Skip to content
BIZENIUS.

Digital Operational Resilience & ICT Third-Party Risk

Regulators stopped asking whether you can prevent every incident and started asking what happens when you can’t — resilience is the ability to take the hit and keep serving.

The programme

Europe’s DORA regime has set the template — ICT risk management, resilience testing, incident classification and reporting, and a controlled register of every critical third party — and supervisors across the Gulf, Africa and Asia are issuing parallel rules. This programme builds the working system behind the acronyms: mapping critical business services and setting impact tolerances; the ICT risk framework that connects technology risk to board appetite; scenario-based resilience testing that proves tolerances rather than asserting them; incident response with the classification and reporting clocks regulators now run; and the third-party dimension — concentration risk, exit plans, contract clauses and the register — where most institutions are most exposed. Read as a design specification for any supervised institution, wherever its regulator sits on the adoption curve.

What you will do

Map critical business services and set defensible impact tolerances
Build an ICT risk framework connected to board appetite
Run scenario-based resilience testing that proves tolerances
Operate incident classification and reporting on regulatory clocks
Control third-party ICT risk: concentration, contracts, exit plans, the register

Who attends

Operational-resilience, business-continuity and ICT risk teams; CISOs and technology leaders; outsourcing and vendor managers; compliance and internal audit; executives and board members of banks, insurers and market infrastructures.

Cohorts bring together board members, executives and the rising leaders behind them — kept deliberately small, so every seat is a peer’s.

Programme agenda

Built for the decisions no textbook prepares you for

I.The resilience frame
  • From continuity to resilience: what changed in the supervisory ask
  • Critical business services and impact tolerances that mean something
  • The ICT risk framework and board accountability
II.Proving it
  • Scenario-based testing: severe-but-plausible, run honestly
  • Incident classification, reporting clocks and the communication drill
  • Lessons-learned loops that actually change the estate
III.The third-party exposure
  • The register: every critical ICT provider, mapped and owned
  • Concentration risk, cloud dependency and exit plans that could run
  • Contract clauses, audit rights and the supervisory dialogue

Frequently asked

Who should attend the operational resilience programme?

It serves operational-resilience, business-continuity and ICT risk teams, CISOs and technology leaders, outsourcing and vendor managers, compliance and internal audit, and the executives and board members of banks, insurers and market infrastructures who answer for resilience to their supervisor.

Do we need to be subject to DORA for the course to apply?

No. DORA has set the template, but supervisors across the Gulf, Africa and Asia are issuing parallel rules, and the programme is read as a design specification for any supervised institution, wherever its regulator sits on the adoption curve. It is professional training on building the resilience system, not legal advice on a specific regime.

Can BIZENIUS deliver this in-house and in French?

Yes. The programme runs in English and French, and an in-house edition can be tailored to your critical services, third-party register and supervisory context. Sessions run on a rolling calendar with dates confirmed on request; fees and quotations are provided on enquiry.

Share this programme

LinkedInWhatsAppFacebookEmail

Know the right person for this seat?Nominate a colleague →

In their words

Knowledge transfer, emphasised throughout

“We worked with BIZENIUS for our Fresh Graduates Programme — they are simply amazing. Knowledge transfer and practical learning were emphasised throughout.”

Kuwait Investment Authority

From the Mandate Record

Mandate № 04 · Africa

Capital frameworks built to run the bank, not to satisfy a filing

Most frameworks are written to satisfy the regulator. We build the kind that run the bank.

Open the dossier →

The Capability Arc™

Fix it · Advisory

Advisory & Consultancy

A senior bench across risk, treasury and regulation.

Learning is one point on the Capability Arc. Many institutions pair this programme with the advisory engagement — and automate what the framework demands.

Teams from these institutions train with BIZENIUS

  • Citi
  • Barclays
  • ExxonMobil
  • Total
  • Gazprom
  • Standard Bank
  • QNB
  • Crédit Agricole
  • Nedbank
  • Absa
  • Raiffeisen
  • Halliburton
  • Baker Hughes
  • ConocoPhillips
  • Ooredoo
  • National Bank of Kuwait
  • Kuwait Finance House
  • Bank Muscat
  • Bank Audi
  • SABB
  • Garanti BBVA
  • Ecobank
  • Arab Bank
  • National Bank of Egypt
  • ADIB
  • Access Bank
  • Afreximbank
  • Repsol
  • QNB ALAHLI
  • Stanbic Bank
  • Equity Group Holdings
  • KCB Bank
  • Lombard Odier
  • NOV
  • Weatherford
  • Subsea 7
  • Al Baraka
  • Banque Misr
  • Burgan Bank
  • Bank ABC

BIZENIUS

Speak to an expert

Tell us where you stand — an expert replies within one business day.

Phone *
Area of interest
+ Add a message or details (optional)

We only use your details to respond to your enquiry. See our Privacy Policy.