Skip to content

DORA — Implementation in the Financial Sector

End-to-end implementation of the Digital Operational Resilience Act (DORA) in financial institutions: the five pillars of ICT risk management, TLPT testing, the ICT third-party register, and incident reporting procedures aligned with EBA/ESMA/EIOPA RTS/ITS.

DORA implementation is more than a single compliance document

DORA is not another security policy bolted onto an existing risk management system — it is a new, integrated framework spanning five interconnected pillars. Financial institutions that implement them piecemeal (incident reporting here, testing there, the provider register separately) lose the synergy between pillars and generate extra work with every update. This training walks through implementation as a whole, so a single risk register feeds both incident classification and TLPT test planning.

From asset inventory to a working framework

The starting point is an inventory of ICT assets and critical functions — without it, the scope of the other pillars cannot be correctly defined. Participants work through the full path: classifying critical functions, building an Article 28-compliant ICT provider register, designing an incident reporting procedure aligned with RTS/ITS deadlines, and planning a resilience testing programme matched to the institution’s risk profile.

TLPT without the guesswork

Threat-led penetration testing raises the most practical questions — who must run it, how often, and under what methodology. In the workshop we clarify the difference between basic ICT resilience testing and advanced TLPT under the TIBER-EU framework, and show how test results translate into concrete remediation actions in the risk register.

Benefits

  • Design and implement a complete ICT Risk Management Framework aligned with the five DORA pillars
  • Build a register of information on ICT third-party providers required under Article 28 of DORA
  • Prepare incident classification and reporting procedures aligned with RTS/ITS deadlines
  • Plan a digital operational resilience testing programme, including threat-led penetration testing (TLPT) for systemically important entities

Who is this training for?

CISOs and ICT security managers at banks, insurers and investment firms
Compliance officers and risk managers in the financial sector
IT leaders responsible for implementing an ICT risk management framework
ICT service providers serving financial-sector clients (third-party providers)

Prerequisites

  • Basic understanding of the organizational structure and IT processes of a financial institution
  • Familiarity with general operational risk management principles (helpful, not required)

Training program

01

DORA scope and the five pillars of ICT risk management

  • Financial entities in scope: banks, insurers, investment firms, crypto-asset providers
  • How DORA relates to existing EBA/ESMA/EIOPA ICT risk guidelines
  • The five pillars: ICT risk management, incident handling, resilience testing, third-party risk, information sharing
  • Implementation timeline and consequences of non-compliance
02

ICT Risk Management Framework

  • The management body's role in approving the ICT risk strategy
  • Identifying and classifying ICT assets and critical functions
  • Business continuity and disaster recovery policies under the DORA regime
  • Documentation and auditability of the risk framework
03

Incident management and RTS/ITS reporting

  • Classifying an ICT incident as a major incident
  • Deadlines and formats under regulatory technical standards (RTS) and implementing technical standards (ITS)
  • Decision flow: detection, classification, supervisory notification, final report
  • Coordinating with NIS2/national cybersecurity law at the intersection of both regimes
04

Digital operational resilience testing (TLPT)

  • Basic ICT resilience testing versus advanced TLPT for systemically important entities
  • Threat-led penetration testing methodology aligned with the TIBER-EU framework
  • Scope, frequency and selection of testing providers
  • Using test results to update the risk register
05

Third-party risk management and the ICT provider register

  • Building a register of information compliant with Article 28 of DORA
  • Assessing concentration risk with key ICT providers (including public cloud)
  • Contractual clauses required when outsourcing critical functions
  • Oversight of providers designated as critical (oversight framework)

Delivery Methods

Online

  • Convenience of participating from anywhere
  • Interactive live sessions with trainer
  • Materials available for 30 days
  • No travel costs

On-site

  • Direct contact with trainer and group
  • Intensive hands-on workshops
  • Networking with other participants
  • Full focus on learning

Frequently asked questions

What are the five pillars of DORA and where should implementation start?

The five pillars are: ICT risk management, incident handling and reporting, digital operational resilience testing (including TLPT), third-party risk management, and information sharing. Implementation should start with an inventory of ICT assets and critical functions, since that inventory defines the scope of every other pillar. In training we build an implementation plan in this order, with priorities matched to the institution's size and risk profile.

How does this training differ from DORA for the Board, DORA ICT Risk Management and DORA Incident Reporting in our catalog?

Those three trainings cover narrow modules — board accountability, the risk management framework alone, and incident reporting alone, respectively. This training walks through end-to-end implementation of all five pillars together, emphasizing the integration between them — for example, how TLPT results feed into the risk register, and how the provider register drives incident classification.

Does our institution need to run TLPT tests?

Advanced TLPT testing is mandatory for financial entities designated as systemically important by the competent supervisory authority, based on DORA criteria such as size, complexity, and significance to financial stability. Other entities run basic ICT resilience tests on an annual cycle. In training we show how to determine which group your organization falls into and how to plan the right testing programme.

How do we build a register of information for ICT providers under Article 28 of DORA?

The register must cover all ICT service providers supporting critical or important functions, including service scope, data processing location, criticality level, and the existence of exit strategies. In the workshop we work through a register template and a risk-based classification method for providers, including public cloud providers.

What are the consequences of DORA non-compliance?

Financial supervisory authorities (KNF in Poland, EBA/ESMA/EIOPA at EU level) can impose administrative penalties, require remediation plans, and — in extreme cases — restrict an entity's scope of activity. Beyond formal sanctions, non-compliance increases real operational risk stemming from unmanaged ICT incidents and provider dependencies.

Patrycja Petkowska
Patrycja Petkowska Opiekun szkolenia

Request a quote

Funding Options

Check funding options for your company

Up to 80%

Development Services Database

Up to 80% funding for SMEs from EU funds

Check availability
Up to 100%

National Training Fund

Up to 100% funding for employers

Learn more

Trusted by

We train teams at Poland's largest companies

ING Bank - EITT client
mBank - EITT client
PKO Bank Polski - EITT client
PZU - EITT client
Allianz - EITT client
T-Mobile - EITT client
KGHM - EITT client
PGE - EITT client
IKEA - EITT client
InPost - EITT client
Leroy Merlin - EITT client
ZUS - EITT client

Interested in this training?

Contact us - we'll prepare an offer tailored to your organization's needs.

500+ experts
2500+ trainings available
ISO 9001 quality certified
Request Training
Call us +48 22 487 84 90