Skip to main content
CYB-0174PractitionerCurrent Intake
X-CWCIF-P

Critical Infrastructure Defence: Finance and Banking

3-Day Instructor-Led Programme

A practitioner programme for financial sector security professionals covering nation-state tactics against banking infrastructure, DORA operational resilience requirements, and advanced financial fraud defence. Develop the skills to protect SWIFT networks and payment systems from Lazarus Group-style APT operations, classify incidents under DORA, and produce regulatory notifications under time pressure.

Duration

3 Days

Price

$3,492

Critical Infrastructure Defence: Finance and Banking
Duration
3 Days
Complete in 3 days
Learning Style
Mentor-led, practical and scenario-based
Guided walkthroughs, real-world examples, and applied skills for the workplace.

Course Overview

The Lazarus Group's theft from Bybit in early 2025 demonstrated that North Korean state-sponsored actors now operate as the most prolific financial cybercriminals in the world. Financial institutions simultaneously face threats from nation-state actors blurring espionage and organised crime, AI-powered fraud at unprecedented scale, and increasing regulatory obligations under DORA and sector-specific PRA and FCA requirements.

Over three mentor-led days, participants examine nation-state tactics specific to financial sector targeting, apply DORA resilience requirements to cyber warfare threat scenarios, protect SWIFT network infrastructure and payment rail systems, develop fraud detection approaches for AI-powered financial attacks, and produce a DORA-aligned incident response and regulatory reporting plan.

The programme concludes with a full capstone simulating a nation-state intrusion into a banking network: participants classify the incident under DORA, produce the regulatory notification within the exercise window, and present a board briefing. This course is aligned with DORA, PRA Operational Resilience Policy, FCA guidance, and SWIFT Customer Security Programme mandatory controls.

Hands-On Learning

SWIFT network security control analysis, DORA incident classification practical exercises, fraud detection versus APT detection tool comparison, and a nation-state banking intrusion classification and board briefing capstone.

Mentor-Led Sessions

Practitioner-led analysis of the Bybit Lazarus Group theft, DORA operational resilience compliance mapping, and regulatory notification design with live commentary on the 2026 financial sector APT landscape.

Career-Ready Skills

DORA operational resilience implementation, SWIFT network security, financial sector APT detection, DORA incident classification and regulatory notification, and board-level cyber risk briefing.

Learning Outcomes

Identify nation-state tactics specific to financial sector targeting, including Lazarus Group operations against banking and cryptocurrency infrastructure.

Apply DORA operational resilience requirements to cyber warfare threat scenarios in a financial institution context.

Protect SWIFT network infrastructure and payment rail systems from nation-state intrusion methodologies.

Classify a financial sector cyber incident under DORA and produce a compliant regulatory notification.

Detect and respond to AI-powered financial fraud and APT operations using appropriate tooling combinations.

Present a board-level briefing on a nation-state cyber incident covering impact, regulatory status, and remediation.

Design a DORA-aligned incident response programme for a financial sector organisation.

Prerequisites

1

Professional experience in financial sector security, fraud risk, technology risk management, or compliance.

2

Basic understanding of the financial sector regulatory environment including PRA, FCA, and EU regulation.

3

Familiarity with cybersecurity fundamentals including SIEM, incident response, and threat detection.

Detailed Syllabus

Step-by-step learning journey from basics to professional practice

Topics Covered

  • Pre-reading: DORA operational resilience requirements overview and Lazarus Group current profile
  • Introduction to SWIFT Customer Security Programme mandatory and advisory control framework
  • Accessing course resources and financial sector threat intelligence datasets
  • Course objectives, financial security knowledge baseline assessment, and pathway alignment

Skills You'll Gain

Master these in-demand skills through hands-on practice

DORA incident classification and notificationSWIFT network security implementationFinancial sector APT detectionAI-powered fraud recognitionRegulatory notification productionInsider threat programme designBoard-level cyber incident briefingPayment system resilience planningDORA compliance gap assessmentFinancial sector threat intelligence

Career Progression

A clear view of the roles this programme supports, what typically comes next, and where learners progress over time

Banking CISOFinancial Security EngineerDORA Compliance LeadFraud Risk ManagerTreasury Technology LeadFinancial Risk Manager
Flexible Delivery Options

Ways to Learn

Choose the learning format that works best for you and your team

Book Now

Live Online

Instructor-Led Training

Join live instructor-led sessions from anywhere. Interactive, engaging, and flexible.

3 Days
Small cohorts
  • Live instructor interaction (real-time)
  • Trainer-led walkthroughs and real examples
  • Guided resources and session notes provided
  • Structured Q&A and practical discussion

Price per person

$3,492+ VAT

Group enrolments and early planning options available.

All prices are exclusive of VAT where applicable. Group enrolments and custom packages available on request.

Premium Training Option

Prefer a Faster, Personalised Route into IT?

Not everyone learns best in a group. If you want focused guidance, faster clarity, and confidence you can use on the job, our 1-to-1 Fast-Track Training gives you private, mentor-led support tailored to your experience and goals.

Personalised Critical Infrastructure Defence: Finance and Banking learning plan
Tailored to your pace and goals
Live 1-to-1 sessions
With an experienced mentor
Real-world troubleshooting
Practice, not just exam theory
Flexible scheduling
To fit around work, study, or family

"Many learners choose 1-to-1 when they want understanding, not memorisation."

Exam & Certification Information

Everything you need to know about the certification exams

Awarding Organisation
Xcademia
Credential Awarded
Certificate Of Completion

Important Information

You will receive an Xcademia certificate of completion based on participation and successful completion of labs and scenario simulations.

Credential

Certificate of Completion

On successful completion of Critical Infrastructure Defence: Finance and Banking, learners receive an Xcademia Certificate of Completion. This standalone certificate is issued directly by Xcademia and is aligned with globally recognised frameworks and best practices.

Frequently Asked Questions

Everything you need to know about this course

Financial sector security teams, fraud and risk managers, DORA compliance leads, treasury technology teams, and banking CISOs responsible for operational resilience and security.

Share:

Ready to Start Your Learning Journey?

Take the next step in your professional development

Digital certificate upon completion
Comprehensive course materials
Expert instructor support
Flexible learning options