Tabletop exercise
DORA (EU 2022/2554) tabletop exercise
Financial-sector ICT resilience: testing, third-party risk, major-incident reporting.
We can run the DORA (EU 2022/2554) exercise for your team, or set you up as a facilitator to run it yourself.
What the room works through
EU Digital Operational Resilience Act (2022/2554) ICT risk requirements
EU financial entity (bank, insurer, payment institution, investment firm) and its critical ICT providers. Use article refs such as Art.5-14, Art.17-20, Art.24-26, Art.28-30 and domains Governance, Risk management, Incident management, Reporting, Testing, Third party risk. Emphasise the register of information, concentration risk, exit strategies and threat-led penetration testing.
- Clauses
- 22
- Rounds
- 10 across two stages
- Room size
- Up to 20 participants
Stage 1 — assess
Tables rate control maturity, agree the risk that matters for the room, then face an audit round where a peer table challenges the call. Every decision is logged against a DORA (EU 2022/2554) clause.
Stage 2 — survive
Incidents and complications hit the tables: crisis injects, budget cuts and a concealed insider. Controls bought in Stage 1 pay out — or the gap shows.
What you take away
- Clause-by-clause coverage across DORA (EU 2022/2554)
- A gap list ranked by what the room could not defend
- Per-table divergence, so you can see where opinion split
- Word and CSV exports plus a drafted findings narrative
New to facilitating? Start with the facilitator manual or read the session walkthrough.