COURSE PROGRAM:
PART 1: FOUNDATIONS AND ICT RISK MANAGEMENT
Objective: Understand the context, scope, and core pillars of DORA, focusing on the identification and management of ICT risks.
Introduction to the European Regulatory Framework
Theory:
" European regulatory context.
" Key objectives: Resilience beyond cybersecurity.
" Scope of application: Is my company subject to DORA?
ICT Risk Management - Part 1
The backbone of DORA
Theory:
" Requirements for the ICT Risk Management Framework.
" Strong governance: Roles and responsibilities of the DORA Manager.
" Identification and inventory of critical assets.
ICT Risk Management - Part 2
From theory to practice.
Theory:
" Risk assessment methodologies (quantitative vs. qualitative).
" Implementation of controls (e.g., NIST, ISO 27001).
" The role of the Digital Resilience Officer.
Incident Management
Preparing for the inevitable.
Theory:
" Distinguishing between events and incidents.
" Establishing an incident response plan.
" Classification and escalation processes.
Workshop - Part 1
Integrative Exercise: "Week 1 at EuroBank FinTech."
Teams present their initial compliance assessment, identify three critical ICT risks, and outline an incident response protocol.
PART 2: DIGITAL RESILIENCE TESTING
Theory:
" Testing scale: From vulnerability assessments to Red Team exercises.
" Test frequency and planning.
" Criteria for selecting testing providers.
Incident Reporting
Clear and timely communication.
Theory:
" Incident classification (major, significant).
" Legal notification timelines (initial, interim, final).
" Communication channels with competent authorities (IPC).
Information Management
Protecting data and institutional knowledge.
Theory:
" Data classification policies (public, internal, confidential, restricted).
" Encryption and key management.
" Data Loss Prevention (DLP) measures.
Supply Chain (TPRM)
Extending resilience to third parties.
Theory:
" Third-party (ICT provider) risk assessment.
" Vendor classification by criticality.
" Mandatory contractual clauses.
Workshop - Part 2
Operational Resilience Testing:
Simulation exercise - design a resilience test for critical systems.
PART 3: THIRD-PARTY MANAGEMENT (CONTRACTS)
Legally securing DORA requirements.
Theory:
" Minimum content for ICT provider agreements (Article 30).
" Audit and information access criteria.
" Exit strategies.
Cyber Threat Intelligence (CTI)
Theory:
" Concept and lifecycle of Cyber Threat Intelligence (CTI).
" Intelligence sources (OSINT, commercial feeds, CERTs).
" Integrating CTI into risk management.
Interconnection with Other Frameworks
Avoiding silos and duplicated efforts.
Theory:
" DORA vs. ISO 27001: Common points and key differences.
" DORA and NIS2: Resilience vs. security focus.
" DORA and GDPR: Handling incidents involving personal data.
Cybersecurity in Procurement
Building security from the start.
Theory:
" Embedding resilience requirements in software development.
" Principles of Security by Design and Privacy by Design.
" Security review in DevOps projects.
Workshop - Part 3
Define critical contractual clauses such as audit rights, data location, security SLAs, and incident response protocols for negotiation with a vendor.
PART 4: THE DORA IMPLEMENTATION PLAN
From theory to execution.
Theory:
" Structuring a DORA implementation project.
" Project phases: Diagnosis, Planning, Execution, Monitoring.
" Resource and budget allocation.
Monitoring and Continuous Improvement
Theory:
" Key Performance Indicators (KPIs) for DORA compliance.
" Conducting internal audits.
" Management review: What to report and how.
Audit Preparation
Demonstrating compliance.
Theory:
" What to expect from a regulatory audit.
" Documentation evidence: What to prepare.
" Managing findings and nonconformities.
Final Simulation (Part 1)
Comprehensive Case Study:
A company with a "partial" DORA implementation suffers a complex cyberattack. Teams analyze the situation, failures, and response actions.
Gap Analysis: Identify all DORA deficiencies found in the case.
Final Simulation (Part 2) & Closing Session
DORA Manager Day:
Teams present their corrective action plan, prioritized roadmap, and communication strategy for senior management and auditors.
Closing Session.