Digital Operational Resilience Act (DORA) - Introduction

On December 2022, the regulation (EU) 2022/2554 on Digital Operational Resilience for the financial sector was published in the Official Journal of the European Union. Also known as Digital Operational Resilience Act (DORA), the regulation intends to harmonise rules regarding digital resilience in the financial sector across all member states.

This training is about understanding the implications of DORA and how your organisation will be impacted from business, compliance, governance, operational and IT perspectives.

This training will provide you an overview of the main provisions and the difference with the existing Information and Communication Technologies (ICT) regulatory framework.

Price: 410.00 €

Duration: 2h

Language: Available in English and French. The supporting material is only available in English.

Number of participants: up to 20

You are interested in participating in this course but no sessions are currently scheduled? Please contact us and you will be added to our Show Interest list.




By the end of this training, participants will be able to understand:

  • the main provisions of DORA regulation and the implications to your organisation;
  • the implications to the existing ICT regulatory framework;
  • how to manage ICT risks;
  • how to classify and report incidents;
  • the types of resilience testing;
  • the key considerations related to the management of ICT third party service provider.


  • Current regulatory landscape in the context of operational resilience and ICT
  • Main provision of DORA and implementation considerations:
    • ICT governance: definition of the roles, responsibilities and segregation of duties within your organisation
    • ICT risk management framework: risk taxonomy, methodology and related documentation
    • Incident classification, management and reporting
    • Resilience testing approach and scope
    • Third party services provider management: process and related documentation

Target audience

This course essentially (but not only) addresses to:

  • Top management
  • Operations/IT managers
  • Operational risk managers
  • Compliance managers
  • Outsourcing managers
  • Procurement managers
  • Internal auditors

Our lead experts

This training is coordinated by Michael Horvath and Koen Maris, Partners at PwC Luxembourg.

Michael has acquired a strong financial and regulatory audit as well as advisory background and significant experience leading projects in the asset management sphere.

In the recent past, Michael has been particularly involved in various regulatory projects related to the implementation of the EU regulatory framework for sustainable finance (i.e. SFDR, taxonomy regulation, CSRD) at entity and product level. Michael is involved in various other regulatory projects for clients, from DORA, AML/CFT regulation over CSSF circular 18/698 to MICA.

Koen, Partner, leads the Cyber Security practice with more than 20 years of experience in information/cyber security in cross industry environments. He is specialised in Secure Operations Centers, incident response and awareness raising at all levels of an organisation. He also has experience with Distributed Ledger Technology, IoT, OT/IT security, threat intelligence and forensics. He has a strong technical background and operational experience in cyber security as well as strong competencies in security architecture, solution design, programme management, business development.

Contact us

Contact details

PwC's Academy, Crystal Park Building, PwC Luxembourg

Tel: +352 49 48 48 4040

Follow us