Loading Events

« All Events

NIS2 / KSC-inspired Management Awareness Training (in English)

Szkolenie Techniczne

Opis

Audience: CxO, business managers, operations managers, finance, HR, customer service, procurement, compliance, and local and HQ management

Format: Lecture, facilitated discussion, business scenarios, case studies, tabletop workshop and Q&A

Language: English

Data/location: to be agreed

Training purpose:

The objective of the training is to present cybersecurity and NIS2 / KSC compliance as a business, operational and management responsibility, not only as a technical IT topic. The training is designed for CxO and mid-level managers responsible for business processes and focuses on practical cyber risks affecting a business operation. The final scope of training is tailored for the specific client’s needs and sector. The sample scope of the session is described below. 

Expected outcome:

The participants will leave the training with a clear understanding that cybersecurity is part of operational reliability, protection, customer trust and management accountability. The expected final output is a practical set of management commitments covering critical systems, trusted communication channels, verification of high-risk changes, early reporting, evidence preservation, manual fallback, access reviews and supplier awareness. The leaders will understand their legal responsibility for cybersecurity control and KSC (NIS2) implementation and compliance, as well as potential penalties and sanctions. Finally, the management board’s responsibility for maintaining compliance and for incident reporting, auditing, and regulatory controls. 


Agenda

    • Session 1 — Cybersecurity and business risk 
      Duration: 90 minutes
      Format: Lecture with short, facilitated questions 
      This session reframes cybersecurity from an IT issue into a business, operational, cargo and customer-risk topic. Participants will discuss how cyber incidents may affect the business’s digital operating model. The session will also explain NIS2 in business terms, including management accountability, supply chain expectations, and why customers may request evidence of cybersecurity controls. Attention will be given to why companies are attractive to attackers and how attackers exploit urgency, time pressure and operational exceptions. 
    • Session 2 — Managerial responsibilities and practical controls 
      Duration: 90 minutes
      Format: Lecture, examples and short discussions 
      This session translates NIS2/KSC-inspired expectations into practical management controls. Participants will discuss what managers own: critical processes, staff behaviors, secure onboarding/offboarding, acceptable downtime, manual fallback procedures, supplier risks, access to information and escalation of suspicious events. The session will include awareness topics based on KSC Annex 4 point 17: types of cyber threats, basic cyber hygiene, reaction to incidents and awareness of the consequences of breaching security rules. Practical controls will include secure communication rules, two-channel verification for high-risk instructions, incident escalation, business continuity and supplier/customer-related cyber risk. 
    •  Session 3 — Workshops, case studies and Q&A
      Duration: 90 minutes
      Format: Tabletop exercise, group discussion, case studies and Q&A
      Participants will identify the affected business process, first management decision, required escalation, evidence to preserve, communication needs and preventive controls. The session will end with Q&A. 

 

Trainer BIO:

The training is provided by an experienced cybersecurity, IT governance and business resilience professional with over 28 years of training experience and more than 23 years of practical experience in information systems audit, cybersecurity management, IT risk and governance. 

He has spent over 20 years working for leading global technology companies, including IBM, HP, Oracle, SAP and Intel, where he gained extensive experience in enterprise IT environments, infrastructure, business-critical systems, technology operations and cooperation with large corporate customers. The trainer combines a strong technical background with management-level understanding of cybersecurity, making him well positioned to explain cyber risk as a business, operational and governance issue rather than only a technical challenge. His areas of expertise include cybersecurity governance, information systems audit, IT risk management, business continuity, incident readiness, NIS2/KSC-related requirements, ISO 27001, ISO 22301 and ISACA certification domains. 

He is currently an ISACA Warsaw Chapter Board Member responsible for ISACA Certifications. He holds several professional certifications confirming his expertise in information systems audit, cybersecurity governance, information security management, business continuity and AI management systems, including Certified Information Systems Auditor (CISA), Certified Information Security Manager (CISM), ISO/IEC 27001 Lead Auditor Information Security Management Systems, ISO 22301 Lead Auditor Business Continuity Management Systems and ISO/IEC 42001 Lead Auditor AI Management Systems. 

In training delivery, the trainer focuses on practical understanding, management accountability and real-life business scenarios. His approach is particularly suited for managers and non-technical audiences who need to understand how cybersecurity affects business continuity, customer trust, operational reliability, regulatory expectations and supply-chain resilience. 


Miejsce i data