A leadership team in discussion around a meeting table

NIS2 Training for Executive Management

In-house, with your risks, with a rehearsed crisis.

The duty sits with the leadership, not with IT

Sec. 38 of the German BSI Act requires the management of important and essential entities to do three things: implement the risk management measures, oversee that implementation, and attend training regularly. These duties cannot be delegated, and the liability is personal. In Austria, the NISG 2026 asks the same of governing bodies, with training designed specifically for them.

We train your leadership team behind closed doors, using your processes, your clients and your scenarios. What you get is not an off-the-shelf certificate, but a leadership team that knows which questions to ask from now on.

Illustration of NIS2 training for executive management
Four people in business attire talking in a bright room

Half a day, closed session

Request the training

Why it matters:

A general seminar explains the directive. It does not answer the question your leadership actually has: where do we stand, and what do we have to decide? So we build the session on your business model and let the room make real decisions.

What you get:

  • Duties, sanctions and personal liability, mapped to the law that applies to you
  • Reporting and registration duties, including the 24-hour early warning
  • The ten minimum measures under Sec. 30 BSIG, each with a question to ask your own organisation
  • Two of your own risks, assessed together and placed on the risk matrix
  • A crisis exercise in three acts, from detection to restart
  • Certificates of attendance and documentation that holds up as evidence
  • A plan with the next six steps for your organisation

Three formats

Set it up properly once, then keep it current every year.

Core training for executive management

Core training

Four to five hours, in one day or two blocks.

  • Duties, liability, sanctions
  • Reporting channels and deadlines
  • The ten minimum measures
  • Risk and crisis exercise
Annual refresher for the leadership level

Annual refresher

Two to three hours, so that "regularly" stays provable.

  • What changed in the law
  • New threats in your own sector
  • Status of the six steps
  • A fresh crisis round
Crisis exercise for the leadership level

Crisis exercise

Half a day of pure incident, for teams that know the basics.

  • Data exfiltration with extortion
  • Decisions under time pressure
  • Reporting, communication, restart
  • Debrief tied back to the measures

One group, three legal regimes

Germany transposed NIS2 into the BSI Act, in force since 6 December 2025. Austria follows with the NISG 2026 from 1 October 2026. Switzerland has no NIS2, but the Information Security Act sets reporting and ISMS duties for critical infrastructure.

If you run companies in several countries, you do not need three separate sessions. We bring the differences into one room and record which duty applies in which entity, and who owns it.

The ODCUS difference

We are practitioners, not a seminar factory. The content comes from live mandates, the scenarios from your core business, and the discussion stays in the room because nobody outside your leadership team is in it. We sell nothing on the side: no tools, no commissions.

What you can show afterwards

Training only counts when it is documented. You get the paperwork for it.

  • A certificate of attendance per person
  • A record with provider, participants and their roles, date, time and duration
  • A content overview mapped to the three competence areas: identify risks, judge measures, assess impact
  • The training materials in digital form
  • The log of the crisis exercise with the decisions taken

Who this fits

  • German companies registered as important or essential entities
  • Austrian companies preparing for the NISG 2026
  • Groups with entities in Germany, Austria and Switzerland
  • Suppliers to regulated clients who have to provide evidence

Who delivers it

  • Yannick Hirt, CISM certified, a trainer on NIS2 and Zero Trust for years
  • Trainer for professional academies and specialist publishers in the German-speaking region
  • From practice: a multi-year CISO mandate, ISMS build-up, ransomware recovery
  • Vendor-independent: we train, we do not sell tools
  • Delivered in German or English
See the reference

Request the training

Tell us briefly who needs the training. We reply within 24 hours with a date and a quote.

Prefer to talk first? Book 30 minutes.

Frequently asked questions

What leadership teams want to know before booking.

How often does executive management have to be trained?

The law says "regularly" and sets no interval. The BSI guidance recommends a thorough initial session followed by regular refreshers. An annual rhythm is common.

Is an e-learning enough?

For ticking a box, perhaps. For the purpose, rarely: your leadership has to assess its own risks and decide in a real incident. A video cannot rehearse that, and it is thin evidence in front of a regulator.

Can the duty be delegated to the CISO?

No. Sec. 38 BSIG addresses management itself, and the liability is personal. The CISO or information security officer supplies the input, management decides.

Does this apply to us as a Swiss company?

Only indirectly. NIS2 applies in the EU. It becomes relevant if you own an EU entity in scope, or if clients demand evidence along the supply chain. In Switzerland itself, the Information Security Act sets the duties.

How many people can take part?

We recommend up to ten. The exercises live on discussion, and discussion gets thin in large rooms.

What does the training cost?

We quote after the intro call. The price depends on the format, the number of participants, how much tailoring your business needs and travel.

In which language is it delivered?

German or English, on site across the German-speaking region or live online.

Talk first, plan second

In 30 minutes we clarify whether your entities are in scope, who belongs in the room and which format fits.

Two men chatting casually over coffee