
This course tackles everything you need to know about the Digital Operational Resilience Act (DORA), one of the most important regulatory frameworks impacting financial institutions and ICT service providers in the European Union.
You will learn the purpose of DORA, understand its five pillars, explore its key requirements, and gain practical insight into areas such as ICT risk management, incident reporting, resilience testing, third-party risk management, and compliance readiness.
By the end of the course, you will have a solid understanding of DORA's requirements and the role they play in strengthening operational resilience across organizations.
What is DORA?
DORA, or the Digital Operational Resilience Act, is a European Union regulation that establishes requirements for managing ICT risk, reporting incidents, conducting resilience testing, overseeing third-party technology providers, and strengthening operational resilience. The regulation creates a comprehensive framework intended to help financial entities withstand, respond to, and recover from technology-related disruptions.
Why DORA?
DORA is designed to ensure that financial organizations can continue operating during technology disruptions, cyber incidents, and operational failures. Rather than focusing solely on prevention, DORA emphasizes preparedness, response, recovery, testing, and continuous improvement.
Who is the instructor?
This course is taught by Konstantin, a public policy and regulatory affairs professional with experience in legislative research, consulting, and public relations. Throughout his career, he has helped organizations understand and adapt to complex regulatory and legislative changes, translating legal and policy requirements into practical business guidance. He holds a Master's degree in International Relations from the University of St Andrews and a Bachelor's degree in Government and Public Policy from University College Cork.
In this course, Konstantin leverages his expertise to break down the European Union's Digital Operational Resilience Act (DORA) into clear, practical concepts that you can confidently apply within your organization.
What is this course all about?
This course focuses on understanding DORA in a clear, structured, and practical way so that you can confidently discuss and assess DORA requirements within your organization.
By the end of this course, you will understand:
The purpose and scope of DORA
The five pillars of the regulation
ICT risk management requirements
Incident reporting obligations
Operational resilience testing expectations
Third-party risk management requirements
Information sharing provisions
Common implementation challenges
Practical readiness considerations
Course Overview
Introduction and Background to DORA - Understand why DORA was created, who it applies to, its objectives, timelines, scope, and the five pillars that form the foundation of the regulation.
DORA Pillar 1: The ICT Risk Management Framework (IRMF) - Learn how organizations are expected to identify, manage, respond to, recover from, and continuously improve their management of ICT risks.
Pillar 2: Incident Reporting - Understand incident classification, reporting obligations, timelines, regulatory notifications, and cyber threat reporting requirements.
Pillar 3: Digital Operational Resilience Testing - Explore DORA's testing requirements, including resilience assessments, threat-led penetration testing, and third-party testing considerations.
Pillar 4: Third Party Risk Management - Learn how DORA addresses ICT third-party risk, contractual requirements, concentration risk, critical providers, and exit planning.
Pillar 5: Information Sharing - Understand how organizations can participate in information-sharing arrangements to strengthen collective cyber resilience.
DORA Readiness - Assess organizational preparedness, identify priority actions, understand common pitfalls, and explore broader regulatory considerations.
Takeaways and Conclusion - Review the key concepts from the course, address common questions, and consolidate your understanding of DORA's requirements.