DoraTraining 1705318836
DoraTraining 1705318836
DoraTraining 1705318836
DORA Training
Courses for
Organisations
and Specialist
Consultants
Our expertise, your professional development
www.itgovernance.co.uk
Andy Johnston
Global Head of Training, IT Governance
The new freedoms of our digital lifestyles come at cost. DORA sets higher standards for safeguarding digital
products and services in the financial sector and its supply chain. It is raising expectations about how to defend
against cyber threats and what it means to respond appropriately. DORA aims to secure the information
highways that link financial hubs and digital supply chains for faster intelligence and risk containment.
Your role in this network is vital. Job roles are evolving to incorporate DORA, and our training courses enable you adapt skilfully so you
can play a valuable part and grow from new career opportunities. We value continual growth and peer interaction. We aim to help you
understand DORA’s impact on your organisation and learn the skills to excel in your role, helping to create a secure digital economy for all.
DORA is an EU regulation that touches organisations everywhere. It was developed to fortify financial services infrastructure, improve
business continuity and mitigate cyber security threats. It recognises that risk extends across the digital supply chain. Companies must
identify and ensure compliance with DORA’s requirements. Finance firms lead the change and will exert pressure on their suppliers
worldwide, who will also need to adapt alongside them. Training will help all those involved anticipate and prepare for new ways of working.
In an era of open banking and financial innovation, DORA safeguards our digital freedoms, and fosters accountability and collaboration.
DORA may be a new regulation but to our experts it is a logical development of existing standards and regulations. In all areas of IT
Governance and across our sister companies in the GRC International Group, you will find products and services that will help you
understand, implement and maintain DORA-compliant practices, slotting them in with your business-as-usual processes.
DORA
DIGITAL OPERATIONAL RESILIENCE ACT
Financial services organisations operating in the EU need to attain and maintain compliance with DORA. To achieve this, they need to
demonstrate that the software, hardware and IT services companies that supply them are also meeting minimum standards, and follow
prescribed procedures and undergo regular testing themselves in order to maintain digital operational resilience.
No matter where ICT third-party companies operate from, if they supply products or services to in-scope financial entities in the EU, they
will be affected. The ripple effect of DORA will be felt worldwide, prompting an increased demand for qualified and experienced cyber
security professionals, auditors and consultants.
Banking & central banking Insurance & reinsurance Public & statutory authorities
Lending (Re)insurance intermediaries EBA
Crypto-asset issuing (Re)insurance ancillaries EU Joint Committee
Asset referenced tokens ESMA
Account information services Admins benchmarks & indicies
Payment networks Investments & investment funds IT services, e.g. web services
eMoney Pensions Telecoms / network services
Crowdfunding Trade & securities repositories IT softwawre, hardware & SaaS
Credit rating Trade counterparties Statutory auditors and audit firms
Currency exchanges Securities depositories
Risk-based insight for leaders with For those designing and monitoring Those designing and managing systems
accountability for maintaining information security, data privacy and to ensure business continuity and
compliance cyber security disaster recovery
Strong working knowledge to Fact finding and performing gap Supporting where changes to contract
motivate cross-functional teams on analysis to guide project planning and terms are required or in relation to
implementation projects prioritisation risks, breaches and remediation
Detailed understanding of the Analysing risk up and down the supply Involved in supplier sourcing, due
requirements relevant to the risk chain for commercial stability and diligence and contract management as
appetite and size of the organisation continuity well as contract termination
The transition period for DORA ends on 17 January 2025, and while financial sector organisations are directly affected by the impending
deadline, the changes they initiate will be felt all along the supply chain.
Contracts and service level agreements are coming under scrutiny, processes for sharing information about risk are being laid down and
new expectations are being set for proactive cyber security testing.
High quality ISO/IEC 17024:2012-certified qualifications help you see the bigger picture and identify the opportunities, not just the
challenge of achieving compliance.
DORA IMPLEMENTATION
Economic and sectoral knock-on effects: Loss of trust and reputational damage:
Fines and the remediation costs of breaches can impair the Cyber security incidents and compliance failures cause widespread
organisation’s delivery of services to customers and payment to bad press across mainstream and social media. Bad news travels
suppliers, affecting the welfare of multiple organisations and their fast, but it can take a long time for a business to come back from a
employees. loss of trust among its customers, investors and other stakeholders.
Our IBITGQ certified DORA training courses are structured to give a good grounding in the principles underpinning DORA so you appreciate
how to work with it in your role, allowing you to participate in the conversation.
The Foundation course creates a shared understanding of what DORA is, what it means and why it presents an opportunity, not just a
compliance challenge.
Specialist training courses enable you to progress your learning and become instrumental in establishing DORA-compliant ways of working.
There are courses to support a range of roles in the cross-functional teams that will implement DORA, and then manage and maintain it as it
transitions into business as usual.
Mastery of DORA principles for those in DORA related roles • Project managers & teams
DORA • Cyber security specialists
PRACTITIONER • Rapidly upskill implementation team members • Compliance teams
• Give technical specialists a shared language and context for new • Operational risk managers
28
responsibilities • Contract managers
• Demonstrate a commitment to professional development • ICT company directors
C-DORA P • Deepen your understanding of digital operational resilience • Consultants and legal advisers
More choice
We want you to learn, qualify and progress, and we are committed to providing learning options for all scenarios: deadline-driven, career-
oriented, company-wide or interest-led.
Our qualified instructors are seasoned practitioners who enrich Our outstanding course material and the extra practical
the learning experience by sharing their real-world insights. exercises, tools and support make your home learning enjoyable,
digestible and actionable in your work life.
A blend of self-paced and instructor-led learning is proven to As an alternative to booking staff on public courses, we can run
deliver the best outcomes for professionals. training courses solely for your employees, adding material or
elements relevant to your organisation.
We are passionate about helping people develop careers using their knowledge of governance, risk and compliance. Our courses are
designed so you can pass exams first time, qualify for new roles and excel in fulfilling them.
Expedite your DORA implementation by training key project team members. Then you can start planning and building your frameworks
while training other key members of the implementation team as well as those who will be involved in the ongoing maintenance.
To succeed in senior management, a breadth of knowledge is needed, covering general management skills and best practice that is being
implemented within the organisational ecosystem. Our DORA pathways and other career pathways allow you to progress in cyber security,
audit or compliance.
Higher professional
• CIO, CTO CYBER SECURITY FOR qualifications e.g. CISSP,
DORA • CISO, CSO
MANAGERS PATHWAY CEH, CISM and options
PRACTITIONER for aspiring CISOs
• Programme Manager Foundation level
• Legal Adviser
CPD OPTIONS ISO qualifications in compatible
C-DORA P • Cyber Security Manager ISO/IEC frameworks and
• Network Architect
FRAMEWORKS
Financial Regulations
Foundation level
DORA CPD OPTIONS ISO qualifications in compatible
• Compliance Manager
COMPLIANCE • Compliance Officer
FRAMEWORKS ISO/IEC frameworks and
OFFICER • ISMS Manager
Financial Regulations
7 7 14 14 14
CIS F CIS-LI PIMS LI CIS CCS CIS CPS
A comprehensive A three-day, accredited This practitioner-led Become equipped to Build the knowledge and
introduction to the practitioner-led course course equips you to implement cloud security skills required to
critical elements that equips you to implement an controls, assess risks, implement and audit ISO
involved in achieving support your ISO 27701 PIMS and ensure compliance and 27018:2019 controls to
compliance with ISO/IEC organisation in planning, extend an ISO 27001 ISMS effectively secure ensure the security of
27001:2022. implementing, managing to deliver an cloud-based personally identifiable
and monitoring. ISO 27701 PIMS, ensure environments. information (PII) in cloud
compliance with the UK services. Essential for
GDPR and Data organisations acting as
Protection Act (DPA) PII controllers.
2018.
Broaden your knowledge, enhance your skills and earn CPD points
Use the CPD points to maintain professional Earn CPD points by
EARN CPD POINTS AS YOU LEARN EARN AS YOU WATCH
These certifications in adjacent fields and disciplines add important risk, incident response and business continuity skills to aidattending
compliance
7 qualifications and memberships or to validate our free
with DORA. All CPD points earned can be used to qualifications
your maintain professional memberships and validate qualifications with certifyingwebinars
bodies.
CERTIFIED
CYBER CERTIFIED ISO
CERTIFIED ISO CERTIFIED ISO CERTIFIED ISO
INCIDENT 22301 BCMS
27005 RISK 22301 BCMS 22301 BCMS
RESPONSE LEAD
MANAGEMENT FOUNDATION LEAD AUDITOR
MANAGEMENT IMPLEMENTER
FOUNDATION
21 7 7 35 21
CIS RM CIRM F CBC F CBC LA CBC LI
A hands-on course A one-day course, This one-day Focused on the practical A 3-day course geared
imparting the skills to covering the principles of introductory course skills needed to plan ana towards scoping,
perform risk incident response and covers the concepts and execute audits of planning and managing a
assessments in line with business continuity and terminology of business business continuity BCMS in line with ISO
the ISO 27005 standard the three phases of the continuity and the main management systems 22301, including
to complement your ISO CREST incident response processes e.g. business and report and follow up evaluating and improving
27001 practice. process. impact analysis, risk in line with performance and
assessment and incident ISO 22301:2019 preparing for an audit.
response.
Chris Stephen
‘It’s the second course I have taken with IT Governance ‘Comprehensive, in-depth, plenty of context, great
and one of the things I love about the onsite training learning materials and take-away information and links
facility is the excellent learning guides they provide. for future reference. The trainer continually ensured
This means you do not have to take notes and can fully we all had a positive training course experience. Really
concentrate on the course following the materials.’ enjoyed – Highly recommended.’
Maria Lisa
We value our corporate partnerships and are dedicated to delivering exceptional training solutions that help you maintain and improve your
organisation’s cyber defence and compliance capabilities. Corporate partners can enjoy significant discounts and exclusive benefits, along
with the added reassurance of our expert consultants, on stand-by to help you meet audit deadlines or address specific challenges.
• The annual IT Governance spend will be calculated from April to March for each financial year, and the benefits will be effective from the
new financial year.
• To qualify for a particular tier, the minimum annual IT Governance spend thresholds must be met.
• Exam resits are subject to specific terms and conditions outlined in our agreement.
IT Governance is a leading global provider of cyber risk and data privacy management solutions.
We deliver projects all over the world, across the spectrum of cyber security and resilience, data privacy, incident response and business
continuity. Our unique and unrivalled blend of products and services includes bespoke and fixed-price consultancy, training, toolkits,
software, staff awareness elearning and penetration testing.
We take pride in serving an international customer base, delivering high-quality solutions globally. Our deep industry expertise and focus
on real-world needs enable us to address the unique challenges faced by financial services organisations.
Our credentials
IT Governance is proud of its long-standing commitment to quality in the services we provide and in the processes we use to deliver those
services. We strive for excellence in all aspects of business and believe that both continuing education and professional certifications help
us to better meet our clients’ needs. IT Governance is a member of The GRC International Group of companies.
IT Governance delivers a unique and unrivalled portfolio of training courses and examinations leading to ISO 17024-accredited
qualifications awarded by IBITGQ (International Board for IT Governance Qualifications), BCS Professional Certification, ISACA®, EC-Council,
PeopleCert and Microsoft(R).