Digital Operational Resilience Act (DORA)
-
25 Minutes
-
For all staff
-
UK
The Digital Operational Resilience Act is an EU framework designed to strengthen the cybersecurity and operational resilience of financial institutions. This 25-minute course covers implementing and maintaining a comprehensive ICT risk management framework, participating in risk assessments and mitigation, and understanding the obligations DORA places on financial entities and their technology providers.
DORA is prescriptive in a way earlier resilience guidance was not, with defined requirements for incident reporting, testing and third party oversight, and supervisory consequences for gaps. The obligations reach beyond the technology function into procurement, operations and governance. Training staff across those areas is what allows a firm to demonstrate compliance rather than describe an intention to comply.