S104
·
Weiterbildung

DORA: IT Risk Management in Banks and Insurance Companies

The Digital Operational Resilience Act has applied directly to banks, insurance companies, and other financial entities since January 2025. You learn about ICT risk management, incident reporting, resilience testing, and third-party risk management.

Risk manager runs an emergency drill at a status screen while a board member and the head of IT discuss
Duration

55 min

Format

Multimodal

Languages

Über 30 Sprachen

Proof

Teilnahmebescheinigung

Challenge

Since January 17, 2025, DORA (Regulation (EU) 2022/2554) has applied directly to credit institutions, insurance companies, investment firms, payment service providers, and other financial entities. The Regulation requires ICT risk management, the reporting of major ICT-related incidents within tight deadlines, regular resilience testing, and strict management of ICT third-party service providers, including a register of information. The management body bears full responsibility and must be demonstrably trained, and supervisors are already reviewing implementation.

Learning objectives
  • You have an overview of the scope, structure, and five pillars of DORA.
  • You understand the requirements for the ICT risk management framework and the responsibility of the management body.
  • You know the classification, reporting deadlines, and reporting content for ICT-related incidents.
  • You know the requirements for digital operational resilience testing, including TLPT.
  • You manage ICT third-party service providers contractually, maintain the register of information, and know the oversight framework for critical providers.
Agenda
00 Fundamentals and scope of DORA
01 ICT risk management and governance
02 Reporting of ICT-related incidents
03 Digital operational resilience testing
04 Management of ICT third-party risk and information sharing
05 Summary
06 Knowledge check incl. certificate of completion
Target group

Executive management, IT, risk, and compliance officers, as well as outsourcing officers in banks, insurance companies, and other financial entities.

Leading organizations trust Bridgly

Logo von Ols
Logo von Ols
Logo von Ols
All training courses on one platform:

Bridgly learning platform

Our platform bundles all training management functions, from planning to reporting, in one place.

Training organization

Define who is trained on which content and when.

Training documentation

See at any time who completed which content and when.

Manage participants

CSV import, learning groups, and access rights in one place.

Automated
reminders

Deadlines and recurring training run automatically.

FAQ

Frequently Asked Questions

Here you will find the most important answers.

Is data protection training for employees mandatory under the GDPR?
Which cyber threats should companies train their employees on?
What are the consequences of missing data protection training in the event of a data breach?
What training obligations arise from NIS-2 and the BSI Act (BSIG)?
How often must data protection and IT security training be repeated?
How does GDPR training for employees differ from the qualification as a data protection officer?
Contact

Train your employees in a legally compliant and verifiable way

Training and professional development for companies and public-sector clients – with audit-proof documentation and a practical focus.

Get in touch now
Eine Hand blättert in einem grauen Ringordner mit Tabellen, dahinter ein aufgeklappter Laptop

Note: Some text, images, and videos on this website were generated using artificial intelligence.
All content is for informational purposes and has been carefully reviewed from a journalistic perspective, but does not claim to be exhaustive or legally binding.