Course Overview
The Lazarus Group's theft from Bybit in early 2025 demonstrated that North Korean state-sponsored actors now operate as the most prolific financial cybercriminals in the world. Financial institutions simultaneously face threats from nation-state actors blurring espionage and organised crime, AI-powered fraud at unprecedented scale, and increasing regulatory obligations under DORA and sector-specific PRA and FCA requirements.
Over three mentor-led days, participants examine nation-state tactics specific to financial sector targeting, apply DORA resilience requirements to cyber warfare threat scenarios, protect SWIFT network infrastructure and payment rail systems, develop fraud detection approaches for AI-powered financial attacks, and produce a DORA-aligned incident response and regulatory reporting plan.
The programme concludes with a full capstone simulating a nation-state intrusion into a banking network: participants classify the incident under DORA, produce the regulatory notification within the exercise window, and present a board briefing. This course is aligned with DORA, PRA Operational Resilience Policy, FCA guidance, and SWIFT Customer Security Programme mandatory controls.
Hands-On Learning
SWIFT network security control analysis, DORA incident classification practical exercises, fraud detection versus APT detection tool comparison, and a nation-state banking intrusion classification and board briefing capstone.
Mentor-Led Sessions
Practitioner-led analysis of the Bybit Lazarus Group theft, DORA operational resilience compliance mapping, and regulatory notification design with live commentary on the 2026 financial sector APT landscape.
Career-Ready Skills
DORA operational resilience implementation, SWIFT network security, financial sector APT detection, DORA incident classification and regulatory notification, and board-level cyber risk briefing.
Learning Outcomes
Identify nation-state tactics specific to financial sector targeting, including Lazarus Group operations against banking and cryptocurrency infrastructure.
Apply DORA operational resilience requirements to cyber warfare threat scenarios in a financial institution context.
Protect SWIFT network infrastructure and payment rail systems from nation-state intrusion methodologies.
Classify a financial sector cyber incident under DORA and produce a compliant regulatory notification.
Detect and respond to AI-powered financial fraud and APT operations using appropriate tooling combinations.
Present a board-level briefing on a nation-state cyber incident covering impact, regulatory status, and remediation.
Design a DORA-aligned incident response programme for a financial sector organisation.
Prerequisites
Professional experience in financial sector security, fraud risk, technology risk management, or compliance.
Basic understanding of the financial sector regulatory environment including PRA, FCA, and EU regulation.
Familiarity with cybersecurity fundamentals including SIEM, incident response, and threat detection.
Detailed Syllabus
Step-by-step learning journey from basics to professional practice
Topics Covered
- Pre-reading: DORA operational resilience requirements overview and Lazarus Group current profile
- Introduction to SWIFT Customer Security Programme mandatory and advisory control framework
- Accessing course resources and financial sector threat intelligence datasets
- Course objectives, financial security knowledge baseline assessment, and pathway alignment
Skills You'll Gain
Master these in-demand skills through hands-on practice
Career Progression
A clear view of the roles this programme supports, what typically comes next, and where learners progress over time
Ways to Learn
Choose the learning format that works best for you and your team
Live Online
Instructor-Led Training
Join live instructor-led sessions from anywhere. Interactive, engaging, and flexible.
- Live instructor interaction (real-time)
- Trainer-led walkthroughs and real examples
- Guided resources and session notes provided
- Structured Q&A and practical discussion
Price per person
Group enrolments and early planning options available.
All prices are exclusive of VAT where applicable. Group enrolments and custom packages available on request.
Prefer a Faster, Personalised Route into IT?
Not everyone learns best in a group. If you want focused guidance, faster clarity, and confidence you can use on the job, our 1-to-1 Fast-Track Training gives you private, mentor-led support tailored to your experience and goals.
"Many learners choose 1-to-1 when they want understanding, not memorisation."
Exam & Certification Information
Everything you need to know about the certification exams
Important Information
You will receive an Xcademia certificate of completion based on participation and successful completion of labs and scenario simulations.
Credential
Certificate of Completion
On successful completion of Critical Infrastructure Defence: Finance and Banking, learners receive an Xcademia Certificate of Completion. This standalone certificate is issued directly by Xcademia and is aligned with globally recognised frameworks and best practices.
Frequently Asked Questions
Everything you need to know about this course
Financial sector security teams, fraud and risk managers, DORA compliance leads, treasury technology teams, and banking CISOs responsible for operational resilience and security.
Ready to Start Your Learning Journey?
Take the next step in your professional development
