Our offices will be closed for the holiday season from December 25, 2025, to January 11, 2026. For urgent matters, please contact support@pecb.com.

Our offices will be closed for the holiday season from December 25, 2025, to January 11, 2026. For urgent matters, please contact support@pecb.com.

Our offices will be closed for the holiday season from December 25, 2025, to January 11, 2026. For urgent matters, please contact support@pecb.com.

Digital Operational Resilience Act (DORA) — Training Courses

What Is Digital Operational Resilience?

Digital operational resilience refers to the ability of a financial entity to build, assure, and review its operational integrity and reliability by ensuring, either directly or indirectly through the use of services provided by ICT third-party service providers, the full range of ICT-related capabilities needed to address the security of the network and information systems which a financial entity uses, and which support the continued provision of financial services and their quality, including throughout disruptions.1 

As the financial sector heavily relies on digital technologies, new cyber threats continue to emerge. In response, the European Union has developed the Digital Operational Resilience Act (DORA) to enhance digital operational resilience in the financial sector.

What Is DORA?

DORA is a regulation that requires entities in the financial sector to ensure they can withstand, respond to, and recover from all types of ICT-related incidents, risks, and threats. It was enacted by the European Parliament and the Council of the European Union on December 14, 2022, Regulation (EU) 2022/2554, and seeks to harmonize and streamline regulations related to ICT risk management, ensuring consistency and coherence across the EU. DORA requires financial entities to adhere to the principle of proportionality, which considers their operations’ size, risk profile, and complexity.

DORA sets out the key requirements for financial entities in five main areas:

  1. ICT risk management: Financial entities must establish and maintain an effective ICT risk management framework to effectively identify, classify, and reduce ICT risks.
  2. Incident management: Financial entities must establish effective incident management and a harmonized framework for reporting major ICT-related incidents to regulatory bodies, facilitating a better understanding of emerging threats and enabling coordinated responses.
  3. Digital operational resilience testing: Financial entities must conduct regular testing to assess their capacity to withstand ICT disruptions. This includes vulnerability assessments and penetration testing, with requirements tailored to the entity’s size and risk profile.
  4. Third-party risk management: Recognizing the increasing reliance on third-party service providers, including cloud services, DORA sets out rules for managing ICT risks in the supply chain, ensuring that financial entities have oversight over the resilience of their critical third-party providers.
  5. Information and intelligence sharing: DORA encourages financial entities to share cyber threat intelligence and other relevant information to enhance collective understanding and defense mechanisms against ICT threats.

Why Is DORA Important?

As of January 17, 2025, financial entities will be required to ensure compliance with DORA requirements. Noncompliance with DORA can result in significant penalties, reflecting the seriousness with which the EU views digital operational resilience. While the specific penalties can vary based on the nature and severity of the noncompliance, they are designed to be dissuasive and proportionate.

Organizations must adapt and update their digital operational resilience strategies to keep pace with evolving technologies and threats. This ongoing process involves collaboration across all levels of the organization, from executive leadership to operational staff, as well as with external partners and regulators.

How Do I Get Started?

The PECB Certified DORA Lead Manager training course will help you gain the knowledge and advance the skills in establishing, implementing, and managing an ICT risk management framework based on DORA requirements. PECB experts are eager to guide and assist you throughout the certification process to offer you a worthwhile experience.

1 DORA, Article 3 Definitions 

Need support for your career development?

Download and personalize our request letter to ask your employer for funding.

Explore Issue

Related Course

Cloud Security – Training Course & Certification

 

What is Cloud Security?

Cloud security is a set of strategies and practices used to secure cloud environments, applications, and data. Cloud security ensures the preservation of confidentiality, integrity, availability, and privacy of information hosted in a private, public, community, or hybrid cloud deployment model. It provides multiple levels of security controls in the cloud infrastructure that ensure data protection and business continuity.

Why is Cloud Security important for you?

As the use of cloud computing grows constantly, so does the need to ensure cloud security. Data breaches and other forms of attacks happen mainly as a result of poor security practices, complicated controls, and misconfigurations. This makes cloud security essential to the effective operation of cloud services.

Organizations adopting cloud technology must ensure that the level of security of their cloud systems meets their requirements and complies with the applicable laws and regulations.

Implementing the guidelines of ISO/IEC 27017 helps cloud service providers and customers to establish, implement, and maintain information security controls related to cloud services. ISO/IEC 27017 provides additional guidance in selecting information security controls applicable to cloud services based on risk assessment and other cloud-specific information security requirements.

In addition, cloud service providers that process personally identifiable information (PII) in the cloud can implement the guidelines of ISO/IEC 27018 to meet the requirements of applicable regulations and legislation related to the protection of PII.

The Benefits of Cloud Security Certification

A PECB Cloud Security certificate demonstrates that you possess:

  • A comprehensive understanding of cloud security concepts and principles
  • The ability to identify and assess cloud-specific vulnerabilities and threats
  • Practical knowledge to advise an organization in managing a cloud security program
  • Knowledge on the tools and best practices needed to migrate to the cloud
  • Knowledge needed to respond to and recover from a cloud security incident
  • Skills needed to maintain and improve cloud security

The following are the results of a survey conducted with organizations that use cloud solutions:

How do I get started with Cloud Security Training?

We aim to help you expand your professional knowledge and advance your skills in cloud security. PECB experts are willing to help you with the certification process and with obtaining your PECB Certified Cloud Security Manager credentials.

Contact us to begin with the first step

PECB Certified Cloud Security Training Courses Available

Learn more about cloud security by attending the PECB Certified Lead Cloud Security Manager training course.