Digital Risk Management and Business Continuity Training Course

Manage digital dependency and build continuity that holds, from dependency mapping and ISO 22301 planning to recovery objectives and long-term resilience.

25 dates in 15 cities · Sep 2026 – Jun 2027

Zurich

Fees: 6600
From:
To:

Dubai

Fees: 4700
From:
To:

Istanbul

Fees: 4700
From:
To:

Kuala Lumpur

Fees: 4700
From:
To:

Zurich

Fees: 6600
From:
To:

Manama

Fees: 4700
From:
To:

Singapore

Fees: 5900
From:
To:

Brussels

Fees: 5900
From:
To:

Kuala Lumpur

Fees: 4700
From:
To:
See all 25 dates & locations
15 cities · filter by city or month

Course overview

Digital risk is no longer a technology topic. When an enterprise resource planning system is unavailable, a manufacturer cannot ship. When a payments provider fails, a retailer cannot take money. When a ransomware event encrypts a hospital's records, clinical care changes that morning. The exposure is operational, financial and sometimes physical, and it is created by dependencies that were adopted for good business reasons and never risk-assessed as a whole.

This course covers the digital risk picture and the continuity response together, because separating them is what leaves organizations with a technically accurate risk register and a recovery plan that has never been tested. It works through the threat and dependency landscape, assessment frameworks, business continuity planning, integration with enterprise risk management, and long-term resilience. Reference points include ISO 22301 for business continuity, ISO 27001 for information security management, and the NIST Cybersecurity Framework.

Why continuity plans fail on the day

Usually for mundane reasons. The recovery time objective was set by the business at four hours, and the technology team built for twenty-four. The contact list is out of date. The plan assumes the primary site is unavailable, and the actual event made the data unusable at every site simultaneously. The third-party provider's own recovery arrangements were never examined, and their contract commits to nothing.

Regulatory attention has followed. Operational resilience expectations in financial services and critical infrastructure now ask organizations to identify important business services, set impact tolerances, map the dependencies behind each service, and prove through testing that they can stay within tolerance during severe disruption. That is a much harder standard than having a plan on file.

What you will be able to do afterwards

By the end of the course, participants will be able to:

  • Map digital dependencies behind critical services, including third parties
  • Assess digital risk using recognized frameworks
  • Conduct a business impact analysis and set achievable recovery objectives
  • Build continuity and recovery plans with workable workarounds
  • Integrate continuity into enterprise risk management and board reporting
  • Test arrangements through scenario exercises and close the gaps

Course outline

Unit 1: Digital risk landscape and enterprise vulnerabilities

  • Sources: cyber attack, failure, data corruption, outages
  • Dependency mapping and single points of failure
  • Concentration risk in cloud and platform providers
  • Human factor: privileged access, phishing, insider risk

Unit 2: Frameworks for risk assessment and management

  • NIST Cybersecurity Framework functions
  • ISO 27001 controls and residual risk
  • Third-party risk: due diligence, exit, audit rights
  • Quantifying digital exposure and its limits

Unit 3: Business continuity planning essentials

  • Business impact analysis: MTD, RTO, and RPO
  • ISO 22301 business continuity management
  • Recovery strategies and manual workarounds
  • Incident response and crisis coordination

Unit 4: Integrating continuity into enterprise risk management

  • Digital and continuity risk in the enterprise register
  • Impact tolerances and operational resilience
  • Board reporting on exposure and tested recovery
  • Investment cases made before the incident

Unit 5: Building long-term organizational resilience

  • Tabletop testing of severe-but-plausible scenarios
  • Maintaining plans through change and turnover
  • Learning from incidents and near misses
  • Resilience culture and blame-free escalation

How the course is delivered

The course uses documented incidents, published outage reports, dependency maps and continuity plans as material for analysis and discussion. Worked examples take a business impact analysis through to recovery objectives that the technology arrangements can meet. Scenario testing is done as structured tabletop discussion, not as a technical exercise: there is no live system environment. The course is educational and does not certify participants or assess any organization's resilience. Those who want the wider enterprise view should look at Enterprise Risk Management Strategies.

Who should attend

  • Business continuity and resilience managers.
  • Risk and compliance professionals responsible for digital and operational risk.
  • IT managers and service owners accountable for recovery capability.
  • Operations and business leaders who own the services that must keep running.

About EuroQuest International Training

EuroQuest International Training was founded in 2015 by a team with more than 25 years of experience in professional development. We run over 1,000 courses and have trained more than 15,000 participants. Our head office is in Bratislava, Slovakia, with delivery hubs in Dubai, London, Barcelona, Istanbul, Vienna, Paris and Geneva. Courses are developed and reviewed by practitioners from the fields they teach.

Frequently asked questions

Is this a technical cybersecurity course?

No. It treats cyber attack as one source of digital disruption among several, and stays at the level of risk, dependency and recovery. Security controls are discussed as risk treatments, not configured.

Does the course include a live lab?

No. There is no technical environment. Testing is covered through structured tabletop discussion of documented scenarios.

Will the course certify our business continuity management system?

No. Certification against ISO 22301 is performed by certification bodies. This course is educational, does not certify participants, and does not assess your organization's arrangements.

Related courses

Register for this course

Choose a city and date from the schedule above and register, or contact EuroQuest about in-house delivery for a continuity, risk or technology team.

All Course Dates & Locations

25 dates · 15 cities · Sep 2026 – Jun 2027

September - 2026
October - 2026
November - 2026
December - 2026
January - 2027
February - 2027
March - 2027
April - 2027
May - 2027
June - 2027
July - 2027
August - 2027
Amman
Amsterdam
Barcelona
Brussels
Budapest
Cairo
Dubai
Istanbul
Jakarta
Kuala Lumpur
London
Manama
Singapore
Vienna
Zurich
Showing 25 of 25 dates

Zurich

Fees: 6600
From:
To:

Dubai

Fees: 4700
From:
To:

Istanbul

Fees: 4700
From:
To:

Kuala Lumpur

Fees: 4700
From:
To:

Zurich

Fees: 6600
From:
To:

Manama

Fees: 4700
From:
To:

Singapore

Fees: 5900
From:
To:

Brussels

Fees: 5900
From:
To:

Kuala Lumpur

Fees: 4700
From:
To:

Budapest

Fees: 5900
From:
To:

Zurich

Fees: 6600
From:
To:

London

Fees: 5900
From:
To:

Singapore

Fees: 5900
From:
To:

Brussels

Fees: 5900
From:
To:

Barcelona

Fees: 5900
From:
To:

Vienna

Fees: 5900
From:
To:

Singapore

Fees: 5900
From:
To:

Amsterdam

Fees: 5900
From:
To:

Istanbul

Fees: 4700
From:
To:

Cairo

Fees: 4700
From:
To:

Budapest

Fees: 5900
From:
To:

Amman

Fees: 4700
From:
To:

Barcelona

Fees: 5900
From:
To:

Jakarta

Fees: 5900
From:
To:

Amsterdam

Fees: 5900
From:
To: