
The duty is quickly explained: executive management has to be trained on cybersecurity. The more interesting question is what should happen during those hours so that something is different afterwards.
Germany's BSI has published guidance on exactly that, updated version of 17 April 2026. It is not legally binding, but it describes what the BSI expects from a session. Anyone buying training or assembling it internally has a checklist. We walk through it here and say which parts carry weight in practice.
One goal above all: being able to implement and oversee
The guidance states an overarching goal, and it is deliberately not "knowledge about cybersecurity". Management has to be able to meet its legal duties to implement the measures and to oversee that implementation. Enablement, not training people into experts.
That gives you a selection rule for every agenda item: does it pay into deciding and overseeing, or is it merely interesting? Most agendas we see carry two or three items too many.
Three core contents, none of them optional
The BSI names three core contents, all following from Sec. 38 (3) BSIG.
- Identifying and assessing risks. Purpose, goals and terms of risk management as a systematic process. How risks are identified, assessed and monitored. The central risk sources, weaknesses and protection needs of your own organisation. The basic terms of assessment, so likelihood, type and scale of damage, risk acceptance. And the insight that risk management is a continuous process, not a project.
- Risk management practices. Nature, purpose and effect of technical and organisational measures, at minimum the ten measures under Sec. 30 (2) BSIG. How measures are selected, prioritised and reviewed, which treatment strategies exist, and that measures have to be documented and justified.
- Judging the impact. Estimating operational, economic and regulatory consequences. Placing cyber risks as business risks. Understanding dependencies between systems, processes and services. And recognising conflicts between security and service delivery, then weighing them.
The guidance adds one sentence that sorts out a lot in practice: focusing only on risk management measures falls short of the legal requirements. Yet that is the usual seminar format, a tour through the ten measures. Without risk assessment before and impact judgement after, half the session is missing.
Supporting content: the frame that places the duties
On top of that comes an overview of the regulation itself. The BSI lists what management should know: the content and goals of the BSIG regulation, the reporting duty and its deadlines for significant incidents, the registration duty including its deadline, their own duty to implement and oversee, the possible liability for culpably caused damage, and the training duty itself.
Optional, in the language of the guidance "can", are the history of national and European legislation and the interaction with other regulations. Both stop being optional in a group with EU entities, because DORA, GDPR and national transpositions sit in the same room there.
The part that separates a session from a webinar
The guidance asks for sector-specific and entity-specific content: a transfer to your own organisation and your own sector, with typical threat scenarios, the central IT-supported business processes, the governance structures and the relevant industry requirements.
This is where a standard course cannot keep up. A slide deck for twenty companies does not know your core processes. The BSI also writes something uncomfortable for providers: external trainers have to take these entity-specific aspects into account, which means more effort.
The other way round, the guidance warns about purely internal sessions and their structural blind spots. Management then learns how processes are implemented, but cannot judge on its own whether they are legally and technically adequate. Contributions from external, independent risk, compliance and legal expertise can therefore be an essential part of effective governance. Coming from a public authority, that is remarkably direct.
Formats: hours of lecturing are not required
Risk management is abstract. So the guidance recommends making the content tangible through example scenarios, interactive exercises or case studies, and it explicitly names formats beyond the classroom:
- Risk management quarterly: a fixed quarterly slot for management with the information security officer, on real questions from the business
- Tabletop exercise or war game: moderated, on typical scenarios, to show the interplay between risks, measures and management decisions
- Audit simulation: recreating an audit situation, for instance to ISO 27001 or as a critical-infrastructure review, with management as participants
- Management red and blue teaming: management plays corporate steering, a second team plays attacker and crisis development
- Case studies and live hacking: showing decisions and mistakes on concrete cases, with live hacking as an add-on rather than the core
Our experience from sessions like these: the quarterly slot is the underrated item on that list. It costs four times two hours a year, keeps the topic inside leadership work, and produces exactly the decision documentation that later serves as evidence.
Interval and duration: no number, but clear triggers
The BSIG sets no requirements on interval or duration beyond the word "regularly". The BSI recommends a thorough initial session followed by regular refreshers, and names four anchors that should drive type, duration and interval:
- A change in executive management
- Significant changes in business processes
- Significant changes in risk exposure
- Significant changes in implemented or planned measures
That is more usable than an annual number. Whoever has a new managing director, migrates an ERP or connects a production line to the network does not need a calendar entry to know the room needs training again.
The evidence is created on the same day
The documentation has to be traceable and meaningful, and according to the guidance contains at minimum: details of the training provider or internal unit, the participants with name and role, date, time and duration of the units, and the content and formats covered with a reference to Sec. 38 (3) BSIG.
Two things about this are regularly misunderstood. First, testing participants is required neither by law nor by the BSI. Second, the documentation only proves attendance, not learning. Learning shows up, per the guidance, in the documentation of decision-making, so in whether management demonstrably takes part in risk management afterwards.
That is the real bar, and it is not cleared on the training day. It is cleared in the three months that follow.
What this means for your agenda
If you are buying a session, test it against four questions. Does it cover all three core contents or only the measures? Is there a transfer to your processes and your sector? Is there a format in which people decide rather than listen? And does the documentation for the record emerge automatically?
How we set this up is on the page for NIS2 training for executive management. What the duty requires legally is in our article on the training duty under Sec. 38 BSIG, and for Austria in NISG 2026 and governing bodies. The guidance itself is available from the BSI.
Frequently asked questions
Which content does the BSI recommend for a management session?
Three core contents: identifying and assessing risks, risk management practices including the minimum measures under Sec. 30 BSIG, and judging the impact. Plus supporting content on the regulation, reporting and registration duties and liability.
Is a session that only covers the ten measures enough?
No. The BSI guidance states explicitly that focusing only on risk management measures falls short of the legal requirements. Risk assessment and impact judgement belong in the session.
Which formats work besides classroom teaching?
The BSI names a quarterly risk management slot with the information security officer, tabletop exercises and war games, audit simulations, management red and blue teaming, case studies, and live hacking as an add-on.




