Training

Cybersecurity training for management and staff

NIS2 requires the members of management bodies to follow cybersecurity training, and national laws extend it to staff. We deliver it as practical sessions built on situations from your own work, and leave you the records that show it took place.

Scope and price are confirmed in writing before work starts.

Discuss your case

The benefit for your organisation

  • Management meets the training requirement and has records to show it.
  • Leaders know which questions to ask IT and suppliers and what to decide in an incident.
  • Staff recognise the fraud attempts they actually face in their work.

Two training formats

Management training

A practical half-day session for management: up to 10 participants, on site or online. Includes a realistic scenario exercise, a written record and certificates.

from €1 400half a day

Role-based staff training

Modules matched to people’s work: all staff, finance, front office and records, IT. A programme and schedule for management approval, sessions held and records kept.

by written quotationdepending on headcount and modules

What the law requires

  • NIS2 requires the members of the management bodies of essential and important entities to follow training (Art. 20(2)).
  • The purpose is set in the Directive: sufficient knowledge and skills to identify risks and assess cybersecurity risk-management practices and their impact on the services the entity provides.
  • Entities are encouraged to offer similar training to their employees on a regular basis. National laws can go further: in Bulgaria, for example, management trains every two years and must organise staff training (Art. 21(2)–(3) of the Cybersecurity Act).
  • Neither NIS2 nor most national laws prescribe a format or a licensed provider, so the training has to meet the stated purpose and be documented. We check the national rules that apply to you.

What the management training covers

  • What the law asks of management personally: approving measures, oversight, reporting and accountability.
  • The main risks to your organisation’s services, worked through with your own systems and suppliers rather than generic examples.
  • How to assess the measures: which questions to ask your IT team and supplier, and which evidence to ask for.
  • Incidents: who decides, who reports and within which deadlines.
  • An exercise on a realistic scenario, such as a fraudulent payment request or a key system going down, and decisions under pressure.

What you receive

  • A programme matched to the stated purpose and to your organisation.
  • An attendance record and a certificate of participation for each participant.
  • A written record of the exercise: decisions, owners and next actions.
  • The date of the next training recorded, where national law sets a cycle.

Staff training

We prepare an annual programme and schedule for management to approve, and run 60–90 minute sessions on site or online. Each session ends with a short check of understanding and a record that it took place.

ModuleTopics
All staffSuspicious emails and calls, passwords and multi-factor sign-in, handling personal data and AI tools, and how and to whom to report a problem.
FinanceBank-detail changes, urgent payment requests from “the boss”, second approval and independent verification.
Front office and recordsDocuments and attachments from outside parties, access to registers, file sharing and protecting customer or citizen data.
IT and administratorsAccess and permissions, backups and restore, first steps in an incident, and reporting.

Who delivers it

A cybersecurity specialist from the team leads the legal and technical part; the decisions-under-pressure part is run with a business psychologist. See the team. Sessions are held in English or Bulgarian.

After the training

Training often shows what is still missing. The logical next step is the readiness and evidence pack.

Boundaries

  • The certificate confirms participation. It is not a certification or a licence issued by an authority.
  • Training does not replace the risk-management measures and is not a compliance assessment.
  • We do not run simulated attacks on staff and do not assess individuals.

General information, not a legal opinion.

Discuss your case