DORA training package - Online courses on Digital Operational Resilience Act UK
The Digital Operational Resilience Act (DORA) is an EU regulation requiring the financial sector to adopt a rigorous risk management framework, ensuring resilience across IT, data, and digital operations. In full effect since 17th January 2025, DORA mandates that financial entities and their third-party technology providers align with specific technical standards for robust operational security.
Our DORA training package gives users access to almost 40 courses on cybersecurity and risk management from our off-the-shelf course libraries. These are designed to guide staff through compliance essentials, covering reporting, resilience testing, third-party risk management, and effective information sharing, to maintain regulatory standards and strengthen cybersecurity practices.
About Our DORA Training Package
Our training package gives users access to almost 40 courses on cybersecurity and risk management from our off-the-shelf course libraries.
Comprehensive Training
- From electronic communications and malware to risks in the use of AI, our complete training package provides your staff with the knowledge and tools to protect your organisation. The interactive courses cover topics such as operational risk, security awareness, and device, network, and information security.
- The training is customisable to your needs. You can tailor courses based on your company's specific policies, risk areas, or compliance requirements.
Engaging Content for All Levels
- You can select preferred delivery formats, from micro-learning training to in-depth, express and refresher courses—each concluding with a certificate of completion.
- Our training uses interactive modules and real-world scenarios which have been proven to boost retention and enhance practical knowledge application.
Before working with Skillcast, we were impressed by the promises of quality service. But only once we started working with the Skillcast team did we realise how much that could mean. The team is exceptionally responsive, capable and committed to excellence. They will try new things, and the extremely customisable system means they’re often delivering things way beyond what we originally expected or had set out to achieve. Skillcast has been the ideal partner for our PRIDE journey
Talent Development Business Partner
Kentro
DORA training overview
Assessments
- All courses include assessments to measure knowledge retention and effectiveness.
Reporting
- Comprehensive reporting tools provide detailed diagnostics, highlighting problem areas and specific risks within your organisation.
Track progress
- Monitor your employees' progress through real-time dashboards that track course completion and assessment results.
Feedback
- Customised feedback reports identify knowledge gaps, enabling you to focus future training efforts where they're needed most.
About our learning styles
In-depth
These are our more detailed e-learning courses that include practice scenarios and typically last between 25 and 45 minutes.
Refresher
These targeted courses help reinforce your employees' knowledge and notify them of any updates they might not be aware of.
Express
Our focused training courses deliver employee learning in smaller chunks, typically lasting between 10 and 15 minutes.
Microlearning
These bite-sized animated training videos can be delivered as: standalone, embedded in detailed e-learning courses, or compiled into a learning path.
Operational Resilience
Resilience regulation shifted the question from whether a firm can prevent disruption to whether it can keep serving customers during one. That needs more than the business continuity plan already sitting on the shared drive. Training staff on impact tolerances and service mapping is what turns a board-level commitment into something your operational teams can actually execute under pressure.
Explore the course
Operational Risk
Operational risk frameworks usually fail at the reporting layer, not the design layer, because staff never learned what counts as a risk event worth escalating. A shared way of describing cause and consequence fixes more of that than another policy revision will. This course gives every function the same language, which is what makes aggregated risk data mean something to a board.
Explore the course
Business Continuity Management
Continuity plans are written by a small group and executed by everyone, usually at short notice and under stress. If staff first encounter the plan during an incident, it will not work as designed. Training the wider workforce is what converts documentation into capability, and it supports the resilience expectations that now apply across financial services and beyond.
Explore the course
Information Security Compliance Training Course
Attackers target people because people are reachable, and most incidents begin with an ordinary action rather than a technical failure. For firms in scope of DORA or facing supplier security assessments, evidence of staff-level security training is now requested directly. Delivering it across the workforce gives you both the practical control and the documentation.
Explore the course
Digital Operational Resilience Act (DORA)
DORA is prescriptive in a way earlier resilience guidance was not, with defined requirements for incident reporting, testing and third party oversight, and supervisory consequences for gaps. The obligations reach beyond the technology function into procurement, operations and governance. Training staff across those areas is what allows a firm to demonstrate compliance rather than describe an intention to comply.
Explore the course
Electronic Communications
Business communications are disclosable in litigation and reviewable by regulators, and the informal register people use in chat tools does not read well years later out of context. Recording and retention obligations also extend to channels many staff assume are private. Setting the expectation clearly protects individuals from a message written quickly and protects the firm from having to explain it.
Explore the course
Digital Operational Resilience Act (DORA)
DORA reaches beyond EU-domiciled firms, catching group entities and technology providers that serve in-scope financial institutions wherever they are based. Non-EU organisations frequently discover their obligations through a client contract rather than a regulator. Training staff across technology, procurement and operations gives an international group one standard rather than a patchwork assembled entity by entity.
Explore the course
Cybersecurity Compliance Training Course
Attackers target people because people are reachable and predictable under time pressure. The short format matters here: cyber awareness works best delivered frequently rather than thoroughly once a year, since the techniques change faster than annual training cycles. Running this across the whole workforce gives you a control that scales, and satisfies the staff awareness expectations that appear in client and supplier security assessments.
Explore the course
Information Security
Security behaviour degrades between annual courses, and attackers rely on that. A short refresher keeps classification habits and email caution current without repeating the full course, which makes it practical to run more than once a year. For firms subject to DORA or regular client security assessments, a documented refresher cycle is increasingly what evidence of ongoing awareness actually means.
Explore the course
Records Management
Records are held too long as often as they are destroyed too early, and both create exposure: one under data protection law, the other during litigation or a regulatory request. Retention decisions are made by individuals every day without much thought. Giving the workforce a clear framework means your retention schedule describes what actually happens rather than what was intended.
Explore the course
Cybersecurity
Attackers probe an international group for its weakest point, and inconsistent awareness between locations gives them one. Time zones also mean an incident often starts where nobody senior is awake. Delivering the same standard everywhere shortens the time between something looking wrong and someone reporting it, which is the variable that determines how much damage an intrusion causes.
Explore the course
Phishing
Phishing is how most breaches begin, and the messages have improved enormously with better tooling behind them. The decisive factor is rarely whether someone clicked but how quickly they said so. Training that removes the embarrassment around reporting shortens that gap, and short modules can be repeated often enough to keep pace with techniques that change every few months.
Explore the course
Spot a Phishing Attempt
Phishing emails are fraudulent attempts by cybercriminals to trick individuals into revealing sensitive information. This training helps employees recognise phishing attempts, identify red flags in emails and take steps to protect personal and company data from cyber threats.
Business Email Compromise
Business Email Compromise (BEC) is a targeted cyberattack where criminals impersonate executives or hack accounts to steal money or sensitive information. This training helps employees recognise different types of BEC scams, understand the risks and apply verification steps to prevent fraud.
Deepfake Awareness
Deepfakes use artificial intelligence to create fake images, audio or videos that can deceive individuals and organisations. This training helps employees recognise deepfake scams, understand their risks and apply verification steps to prevent fraud and cybercrime.
Understanding Information Security
Information security is essential to protect sensitive business and customer data from unauthorised access, breaches and cyber threats. This training helps employees understand their role in safeguarding information, following security policies and identifying potential risks.
Common Cyber Threats
Cyber threats such as phishing, malware, ransomware and unsecured networks pose significant risks to businesses. This training helps employees recognise common cyber threats, understand their impact and apply best practices to prevent security breaches.
Zero Trust Cybersecurity
The zero trust cybersecurity model ensures IT systems remain inaccessible by default, requiring strict verification before granting access. This training helps employees understand how zero trust works, including authentication measures, restricted access and continuous security monitoring.
Bring Your Own Device Security
Bring Your Own Device (BYOD) policies offer convenience and flexibility but also introduce cybersecurity risks. This training helps employees understand the precautions necessary to secure personal devices and protect company data from threats like theft, hacking and data breaches.
Device Hygiene
Device hygiene is the practice of keeping digital devices secure and free from cyber threats to protect company data and networks. This training helps employees understand the importance of device hygiene and apply best practices to prevent malware infections, data breaches and unauthorised access.
Malware
Malware is malicious software designed to harm or exploit computer systems, ranging from viruses and ransomware to spyware and botnets. This training helps employees recognise different types of malware, understand how they spread and take proactive steps to prevent infections.
Ransomware
Ransomware is a type of malware that encrypts files and demands payment for their release, often causing severe financial and operational damage. This training helps employees recognise ransomware threats, understand how attacks occur and take preventive measures to protect company systems.
Smishing
Smishing is a targeted phishing scam that uses deceptive text messages to gain sensitive information. This training highlights how to recognise and avoid falling victim to smishing attacks.
Spear Phishing
Spear phishing targets specific individuals with convincing emails designed to deceive them. This training demonstrates how to recognise and handle these targeted phishing attempts.
Video Conferencing
Video conferencing is a vital business tool, but it also presents security and privacy risks if not used correctly. This training helps employees understand best practices for secure video meetings, from using approved software to protecting confidential information.
Vishing
Vishing is a social engineering attack where cybercriminals use phone calls to trick individuals into revealing sensitive information. This training helps employees recognise vishing attempts, understand manipulation tactics and apply best practices to verify callers and protect confidential data.
Creating Strong Passwords
Strong password protection is essential to safeguarding company systems from cyber threats such as brute force attacks and password guessing. This training helps employees understand the importance of creating strong passwords, following security policies and preventing unauthorised access.
Multi-factor Authentication
Multi-factor authentication (MFA) enhances security by requiring users to verify their identity through multiple authentication methods. This training helps employees understand the importance of MFA, how it protects company data and when it should be used.
Reacting to Password Breaches
Password breaches can lead to unauthorised access, fraud and data theft, often resulting from weak passwords, phishing or insecure networks. This training helps employees recognise the warning signs of compromised credentials, understand the risks and apply best practices to prevent breaches.
Information Classification
This training helps employees understand different levels of information classification, their restrictions and how to handle data securely.
Information Security on the Move
Handling company information securely, especially when working remotely or traveling, is essential to prevent data breaches and security risks. This training helps employees understand how to protect sensitive information, secure devices and minimise exposure to cyber and physical threats.
Tailgating and Piggybacking
Cybersecurity is not just about digital protection but also involves securing physical access to critical systems. This training helps employees recognise security risks like tailgating and piggybacking, understand their consequences and take steps to prevent unauthorised access.
Secure Web Browsing
Practicing safe web browsing helps to reduce security risks and protect sensitive information. This training explains how to browse the internet securely and avoid common cyber threats.
Supply Chain Cybersecurity
A company’s cybersecurity is only as strong as its weakest link and supply chain vulnerabilities can expose businesses to major breaches. This training helps employees understand the risks posed by third-party access, the importance of supply chain security and best practices to prevent cyberattacks.
Transferring Information Securely
Securely transferring information is essential to protect sensitive data from breaches, legal risks and business disruptions. This training helps employees understand best practices for secure communication, including encryption, password protection and using secure transfer protocols.
Using Wi-Fi safely
Wi-Fi connectivity offers convenience but also exposes devices and data to security risks if not properly managed. This training helps employees understand Wi-Fi security threats and apply best practices to protect sensitive information when working from home, in the office and on the move.
Advising Customers on Cybersecurity
Cybersecurity is everyone's responsibility, including guiding customers to protect themselves from online threats. This training helps employees understand common cyber risks customers face and how to provide clear, helpful security advice to build trust and prevent fraud.
CEO Fraud
CEO fraud is a type of Business Email Compromise where cybercriminals impersonate executives to trick employees into making payments or sharing confidential information. This training helps employees recognise CEO fraud attempts, understand spoofing tactics and follow verification steps to prevent financial and data loss.
Guide to Secure Remote Working
Remote work provides flexibility but also introduces cybersecurity risks that can compromise company data and systems. This training helps employees understand the security challenges of working from home and apply best practices to protect sensitive information.
Think Before You Click
Clicking on malicious links or attachments is one of the most common ways cybercriminals infect IT systems with malware. This training helps employees recognise suspicious emails, understand the dangers of phishing and ransomware and apply best practices to protect company data.
Information Security Compliance Training Course
null
See the course
Experience compliance made simple with a Skillcast demo
Book your demoDigital Operational Resilience Act (DORA)
null
See the course
Spot a Phishing Attempt
null
Business Email Compromise
null
Deepfake Awareness
null
Understanding Information Security
null
Common Cyber Threats
null
Zero Trust Cybersecurity
null
Bring Your Own Device Security
null
Device Hygiene
null
Malware
null
Ransomware
null
Smishing
null
Spear Phishing
null
Video Conferencing
null
Vishing
null
Creating Strong Passwords
null
Multi-factor Authentication
null
Reacting to Password Breaches
null
Information Classification
null
Information Security on the Move
null
Tailgating and Piggybacking
null
Secure Web Browsing
null
Supply Chain Cybersecurity
null
Transferring Information Securely
null
Using Wi-Fi safely
null
Advising Customers on Cybersecurity
null
CEO Fraud
null
Guide to Secure Remote Working
null
Think Before You Click
null
By the end of the training, users will be able to:
- Understand DORA’s role in managing ICT risks for the EU financial sector.
- Identify key DORA requirements, including third-party risk, resilience testing, and reporting.
- Recognise and respond to cybersecurity threats like phishing and ransomware.
- Apply best practices for operational resilience, including multi-factor authentication, data security, and secure remote work.
- Support regulatory compliance and enhance the organisation’s digital resilience.
Prior to working with Skillcast, we used inflexible systems and our CPD tracking and reporting processes were largely manual, which cost us a lot of time. We value our customers and care about empowering their professional journey. It became clear that a change was needed to honour our commitment to maintaining high standards. We not only found an FCA-focused provider that offers ongoing support in Skillcast but we have improved our processing and reporting standards. Training 360 has been a Godsend!
CE Learning Designer
Commercial Express
Before working with Skillcast, our mandatory and refresher training was a labour intensive process focussed on administration and keeping materials up to date. Now it is a system that delivers 100% compliance with up-to-date and relevant material. It has freed us up as a business to concentrate far more on the learner experience instead of ticking boxes.
Senior Talent and Development Consultant
MS ABS
It’s been a very positive experience for me. The videos make training easier to follow, it's much quicker to learn things, and overall it takes up less of my time. So well done on this new format, it gets a thumbs up from me!
Learner
NORD/LB
See it in practice
Book your DORA training package demo today
With nearly 40 courses included within our Digital Operational Resiliency Training Package, your staff will use a range of course learning styles such as in-depth, refresher, and microlearning to increase knowledge retention and support your DORA compliance targets.
Your questions, answered
DORA