A focused course, tailored for you
Banking IT Continuity Under DORA Scrutiny
Build the ICT resilience testing programme your regulator actually wants to examine.
Your recovery tests prove the systems come back. They do not prove your testing methodology is proportionate, threat-informed, and mapped to DORA resilience categories. That gap is what ACPR examiners look for, and it sits in the space between your existing continuity programme and the specific artefacts DORA Articles 25 and 26 require.
Includes a hand-built implementation playbook delivered alongside course access, generated for your specific situation.
Why this course
IT Security and IT Continuity roles at significant financial institutions have both been reshaped by DORA, but in different directions. Security teams are absorbing new threat intelligence and TLPT obligations. Continuity teams are discovering that traditional BCP documentation does not satisfy DORA scope and proportionality requirements. The officer holding accountability across both functions has to produce testing evidence that satisfies the security team's risk register, the continuity team's recovery objectives, and the regulator's expectation that TLPT results feed back into the risk management cycle. Most programmes were not designed to do all three at once, and patching them together produces documentation that looks complete but does not hold up under a supervisory review.
What you walk away with
- Map your existing ISO 22301 and ISO 27001 programme to DORA Articles 5-16 and identify exactly which gaps need documented remediation.
- Design a resilience testing programme with scope documentation, threat scenario matrices, and a testing register that satisfies ACPR and ECB supervisory review.
- Build the TLPT preparation package required for significant institutions, including the intelligence-led threat scenario documentation regulators examine.
- Structure ICT incident classification and reporting to meet DORA's 4-hour initial notification, 72-hour intermediate, and 1-month final report cycle.
- Manage third-party ICT risk under DORA Articles 28-30 with compliant contracts, criticality assessments, and exit strategy documentation.
- Integrate IT Security and IT Continuity testing evidence into a single programme that holds up under both internal audit and supervisory examination.
The 12 modules
How this addresses your situation
Specific modules that map to what you said you are dealing with.
What you get with this course
- 12 written modules covering DORA ICT risk management, resilience testing design, TLPT preparation, incident classification, and third-party ICT risk.
- Downloadable templates for every module: gap register, ICT asset classification tool, continuity policy structure, incident report formats for each DORA reporting stage, testing register, TLPT preparation brief, and board reporting template.
- The hand-built implementation playbook tailored to IT Security and IT Continuity Officer responsibilities at significant financial institutions.
- Access within 24 hours of purchase through the Art of Service learning environment.
What you will have in hand by Day 1, Week 1, Month 1
Access to all 12 modules within 24 hours of purchase.
Implementation playbook delivered alongside course access, built for IT Security and IT Continuity Officer responsibilities at significant financial institutions.
Before and after
Recovery tests pass technically but cannot be linked to a DORA-compliant testing programme with proportionate scope. BCP documentation satisfies ISO 22301 internally but does not map to DORA Articles 11-12. TLPT preparation is pending because the intelligence-led threat scenario brief has not been drafted. Third-party ICT providers are under review but exit strategies are undocumented.
A testing register maps every exercise to a DORA resilience category and to your ICT risk profile. Continuity documentation satisfies DORA Articles 11-12 scope and review requirements. TLPT preparation package is complete and defensible. Third-party criticality tiers are set, contracts reviewed, and exit strategies drafted for critical ICT providers.
What happens if you do not address this
DORA supervisory examinations focus on testing evidence, not testing activity. An institution that ran tests but cannot produce proportionate scope documentation, threat scenario matrices, and a compliant testing register faces regulatory findings regardless of how well the recovery actually performed. For a significant institution, that means mandatory remediation timelines and potential scrutiny of the broader ICT risk management framework by the national competent authority.
Who it is for
IT Security and IT Continuity Officers at large financial institutions who hold accountability for DORA compliance across both disciplines and need to produce a coherent testing programme, not two parallel ones. Typically responsible for the annual resilience testing plan, TLPT coordination for significant institutions, and ICT risk reporting to senior management. Familiar with ISO 22301 and ISO 27001 but working to map those existing frameworks to DORA's specific requirements without rebuilding from scratch.
How it arrives
Text-based course in the Art of Service learning environment, plus downloadable templates and worked examples for every module, plus the hand-built implementation playbook delivered alongside course access.
Time investment. Each module is designed to complete in 45-60 minutes. The full course takes approximately 10-12 hours. Templates are ready to apply immediately after each module.
Why $199 is the right number
Regulatory consultancies offer DORA gap assessments at engagement rates that exceed this course cost many times over, without leaving your team with the skills to manage subsequent regulatory change cycles independently. Internal programmes built from scratch require months of stakeholder alignment before producing the artefacts this course delivers in weeks. This course gives the IT Security and IT Continuity Officer the methodology to build a compliant programme without external dependency for the next examination cycle.
FAQ
30-day money-back guarantee. If after a week of working through the materials this is not what you needed, reply to the receipt email and a full refund is processed. No questions, no forms.
Within 24 hours your account in the learning environment is provisioned and the tailored implementation playbook is delivered alongside it.