DORA — Implementation in the Financial Sector
End-to-end implementation of the Digital Operational Resilience Act (DORA) in financial institutions: the five pillars of ICT risk management, TLPT testing, the ICT third-party register, and incident reporting procedures aligned with EBA/ESMA/EIOPA RTS/ITS.
DORA implementation is more than a single compliance document
DORA is not another security policy bolted onto an existing risk management system — it is a new, integrated framework spanning five interconnected pillars. Financial institutions that implement them piecemeal (incident reporting here, testing there, the provider register separately) lose the synergy between pillars and generate extra work with every update. This training walks through implementation as a whole, so a single risk register feeds both incident classification and TLPT test planning.
From asset inventory to a working framework
The starting point is an inventory of ICT assets and critical functions — without it, the scope of the other pillars cannot be correctly defined. Participants work through the full path: classifying critical functions, building an Article 28-compliant ICT provider register, designing an incident reporting procedure aligned with RTS/ITS deadlines, and planning a resilience testing programme matched to the institution’s risk profile.
TLPT without the guesswork
Threat-led penetration testing raises the most practical questions — who must run it, how often, and under what methodology. In the workshop we clarify the difference between basic ICT resilience testing and advanced TLPT under the TIBER-EU framework, and show how test results translate into concrete remediation actions in the risk register.
Benefits
- Design and implement a complete ICT Risk Management Framework aligned with the five DORA pillars
- Build a register of information on ICT third-party providers required under Article 28 of DORA
- Prepare incident classification and reporting procedures aligned with RTS/ITS deadlines
- Plan a digital operational resilience testing programme, including threat-led penetration testing (TLPT) for systemically important entities
Who is this training for?
Prerequisites
- Basic understanding of the organizational structure and IT processes of a financial institution
- Familiarity with general operational risk management principles (helpful, not required)
Training program
DORA scope and the five pillars of ICT risk management
- Financial entities in scope: banks, insurers, investment firms, crypto-asset providers
- How DORA relates to existing EBA/ESMA/EIOPA ICT risk guidelines
- The five pillars: ICT risk management, incident handling, resilience testing, third-party risk, information sharing
- Implementation timeline and consequences of non-compliance
ICT Risk Management Framework
- The management body's role in approving the ICT risk strategy
- Identifying and classifying ICT assets and critical functions
- Business continuity and disaster recovery policies under the DORA regime
- Documentation and auditability of the risk framework
Incident management and RTS/ITS reporting
- Classifying an ICT incident as a major incident
- Deadlines and formats under regulatory technical standards (RTS) and implementing technical standards (ITS)
- Decision flow: detection, classification, supervisory notification, final report
- Coordinating with NIS2/national cybersecurity law at the intersection of both regimes
Digital operational resilience testing (TLPT)
- Basic ICT resilience testing versus advanced TLPT for systemically important entities
- Threat-led penetration testing methodology aligned with the TIBER-EU framework
- Scope, frequency and selection of testing providers
- Using test results to update the risk register
Third-party risk management and the ICT provider register
- Building a register of information compliant with Article 28 of DORA
- Assessing concentration risk with key ICT providers (including public cloud)
- Contractual clauses required when outsourcing critical functions
- Oversight of providers designated as critical (oversight framework)
Delivery Methods
Online
- Convenience of participating from anywhere
- Interactive live sessions with trainer
- Materials available for 30 days
- No travel costs
On-site
- Direct contact with trainer and group
- Intensive hands-on workshops
- Networking with other participants
- Full focus on learning
Frequently asked questions
What are the five pillars of DORA and where should implementation start?
The five pillars are: ICT risk management, incident handling and reporting, digital operational resilience testing (including TLPT), third-party risk management, and information sharing. Implementation should start with an inventory of ICT assets and critical functions, since that inventory defines the scope of every other pillar. In training we build an implementation plan in this order, with priorities matched to the institution's size and risk profile.
How does this training differ from DORA for the Board, DORA ICT Risk Management and DORA Incident Reporting in our catalog?
Those three trainings cover narrow modules — board accountability, the risk management framework alone, and incident reporting alone, respectively. This training walks through end-to-end implementation of all five pillars together, emphasizing the integration between them — for example, how TLPT results feed into the risk register, and how the provider register drives incident classification.
Does our institution need to run TLPT tests?
Advanced TLPT testing is mandatory for financial entities designated as systemically important by the competent supervisory authority, based on DORA criteria such as size, complexity, and significance to financial stability. Other entities run basic ICT resilience tests on an annual cycle. In training we show how to determine which group your organization falls into and how to plan the right testing programme.
How do we build a register of information for ICT providers under Article 28 of DORA?
The register must cover all ICT service providers supporting critical or important functions, including service scope, data processing location, criticality level, and the existence of exit strategies. In the workshop we work through a register template and a risk-based classification method for providers, including public cloud providers.
What are the consequences of DORA non-compliance?
Financial supervisory authorities (KNF in Poland, EBA/ESMA/EIOPA at EU level) can impose administrative penalties, require remediation plans, and — in extreme cases — restrict an entity's scope of activity. Beyond formal sanctions, non-compliance increases real operational risk stemming from unmanaged ICT incidents and provider dependencies.
Request a quote
Funding Options
Check funding options for your company
Development Services Database
Up to 80% funding for SMEs from EU funds
Check availabilityNational Training Fund
Up to 100% funding for employers
Learn moreTrusted by
We train teams at Poland's largest companies
Interested in this training?
Contact us - we'll prepare an offer tailored to your organization's needs.