DORA regulation: ensuring digital operational resilience in the financial sector and for ICT providers
Szkolenie przedstawia praktyczne aspekty implementacji rozporządzenia DORA w instytucjach finansowych i u dostawców usług ICT. Program szczegółowo omawia pięć filarów regulacji oraz konkretne kroki wdrożeniowe. Uczestnicy poznają wymagania dotyczące testowania odporności oraz zarządzania ryzykiem dostawców zewnętrznych. Zajęcia prowadzone są w formie warsztatów z analizą praktycznych przypadków z sektora finansowego.
Why choose this training?
The DORA regulation imposes binding digital resilience requirements on financial institutions and their ICT service providers, with penalties for non-compliance that include supervisory sanctions and operational restrictions. This training provides a structured, practical overview of all five DORA pillars — from ICT risk management to TLPT testing and third-party oversight — giving participants the knowledge to build and demonstrate compliance.
What makes our approach unique?
EITT’s 500+ experts and experience from 2,500+ trainings include specialists with direct financial sector and regulatory compliance backgrounds. The DORA Regulation course integrates real financial sector case studies, cross-regulation mapping, and implementation best practices that enable participants to translate regulatory requirements into operational resilience programs without unnecessary complexity.
Benefits
- They will gain detailed knowledge of the requirements of the DORA regulation and its impact on the financial sector
- They will master the ability to build an ICT risk management system in compliance with the regulation
- They will learn to design and implement procedures for reporting incidents to supervisory authorities
- They will be able to plan and conduct advanced digital resilience tests, including TLPT
- They will develop competence in risk management of external ICT vendors
- They will receive practical tools for building threat information sharing programs
- They will gain skills to integrate DORA requirements into existing security management systems
- They will be prepared to be an expert in the implementation of digital operational resilience
Who is this training for?
Prerequisites
- Knowledge of the specifics of the financial sector and its regulations
- Basic knowledge of operational risk management
- Experience working with IT systems in financial institutions
- Knowledge of the basics of cyber security and incident management
- Experience in working with external suppliers
Training program
Introduction to the DORA regulation
- The goals and objectives of the Digital Operational Resilience Act
- Regulatory context in the financial sector
- Relationship to other regulations (PSD2, GDPR, NIS2)
- Implementation timeline and transition period
- Subject scope and entity classification
- Responsibilities of different categories of entities
First pillar: ICT risk management
- Establish a risk management framework
- Identification, protection and prevention
- Detecting and responding to incidents
- Restoring the efficiency of systems
Second pillar: ICT incident reporting
- Classification of major ICT incidents
- Reporting procedures and deadlines
- Communication with supervisory authorities
- Incident information management
Third pillar: Testing digital resilience
- Penetration testing requirements
- TLPT - Threat-Led Penetration Testing
- Planning and conducting tests
- Reporting of testing results
Fourth and fifth pillar: ICT vendors and information sharing
- Requirements for contracts with suppliers
- Conducting audits at suppliers
- Exit strategies and contingency plans
- Monitoring of critical suppliers
- Threat information sharing mechanisms
- Cooperation on cyber threats
DORA integration with existing frameworks
- Mapping with EBA and ECB guidelines
- Compliance with ISO 27001/27005 standards
- Integration with NIST frameworks
- Best implementation practices
Delivery Methods
Online
- Convenience of participating from anywhere
- Interactive live sessions with trainer
- Materials available for 30 days
- No travel costs
On-site
- Direct contact with trainer and group
- Intensive hands-on workshops
- Networking with other participants
- Full focus on learning
Frequently asked questions
What are the prerequisites for the DORA Regulation training?
Participants should have knowledge of the financial sector and its regulations, basic understanding of operational risk management, experience working with IT systems in financial institutions, and familiarity with cyber security fundamentals and incident management.
What is the format and duration of this training?
The DORA Regulation training is a 2-day workshop available in both online and onsite formats. It combines lectures with practical case studies drawn from real financial sector scenarios and hands-on exercises covering all five DORA pillars.
Who should attend the DORA Regulation training?
The training is designed for operational risk management specialists in banks, CISOs and IT security managers in the financial sector, compliance officers, representatives of ICT service providers, internal and external auditors, business continuity managers, and lawyers specializing in financial and technology law.
How does DORA relate to other financial sector regulations such as NIS2 and ISO 27001?
The training includes dedicated sessions on mapping DORA requirements to NIS2, PSD2, GDPR, EBA and ECB guidelines, ISO 27001/27005, and NIST frameworks. Participants learn how to integrate DORA compliance into existing security management systems to avoid duplicating effort and ensure coherent governance.
Why choose EITT for the DORA Regulation training?
EITT combines expertise from 500+ specialists and a portfolio of 2,500+ trainings with deep knowledge of financial sector regulations. The DORA Regulation course provides financial institutions and ICT providers with the practical tools and regulatory insights needed to build a compliant digital operational resilience framework efficiently.
Request a quote
Funding Options
Check funding options for your company
Development Services Database
Up to 80% funding for SMEs from EU funds
Check availabilityNational Training Fund
Up to 100% funding for employers
Learn moreTrusted by
We train teams at Poland's largest companies
Interested in this training?
Contact us - we'll prepare an offer tailored to your organization's needs.