
NIS2 training for executive and senior management
Executive management knows its NIS2 duties, treats cyber risks as business risks and rehearses the emergency.
On behalf of a German professional training academy, ODCUS trained the executive and senior management of a service provider to the insurance industry. With NIS2 transposed into German law, cybersecurity is a leadership matter: management must be trained regularly and is personally liable.
Starting point
The company falls under the new German BSI Act and at the same time sits in the supply chain of regulated insurers. Under Section 38 BSIG, executive management must implement the risk management measures, oversee their implementation and attend training. These duties cannot be delegated to IT or the CISO.
Approach
- Content tailored to the business model: its own core processes, clients and scenarios instead of textbook examples
- Block 1: duties and personal liability, sanctions, reporting and registration obligations, identifying and assessing risks
- Block 2: the 10 minimum measures under Section 30 BSIG, each with a guiding question for the organisation and typical answers that call for follow-up
- Group exercise: place two real risks from the core business on the risk matrix and decide how to treat them
- Tabletop exercise in three acts: data exfiltration with extortion, from the first two hours to the restart
- Industry context covered: DORA requirements of insurer clients, GDPR and the EU AI Act
Result
- Executive management that knows its duties under Section 38 BSIG and the requirements for documenting the training
- A clear split of roles: executive management decides on risks, not on technology
- Rehearsed decisions for an emergency, including the 24-hour deadline for the early warning to the BSI
- A plan with six next steps, from registration status and criteria for significant incidents to a quarterly report with the ISO
Frameworks and tools used
NIS2BSIGBSI training guidanceDORAGDPR