Both the NIS 2 Directive and the DORA regulation require formalised incident- and crisis-management arrangements with defined notification deadlines set out in their respective articles. ISO 22361:2022 provides the methodological framework for the crisis cell that responds to both regimes.
The NIS 2 Directive (Article 21) requires essential and important entities to put cyber risk-management measures in place, including incident handling. Article 23 sets the notification obligations: an early warning to the CSIRT or competent authority, followed by a formal incident notification and then a final report, within the deadlines set by the directive.
The DORA regulation (Articles 17 to 23) requires financial entities to maintain an integrated framework for managing ICT-related risk. Notification of major ICT incidents to the competent authorities (ACPR and AMF in France; BaFin in Germany; FINMA in Switzerland for supervised players) follows the deadlines and format defined by the regulatory technical standards (RTS) adopted by the European Commission.
To respond operationally to both regimes, an organisation layers three capabilities: a technical incident-response plan (CSIRT, playbooks, forensics); a strategic crisis cell that activates beyond a severity threshold — this is where ISO 22361 supplies the methodological framework; and an automated regulatory-notification chain to meet the distinct legal deadlines.
The most common operational trap: the technical team manages the incident, but it is the crisis cell that decides what to communicate to regulators, customers and the market. Without formal crisis-management training, that hand-off happens in a panic on the day, with major reputational and legal risk.
Treat notification as a decision, not a task. The clock in NIS 2 and DORA runs during the fog of the incident, so pre-agree who authorises the regulator filing before you ever need it.
This course prepares participants to design, implement, test, and improve an operational resilience management framework. It addresses the growing pressure to maintain critical services through cyber incidents, supplier failures, technology outages, regulatory scrutiny, and physical disruptions. Participants learn how to identify critical business services, set impact tolerances, assess risk, and coordinate response and recovery decisions. Abilene Academy teaches through consultant-led case work, realistic evidence review, and exam-focused coaching built from field practice. It is designed for resilience leaders, risk managers, business continuity professionals, internal consultants, and managers responsible for disruption readiness.
View courseThis course prepares participants to initiate, develop, implement, test, and activate a disaster recovery plan (DRP) for ICT environments. Organizations face growing exposure to natural, human, and technological disruptions that legacy response plans fail to address, leaving recovery teams without tested procedures or clear accountability. Participants work through business impact analysis, risk assessment, recovery strategy design, and post-incident review across four intensive training days. Abilene Academy delivers this training through active consultants who bring operational DRP experience from real incident scenarios, not theoretical frameworks. It targets IT managers, ICT continuity professionals, risk consultants, and DR team members who own or contribute to recovery planning.
View courseThis intensive 4-day training prepares participants to implement and manage a Business Continuity Management System (BCMS) compliant with ISO 22301:2019. It covers planning, deployment, monitoring, updates, and continual improvement, with a focus on context analysis, business impact analysis, risk.
View courseA Lead Crisis Manager builds the crisis-management capability and runs it in a live event. They organise preparation, guide the response, then steer recovery and learning.
The length of crisis management training depends on the level you are aiming for. Awareness for teams runs 1–2 days. The operational Crisis Manager credential — PECB Lead Crisis Manager — runs 5 days, exam included, and is aligned with ISO 22361:2022.
An effective crisis-management framework defines leadership, structure, culture and skills, then tests them through scenarios. It has to make decision-making, information flow and communication explicit.
You will be able to explain crisis management concepts and principles under ISO 22361 and define a crisis management framework integrating leadership, structure, culture, and competence.
Browse all FAQs →
Full knowledge base
Necessary cookies are always active. You can accept, reject non-essential cookies, or customize your preferences.