Skip to main content
Image coming soon

Banking IT Continuity Under DORA Scrutiny

$199.00
Adding to cart… The item has been added

A focused course, tailored for you

Banking IT Continuity Under DORA Scrutiny

Build the ICT resilience testing programme your regulator actually wants to examine.

Your recovery tests prove the systems come back. They do not prove your testing methodology is proportionate, threat-informed, and mapped to DORA resilience categories. That gap is what ACPR examiners look for, and it sits in the space between your existing continuity programme and the specific artefacts DORA Articles 25 and 26 require.

$199 one-time
Tailored to your situation. Access within 24 hours. 30-day money-back.

Includes a hand-built implementation playbook delivered alongside course access, generated for your specific situation.

Why this course

IT Security and IT Continuity roles at significant financial institutions have both been reshaped by DORA, but in different directions. Security teams are absorbing new threat intelligence and TLPT obligations. Continuity teams are discovering that traditional BCP documentation does not satisfy DORA scope and proportionality requirements. The officer holding accountability across both functions has to produce testing evidence that satisfies the security team's risk register, the continuity team's recovery objectives, and the regulator's expectation that TLPT results feed back into the risk management cycle. Most programmes were not designed to do all three at once, and patching them together produces documentation that looks complete but does not hold up under a supervisory review.

What you walk away with

  • Map your existing ISO 22301 and ISO 27001 programme to DORA Articles 5-16 and identify exactly which gaps need documented remediation.
  • Design a resilience testing programme with scope documentation, threat scenario matrices, and a testing register that satisfies ACPR and ECB supervisory review.
  • Build the TLPT preparation package required for significant institutions, including the intelligence-led threat scenario documentation regulators examine.
  • Structure ICT incident classification and reporting to meet DORA's 4-hour initial notification, 72-hour intermediate, and 1-month final report cycle.
  • Manage third-party ICT risk under DORA Articles 28-30 with compliant contracts, criticality assessments, and exit strategy documentation.
  • Integrate IT Security and IT Continuity testing evidence into a single programme that holds up under both internal audit and supervisory examination.

The 12 modules

Module 1. DORA ICT Risk Management Framework
Maps DORA Articles 5-16 to the governance structures an IT Security and IT Continuity Officer already holds. You will produce a gap register that identifies which elements of your existing ISO 27001 and BCM programme satisfy DORA requirements directly and which need supplementary documentation. The output is a structured framework document your risk committee can review, not a parallel governance layer built from scratch.
Module 2. ICT Asset Classification for Resilience Scope
Walks through the DORA requirement to maintain a classified ICT asset register linked to your critical and important functions. You will build the classification methodology and the direct link between asset criticality and your resilience testing scope. Regulators expect this link to be explicit. Most existing asset registers are not structured to provide it, and this module shows the adjustment required without a full rebuild.
Module 3. Continuity Planning That Satisfies DORA Articles 11-12
Examines the specific differences between a traditional BCP and the ICT continuity policy DORA Articles 11 and 12 require. You will revise your policy structure to include the recovery objectives, testing schedule, and senior management review cycle the regulation mandates. The module provides the document template and shows where most existing BCPs fall short under a supervisory read.
Module 4. ICT Incident Classification and Regulatory Reporting
Builds the major incident classification matrix DORA requires financial entities to maintain, including the criteria for initial notification within 4 hours, the intermediate report at 72 hours, and the final report within one month. You will produce the three report templates and the internal escalation workflow that feeds them. The focus is on the decision points that determine classification, not just the reporting formats themselves.
Module 5. Third-Party ICT Risk Under DORA Articles 28-30
Maps your ICT supplier register to DORA's criticality tiers and builds the contractual requirements checklist the regulation mandates for significant providers. You will draft the exit strategy template for critical ICT providers, a requirement many institutions have not yet operationalised. The module shows how to prioritise the supplier review without re-contracting every vendor simultaneously across a complex global institution.
Module 6. Resilience Testing Design and Proportionality
Covers DORA Article 25 in detail: how to design a testing programme proportionate to your institution's ICT risk profile, size, and operational complexity. You will build the test scope document that demonstrates proportionality to a regulator, the scenario selection methodology, and the annual testing calendar. This is the foundation artefact that gives your TLPT preparation a defensible starting point.
Module 7. TLPT Preparation for Significant Institutions
Prepares the documentation package for Threat-Led Penetration Testing under DORA Article 26 and the TIBER-EU framework. You will produce the intelligence-led threat scenario brief, the tester selection criteria, and the test plan structure regulators review before authorising a TLPT exercise. The module is built specifically for significant institutions where TLPT is mandatory, with templates aligned to what national competent authorities examine.
Module 8. Testing Register and Audit Trail
Builds the testing register that maps each recovery exercise, penetration test, and continuity drill to a DORA resilience category and to the risk profile that prompted it. You will construct the register format, the gap documentation standard, and the evidence package structure supervisors examine during an on-site inspection. The output lets you answer any audit question about testing coverage without manual reconstruction under pressure.
Module 9. Security and Continuity Joint Testing
Addresses the integration point most institutions handle poorly: joint scenario tests where IT Security controls and IT Continuity recovery objectives interact. You will design the joint exercise format, the shared risk register section that feeds both teams, and the escalation protocol when a security incident triggers a continuity response. The module resolves the silo problem structurally without requiring an organisational redesign.
Module 10. RTO and RPO Validation and Exception Management
Moves your recovery time and recovery point objectives from stated to tested and evidenced. You will build the validation methodology, the exception register for objectives that cannot currently be met, and the accepted-risk documentation ACPR examiners look for when they find gaps between stated and achieved objectives. The focus is on producing defensible documentation, not on concealing shortfalls that a regulator will find anyway.
Module 11. ICT Continuity Governance and Board Reporting
Designs the governance structure for digital operational resilience reporting to senior management and the board. You will produce the operational resilience self-assessment template DORA encourages significant institutions to complete, the board dashboard format, and the internal escalation framework. The module shows how to present DORA compliance status in terms that non-technical board members can assess and challenge meaningfully.
Module 12. Programme Review and Regulatory Change Management
Builds the annual review cycle for your DORA resilience programme, including the process for incorporating incident learnings, updating testing scenarios, and tracking changes in DORA regulatory technical standards as the European Banking Authority finalises them. You will produce the change management log format and the review governance documentation that demonstrates to supervisors that your programme improves systematically with each cycle.

How this addresses your situation

Specific modules that map to what you said you are dealing with.

Your testing methodology cannot demonstrate proportionality to your ICT risk profile: Modules 2, 6, and 8 build the three artefacts that close that gap.
Your BCP documentation predates DORA and does not satisfy Articles 11-12: Module 3 provides the restructuring template without rebuilding what already works.
You are preparing for TLPT as a significant institution and need the intelligence-led scenario documentation: Module 7 produces the full preparation package regulators examine.
Your third-party ICT provider review is incomplete and exit strategies are not documented: Module 5 prioritises the review and drafts the required contractual and exit documentation.

What you get with this course

  • 12 written modules covering DORA ICT risk management, resilience testing design, TLPT preparation, incident classification, and third-party ICT risk.
  • Downloadable templates for every module: gap register, ICT asset classification tool, continuity policy structure, incident report formats for each DORA reporting stage, testing register, TLPT preparation brief, and board reporting template.
  • The hand-built implementation playbook tailored to IT Security and IT Continuity Officer responsibilities at significant financial institutions.
  • Access within 24 hours of purchase through the Art of Service learning environment.

What you will have in hand by Day 1, Week 1, Month 1

Access to all 12 modules within 24 hours of purchase.

Implementation playbook delivered alongside course access, built for IT Security and IT Continuity Officer responsibilities at significant financial institutions.

Before and after

Before

Recovery tests pass technically but cannot be linked to a DORA-compliant testing programme with proportionate scope. BCP documentation satisfies ISO 22301 internally but does not map to DORA Articles 11-12. TLPT preparation is pending because the intelligence-led threat scenario brief has not been drafted. Third-party ICT providers are under review but exit strategies are undocumented.

After

A testing register maps every exercise to a DORA resilience category and to your ICT risk profile. Continuity documentation satisfies DORA Articles 11-12 scope and review requirements. TLPT preparation package is complete and defensible. Third-party criticality tiers are set, contracts reviewed, and exit strategies drafted for critical ICT providers.

What happens if you do not address this

DORA supervisory examinations focus on testing evidence, not testing activity. An institution that ran tests but cannot produce proportionate scope documentation, threat scenario matrices, and a compliant testing register faces regulatory findings regardless of how well the recovery actually performed. For a significant institution, that means mandatory remediation timelines and potential scrutiny of the broader ICT risk management framework by the national competent authority.

Who it is for

IT Security and IT Continuity Officers at large financial institutions who hold accountability for DORA compliance across both disciplines and need to produce a coherent testing programme, not two parallel ones. Typically responsible for the annual resilience testing plan, TLPT coordination for significant institutions, and ICT risk reporting to senior management. Familiar with ISO 22301 and ISO 27001 but working to map those existing frameworks to DORA's specific requirements without rebuilding from scratch.

Who this is NOT for. Not for general IT practitioners without a continuity mandate. Not useful if your institution has already completed a full DORA gap assessment and built a validated testing programme with regulatory sign-off. Not appropriate for institutions outside DORA scope where equivalent regulation uses a materially different testing framework.

How it arrives

Text-based course in the Art of Service learning environment, plus downloadable templates and worked examples for every module, plus the hand-built implementation playbook delivered alongside course access.

Time investment. Each module is designed to complete in 45-60 minutes. The full course takes approximately 10-12 hours. Templates are ready to apply immediately after each module.

Why $199 is the right number

Regulatory consultancies offer DORA gap assessments at engagement rates that exceed this course cost many times over, without leaving your team with the skills to manage subsequent regulatory change cycles independently. Internal programmes built from scratch require months of stakeholder alignment before producing the artefacts this course delivers in weeks. This course gives the IT Security and IT Continuity Officer the methodology to build a compliant programme without external dependency for the next examination cycle.

FAQ

Does this work if we already have a DORA project underway?
Yes. Most institutions are mid-implementation. The course is structured so each module maps to your existing programme and the templates fill documented gaps rather than replacing what already works. The gap register from Module 1 shows you exactly where to focus.
Is this specifically built for EU institutions under DORA, or does it apply elsewhere?
The course is built around DORA Articles 5-30 and ACPR and ECB supervisory expectations for significant institutions. The methodology transfers to equivalent regulation in other jurisdictions, but the specific article references, reporting timelines, and TLPT requirements are EU-specific.
How does the implementation playbook differ from the course modules?
The modules teach the methodology and provide generic templates. The implementation playbook is built for your specific role, adapting the module outputs to the responsibilities and reporting lines of an IT Security and IT Continuity Officer. It is the working document you carry into your programme.

30-day money-back guarantee. If after a week of working through the materials this is not what you needed, reply to the receipt email and a full refund is processed. No questions, no forms.

Within 24 hours your account in the learning environment is provisioned and the tailored implementation playbook is delivered alongside it.