NIS2 Board & Management Training

This training provides a complete overview of the NIS2 Directive and its obligations, aimed specifically at directors and managers.

NIS2 Board & Management Training

NIS2 Board training is essential for successful implementation of your cybersecurity framework and for support within management. The NIS2 Directive is more than just a guide-it is an obligation. The NIS2 Directive states that executives of vital and important organizations-particularly the Board of Directors and CEOs-must have a demonstrated understanding of cybersecurity. In doing so, they demonstrate the ability to make informed decisions that protect the organization, ensure managerial accountability, and maintain stakeholder trust.

For this training we offer a half-day program for participants already somewhat familiar with cybersecurity, and a full-day program for participants not yet experienced with cybersecurity.

NIS2 Board & Management Training (0.5 day)

NIS2 Board Training - Fully informed in one morning

For whom: directors, board members, and managers who already have some experience with cybersecurity
Duration: 0.5 day (09:00 - 12:30)
Number of participants: maximum 8
Includes certificate of participation

 

9:00

Opening, introduction and content training

 

9:15 - 9:45

What is NIS2?

  • Purpose legislation and cybersecurity law
  • Core principles of information security
  • Duty of care and duty of notification
  • Supervision

 

9:45 - 10:00

Coffee Break

 

10:00 - 11:00

NIS2 obligations at a glance

  • Policy and risk management
  • Incident Procedure
  • Business continuity
  • Security in supply chain
  • Securing networks and information systems
  • Cyber hygiene and training
  • Cryptography
  • Mastering personnel
  • Logical and physical access policies
  • Asset management
  • Alerts, advice and information industry associations
  • Evaluation of implemented management measures

 

11:00 - 12:00

Risk management

  • Recognize and analyze risks
  • Identifying consequences of risks.
  • Select and implement risk management measures
  • Evaluate risk management measures

 

12:00 - 12:30

  • Questions, comments and room for exploration
  • Closing

 

NIS2 Board & Management Training (1 day)

NIS2 Training - Fully prepared in one day

For whom: directors, executives and managers with no experience implementing security
Duration: 1 day (09:00 - 17:00)
Number of participants: maximum 15
Includes certificate of participation

 

9:00 - 9:15

Opening, introduction and content training

 

9:15 - 9:45

What is NIS2?

  • Purpose legislation and cybersecurity law
  • Core principles of information security
  • Duty of care and duty of notification
  • Supervision

 

9:45 - 10:00

Coffee Break

 

10:00 - 12:00

NIS2 obligations explained in detail

  • Risk management policies
  • Incident Procedure
  • Business continuity
  • Securing networks and information systems
  • Cyber hygiene and training
  • Cryptography
  • Management of personnel
  • Logical and physical access policies
  • Asset management
  • Alerts, advice and information from industry associations
  • Evaluation of implemented management measures

 

12:00 - 13:00

  • Space for questions, comments and deepening
  • Lunch break

 

13:00 - 14:45

Comprehensive explanation of risk management including practical examples (provided)

  • Recognize and analyze risks
  • Identifying consequences of risks.
  • Select and implement risk management measures
  • Evaluate risk management measures

 

14:45 - 15:00

Coffee Break

 

15:00 - 15:30

How do you get all that done?

  • NIS2 and ISO 27001

 

15:30 - 16:30

Space for questions, comments, deepening and discussion

 

16:00 - 17:00

Afterglow and closing

Compared to the old NIS guideline, NIS2 applies to significantly more organizations. These are characterized by:

  1. Activity in essential and important sectors (see image to the right)
  1. Minimum 50 employees and/or an annual turnover and balance sheet total of at least EUR 10 million

Not sure if NIS2 is applicable to your organization? Please do not hesitate to contact us without obligation.

Remark:
An organization may still be considered essential or important without meeting the size criteria. For example, when it is critical to the social or economic activity of the Netherlands.

Key and essential organizations must complete a verified self-assessment by April 18, 2026.

The deadline for companies to complete their first external audit for NIS2 compliance is set for June 30, 2026.

The European Commission shall review the operation of the NIS2 Directive by Oct. 17, 2027.

We are happy to help you with NIS2. Leave a message to the right and one of our experts will contact you within one business day!

Margo Sportel
Security Consultant

This field is for validation purposes and should be left unchanged.
Name(Required)