Welcome, Guest

DORA: Digital Operational Resilience for EU Financial Entities

Overview

A 5-module decision-based scenario course covering the Digital Operational Resilience Act (Regulation (EU) 2022/2554). The learner manages an ICT incident classification, builds and audits a third-party register, runs a threat-led penetration test (TLPT), executes an exit strategy, and faces a supervisory examination. Approximately 120 minutes total. Course delivered in English.

Target Audience:

ICT risk managers, third-party risk officers, CISOs, compliance leads, and operational resilience teams at EU credit institutions, payment institutions, investment firms, insurance undertakings, crypto-asset service providers, and other financial entities under DORA scope

Features and USPs:

The course helps learners to understand the scope and impact of the legislation and also to work through the regulation as it appears in the workplace. Learners experience the cause?and?effect of their decisions and are supported with immediate feedback. The course helps to build situational awareness, practical judgment, confidence and real?world problem?solving skills.

This interactive and adaptive online course is designed to turn a complex legislative topic into a memorable, actionable learning experience. Using a dynamic “choose your own adventure” format, the course adapts to the learner’s choices within a relatable workplace scenario.

Learning Objectives:

  • Classify an ICT incident under Article 18 and decide reporting trigger
  • Maintain a DORA-compliant third-party register meeting Article 28 standards
  • Scope and run a threat-led penetration test under Article 26
  • Plan and execute an Article 28(8) exit strategy from a critical ICT third party
  • Engage with a Lead Overseer or competent authority during examination