeted corrective actions.
Module 4: managing third parties and cooperating with authorities
- Rigorous assessment and continuous monitoring of external ICT service providers.
- Negotiating contracts and incorporating strict security clauses.
- Understanding the role of regulators, the Lead Overseer and European coordination.
- Threat information-sharing mechanisms and market standards.
- Raising awareness among internal teams to build a genuine resilience culture.
Module 5: driving continuous improvement and preparing for audits
- Defining key performance indicators (KPIs) to measure digital resilience.
- Building decision-support dashboards and reporting to senior management.
- Preparing for management reviews and implementing internal controls.
- Activating the continuous improvement cycle to adapt processes and procedures to new threats.
Audience
This course is intended for financial sector professionals involved in compliance and security, including:
- ICT risk managers who secure critical business processes;
- project managers and consultants responsible for leading DORA compliance programmes;
- CIOs and CISOs seeking to align their infrastructure with European requirements;
- internal and external auditors seeking to understand supervisors' specific expectations under DORA.
Prerequisites
The following prerequisites apply:
- Professional experience: some initial experience in the financial sector, compliance or information technology.
- Technical skills: basic knowledge of information system security or enterprise risk management.
Teaching and assessment methods
- Initial skills assessment
- Training materials provided to participants
- Continuous assessment throughout the course
- End-of-course feedback questionnaire
- Combination of theory and practical application
- Attendance records
- Post-course follow-up evaluation
- Quiz / multiple-choice questions
- Case study
Course highlights
- Immediately usable operational tools: leave with a structured understanding of reporting processes and assessment methodologies.
- Greater confidence: approach future audits and interactions with supervisory authorities with confidence.
- Practical expertise: benefit from real-world lessons shared by a certified trainer and former Head of IT Risk at HSBC.
- Adaptable approach: identify corrective actions directly applicable to your own asset map.
Dates and sessions
Choose the date and delivery format that suit you.
No upcoming sessions are currently available.
fr
en