A focused course, tailored for you
DORA ICT Risk Management for Bank Security Officers
Build the ICT risk register and governance artefacts that KNF examiners sign off on, not send back.
Your ICT risk register passes internal review and still comes back from the KNF examiner with the same annotation. The problem is not effort, it is knowing which specific artefacts a Polish banking supervisor expects to see, in what form, with what evidence trail behind them.
Includes a hand-built implementation playbook delivered alongside course access, generated for your specific situation.
Why this course
DORA's ICT Risk Management Framework requirement (Article 6) is clear in principle and ambiguous in practice. The European Banking Authority technical standards define a structure. KNF applies that structure through supervisory expectations shaped by Polish banking law and the KNF Recommendation on ICT and IT Environment Security. A Security Officer at a banking subsidiary sits at the intersection of three layers: the group security policy from the parent entity, the EBA RTS on ICT risk management, and the KNF examiner's actual checklist. These three do not produce the same artefact. Group policy documents are too abstract for KNF. EBA templates are too generic. The result is a risk register that satisfies none of them fully, and the Security Officer is the person who has to reconcile all three before the next supervisory visit.
What you walk away with
- Produce an ICT risk register that satisfies both EBA RTS structure and KNF supervisory expectations in a single document.
- Build a threat scenario library anchored to the EBA TIBER-EU taxonomy and aligned to the specific asset categories KNF examiners check.
- Draft a TLPT scope document that passes the pre-engagement review without a request for clarification.
- Establish an ICT incident classification register with the severity matrix and escalation criteria KNF expects to see tested.
- Create the governance trail that links risk identification, treatment decisions, and monitoring evidence into one reviewable package.
- Reduce the ICT Risk Management Framework review cycle from multiple revision rounds to a first-pass approval.
The 12 modules
How this addresses your situation
Specific modules that map to what you said you are dealing with.
What you get with this course
- 12 written modules, each producing a completed artefact rather than a framework concept.
- Downloadable templates: ICT risk register, threat scenario library, TLPT scope document, incident classification register, vendor risk register, governance trail index, annual review workflow.
- Hand-built implementation playbook tailored to a banking subsidiary Security Officer operating under KNF supervision and group CISO reporting.
- Access in the Art of Service learning environment, available at your own pace.
What you will have in hand by Day 1, Week 1, Month 1
Within 24 hours your account in the learning environment is provisioned and the tailored implementation playbook is delivered alongside it.
Before and after
The ICT risk register passes internal review and comes back from KNF with annotations. You redraft, re-circulate, and submit again. Each cycle costs three to four weeks and leaves the underlying artefact structure unchanged.
You submit a risk register with the governance trail, monitoring evidence, and treatment rationale in the form KNF examiners look for. The first-pass approval rate improves. The examination visit has a preparation brief behind it.
What happens if you do not address this
The next KNF supervisory visit will check the same artefacts. If the ICT risk register structure has not changed, the same annotations will come back. A repeated finding in the same area triggers an escalated supervisory response under KNF's ICT examination methodology.
Who it is for
Security Officers and IT Security Managers at commercial banks and financial institutions operating under KNF supervision who are responsible for DORA ICT Risk Management Framework implementation. Typically 5-12 years in security roles, carrying a personal signature on the ICT risk register, and accountable to both a group CISO and a local regulatory compliance team.
How it arrives
Text-based course in the Art of Service learning environment, plus downloadable templates and worked examples for every module, plus the hand-built implementation playbook delivered alongside course access.
Time investment. Each module is designed to complete in one focused session. The full course runs across 12 sessions. Most Security Officers work through the modules most relevant to their immediate examination priority first, then complete the remainder over the following weeks.
Why $199 is the right number
EBA and KNF publish guidance documents, but they describe requirements rather than produce artefacts. Consulting engagements address the same gap but at a cost that is 20 to 50 times higher and on a timeline set by the consultant's schedule. This course produces the artefacts in your own environment at your own pace.
FAQ
30-day money-back guarantee. If after a week of working through the materials this is not what you needed, reply to the receipt email and a full refund is processed. No questions, no forms.
Within 24 hours your account in the learning environment is provisioned and the tailored implementation playbook is delivered alongside it.