Course
digicode: H42685
NIS-2 in Practice: Governance, Implementation, and Crisis Management
Course facts
Download as PDF- Understanding the strategic, legal, and technical requirements of the NIS 2 Directive
- Assessing whether and to what extent your organization is affected
- Developing a structured risk management framework in accordance with Section 30 of the NIS 2 Implementation Act (NIS2UmsuCG)
- Receiving specific checklists and templates for governance, technology, and reporting processes
Day 1 – Strategy, Law, and Governance
1 Introduction and Regulatory Context
- Introduction to the NIS 2 directive and the NIS2UmsuCG
- Distinction from KRITIS and other regulations
- Self-assessment of maturity level to determine current status
- Significance of governance and liability requirements
2 Scope and Obligations (Deep Dive)
- Analysis of the applicability criteria (sectors, size, thresholds)
- Distinction between «essential» and «important» entities
- Key obligations: governance, risk management, reporting, and documentation requirements
- Management liability and sanctions
3 Risk Management and the 10 Core Measures (§ 30)
- Establishing a NIS 2-compliant risk management framework
- Identification of critical services and processes
- Asset management and risk analysis
- Incident and business continuity management
- Vulnerability management, backup strategies, supply chain security
- Cryptography, access controls, and awareness
4 Organization and Governance
- Roles and responsibilities (management, CISO, NIS 2 coordination)
- Integration into existing ISMS and GRC structures
- Handling audits and oversight
- Requirements for executive management and governing bodies
Day 2 – Implementation, Technology, and Practice
1 Technical and Organizational Measures
- «State of the Art»: Attack detection, SIEM, SOC, EDR/XDR
- Monitoring, logging, and incident response
- Zero-trust principles and ransomware prevention
- Cloud and OT security
- Integration with existing security stacks
2 Secure Development and Supply Chain
- Threat modeling and secure architecture
- DevSecOps and SDLC
- Security requirements for service providers and cloud providers
- Contract requirements, SLAs, and auditing
- Vendor management checklists
3 Reporting Requirements and Crisis Management
- Reporting processes and deadlines in accordance with NIS2/NIS2UmsuCG
- Interfaces with the BSI and regulatory authorities
- Establishing internal escalation processes
- Integration with BCM, incident management, and cyber insurance
4 Gap analysis and implementation roadmap
- Analysis of the organization’s maturity level
- Definition of quick wins (0–3 months)
- Medium-term measures (3–12 months)
- Development of a target state and management commitments
The seminar combines structured expert input with hands-on workshops.
You’ll work with templates for risk registers, gap analyses, and roadmaps. Scenario-based exercises and concrete case studies ensure that what you learn can be immediately applied within your organization.
This intensive seminar is aimed at:
- IT security and data protection officers
- Compliance and governance managers
- Executive management and decision-makers
- IT managers and project managers responsible for information security
- Organizations that are classified as NIS 2-relevant entities
There are no formal prerequisites for this course.
We recommend booking at least 14 days before the seminar date so that you can receive any documents by post in good time.