Train yourself and your colleagues
NIS 2 mandates regular training for all staff, including executives. Here is how to structure your cybersecurity training programme.
The training obligation under NIS 2
Article 20 of NIS 2 requires governing bodies to attend training in order to acquire sufficient knowledge of cybersecurity. This knowledge enables them to identify risks and evaluate cyber risk management practices. Entities must also offer similar training to their employees on a regular basis.
Training by profile
Training needs vary by role. Tailor content to each audience.
CISOs & security teams
Deepen your understanding of NIS 2 technical requirements and prepare your organisation for compliance.
- NIS 2 risk analysis
- Incident management and authority notification
- Supply chain security
- Penetration tests and audits
Executives & management
Understand your legal responsibilities and your role in cybersecurity governance.
- Management liability under NIS 2
- Cyber governance and decision-making
- Crisis management and communication
- Reputational and financial risks
All employees
Raise awareness of essential cybersecurity best practices among your entire workforce.
- Phishing and social engineering
- Password management and MFA
- Best practices on mobile devices
- How to report a security incident
Business & IT teams
Integrate cybersecurity into your projects and operational processes.
- Security by design in projects
- Secure development (DevSecOps)
- Identity and access management
- Business continuity and DR/BCP
Building your training plan
4 steps to implement an effective awareness programme.
Map your needs
Identify the profiles to train as a priority (executives, CISO, all staff) and the missing competencies.
Choose the right format
E-learning, in-person, hands-on workshops or serious games — match the format to the audience and your organisation's constraints.
Plan and deploy
Integrate training into the annual training plan. Schedule regular sessions and refreshers.
Measure and improve
Assess training effectiveness (tests, phishing simulations) and adjust the programme every year.
Official resources
Free and reliable resources published by competent authorities.
IT Hygiene Guide
42 fundamental security measures for information systems. Essential reading for technical teams.
SecNumedu — Cybersecurity training
Catalogue of training programmes and educational resources endorsed by ANSSI for professionals.
Cyber Threat Landscape 2023
Annual report on the evolution of the cyber threat landscape, essential for contextualising your risks.
NIS2 Implementation Guide
The European cybersecurity agency's guide to NIS 2 implementation by Member States.
Staff awareness kit
Ready-to-use communication kit to raise your teams' awareness of the most common cyber threats.
Need the NIS 2 vocabulary?
Consult our glossary to master the essential terms before embarking on training.
Browse the NIS2 glossary