Digital Operational Resilience Act (DORA) Training Course

AVAILABLE IN IN-PERSON OR E-LEARNING FORMAT

The Digital Operational Resilience Act (DORA) is a European regulation that establishes a common framework for digital operational resilience in the financial sector.
Its goal is to ensure that all financial entities - including banks, insurance companies, investment funds, and technology service providers - are able to withstand, respond to, and recover effectively from digital incidents and cyberattacks.

DORA is part of the European Union's Digital Finance Package and becomes fully applicable in January 2025. It requires entities to implement comprehensive ICT risk management, enhanced oversight of critical third-party technology service providers, and clear coordination with supervisory authorities.

DORA is not just another cybersecurity regulation:
"        Harmonizes Requirements: Creates a level playing field across the EU, simplifying compliance for entities operating across multiple jurisdictions.
"        Imposes Holistic ICT Risk Management: Requires organizations to manage ICT risk in an integrated, continuous, and proactive way.
"        Regulates the ICT Supply Chain: It is the first regulation to explicitly and strictly address risks arising from outsourced ICT service providers (such as cloud, data, or infrastructure services).
"        Introduces Mandatory Resilience Testing: Requires advanced ICT resilience testing, including penetration testing and red teaming exercises.
"        Enhances Incident Management: Establishes standardized protocols for the reporting and handling of major cyber incidents.

Course Overview
This course is specifically designed for financial executives and senior managers, who play a key role in governing technology and operational risk.
In an increasingly digitalized financial environment, cyber incidents can directly impact an organization's stability, reputation, and business continuity.
Complying with DORA is not only a legal requirement, but also a competitive advantage - demonstrating control, security, and confidence to regulators, investors, and clients.

By participating in this program, executives will:
"        Understand the regulatory requirements and their impact on financial management.
"        Identify technological and operational risks relevant to their organization.
"        Develop resilience and continuity strategies aligned with DORA standards.
"        Prepare their organizations to successfully undergo audits and regulatory inspections.

Target Audience

This course is aimed at:
"        Chief Financial Officers (CFOs)
"        Compliance and Internal Control Officers
"        Chief Executive Officers (CEOs) and Board Members
"        Internal Auditors and Risk Management Consultants
"        Executives from financial institutions, fintechs, and critical technology service providers

Detailed Roles Include:

Financial and Operations Executives:
"        Chief Financial Officers (CFOs)
"        Chief Operating Officers (COOs)
"        Directors of Financial Control and Management
"        Budget and Strategic Planning Managers
Risk and Compliance Leaders:
"        Chief Risk Officers (CROs)
"        Compliance Directors
"        Operational and Technology Risk Managers
Senior Management and Governance Members:
"        Board Members, Audit and Risk Committee Members
"        Chief Executive Officers (CEOs) seeking a comprehensive view of DORA's business impact
Internal Auditors:
"        Heads of Internal Audit responsible for verifying and auditing DORA compliance

INTERCER NORTH AMERICA
880 Third Avenue, 5th Floor, New York, NY 10022

Office Hours: Monday through Friday. 9:00 am to 18:00 pm Eastern Standard Time (EST)

THIS WEBSITE DOES NOT USE COOKIES OR ANY MEANS OF VISITOR CONTROL.

img src="https://tracker.metricool.com/c3po.jpg?hash=b3d5a9f6b99920226f8a6dcb9e2f4080"/
INSIGHT AREAS                                         















WHO WE ARE    SERVICES     TECHNICAL INSPECTION    
COURSE PROGRAM:

PART 1: FOUNDATIONS AND ICT RISK MANAGEMENT

Objective: Understand the context, scope, and core pillars of DORA, focusing on the identification and management of ICT risks.
Introduction to the European Regulatory Framework

Theory:
"        European regulatory context.
"        Key objectives: Resilience beyond cybersecurity.
"        Scope of application: Is my company subject to DORA?

ICT Risk Management - Part 1
The backbone of DORA

Theory:
"        Requirements for the ICT Risk Management Framework.
"        Strong governance: Roles and responsibilities of the DORA Manager.
"        Identification and inventory of critical assets.

ICT Risk Management - Part 2
From theory to practice.

Theory:
"        Risk assessment methodologies (quantitative vs. qualitative).
"        Implementation of controls (e.g., NIST, ISO 27001).
"        The role of the Digital Resilience Officer.

Incident Management
Preparing for the inevitable.

Theory:
"        Distinguishing between events and incidents.
"        Establishing an incident response plan.
"        Classification and escalation processes.

Workshop - Part 1
Integrative Exercise: "Week 1 at EuroBank FinTech."
Teams present their initial compliance assessment, identify three critical ICT risks, and outline an incident response protocol.


PART 2: DIGITAL RESILIENCE TESTING

Theory:
"        Testing scale: From vulnerability assessments to Red Team exercises.
"        Test frequency and planning.
"        Criteria for selecting testing providers.

Incident Reporting
Clear and timely communication.

Theory:
"        Incident classification (major, significant).
"        Legal notification timelines (initial, interim, final).
"        Communication channels with competent authorities (IPC).

Information Management
Protecting data and institutional knowledge.

Theory:
"        Data classification policies (public, internal, confidential, restricted).
"        Encryption and key management.
"        Data Loss Prevention (DLP) measures.

Supply Chain (TPRM)
Extending resilience to third parties.

Theory:
"        Third-party (ICT provider) risk assessment.
"        Vendor classification by criticality.
"        Mandatory contractual clauses.

Workshop - Part 2
Operational Resilience Testing:
Simulation exercise - design a resilience test for critical systems.

PART 3: THIRD-PARTY MANAGEMENT (CONTRACTS)

Legally securing DORA requirements.

Theory:
"        Minimum content for ICT provider agreements (Article 30).
"        Audit and information access criteria.
"        Exit strategies.

Cyber Threat Intelligence (CTI)

Theory:
"        Concept and lifecycle of Cyber Threat Intelligence (CTI).
"        Intelligence sources (OSINT, commercial feeds, CERTs).
"        Integrating CTI into risk management.

Interconnection with Other Frameworks
Avoiding silos and duplicated efforts.

Theory:
"        DORA vs. ISO 27001: Common points and key differences.
"        DORA and NIS2: Resilience vs. security focus.
"        DORA and GDPR: Handling incidents involving personal data.

Cybersecurity in Procurement
Building security from the start.

Theory:
"        Embedding resilience requirements in software development.
"        Principles of Security by Design and Privacy by Design.
"        Security review in DevOps projects.

Workshop - Part 3
Define critical contractual clauses such as audit rights, data location, security SLAs, and incident response protocols for negotiation with a vendor.

PART 4: THE DORA IMPLEMENTATION PLAN
From theory to execution.

Theory:
"        Structuring a DORA implementation project.
"        Project phases: Diagnosis, Planning, Execution, Monitoring.
"        Resource and budget allocation.

Monitoring and Continuous Improvement
Theory:
"        Key Performance Indicators (KPIs) for DORA compliance.
"        Conducting internal audits.
"        Management review: What to report and how.

Audit Preparation
Demonstrating compliance.

Theory:
"        What to expect from a regulatory audit.
"        Documentation evidence: What to prepare.
"        Managing findings and nonconformities.

Final Simulation (Part 1)

Comprehensive Case Study:
A company with a "partial" DORA implementation suffers a complex cyberattack. Teams analyze the situation, failures, and response actions.
Gap Analysis: Identify all DORA deficiencies found in the case.

Final Simulation (Part 2) & Closing Session
DORA Manager Day:
Teams present their corrective action plan, prioritized roadmap, and communication strategy for senior management and auditors.

Closing Session.