NIS2 — Directive and the KSC Act: compliance for management and IT
Practical training on the requirements of the NIS2 Directive and Poland's National Cybersecurity System (KSC) Act for management boards and IT staff: scope of covered entities, incident reporting deadlines of 24h/72h/1 month, and the personal accountability of board members for overseeing cybersecurity.
Why the board and IT must take this path together
The NIS2 Directive shifted the centre of gravity of cybersecurity: it is no longer solely an IT department problem but an oversight obligation of the management body. It is the board that approves risk-management measures, and its members may bear personal accountability for omissions. At the same time, meeting the requirements — from network segmentation to the incident reporting procedure — rests with the IT team. This training connects both levels so that board decisions are executable and IT work has clear authority and priorities.
From legal obligation to action plan
Instead of discussing regulations in isolation from practice, we guide participants through the full path: entity classification, gap analysis against the 10 measures from Article 21 of NIS2, a role map and an implementation timeline. The outcome is a concrete compliance-plan skeleton that the organisation can develop after the training — with a clear division of responsibility between the board, CISO, IT, compliance and ICT suppliers.
Incident reporting that withstands scrutiny
The 24h / 72h / 1 month deadlines look simple on a slide, but in practice they require a decision workflow agreed in advance: who detects, who classifies an incident as significant, who notifies the relevant CSIRT and who approves the final report. During the workshop we build such a workflow for a real organisational structure, so that on the day of an incident you do not improvise but act according to a ready procedure.
Benefits
- Determine whether and as which entity type (essential or important) the organisation falls under the KSC Act implementing NIS2
- Implement incident reporting procedures within the statutory deadlines of 24h / 72h / 1 month
- Understand the scope of personal accountability of board members for overseeing risk management measures
- Translate the 10 minimum risk-management measures from Article 21 of NIS2 into a concrete action plan
Who is this training for?
Prerequisites
- Basic understanding of the company's organisational structure and IT processes
- No technical cybersecurity background is required
Training program
Scope of NIS2 and the KSC Act
- Essential and important sectors from the NIS2 annexes — how to classify your organisation
- Essential vs important entities — differences in supervision and penalties
- Company size thresholds and the entity registration principle
- Relationship between the NIS2 Directive and Poland's KSC Act and implementing acts
Risk-management measures (Article 21 of NIS2)
- The 10 minimum measures: risk-analysis policies, incident handling, business continuity
- Supply-chain security and relationships with ICT suppliers
- Cyber hygiene, staff training and access control
- Cryptography, multi-factor authentication and secured communications
Incident reporting obligations
- Early warning within 24 hours of detecting a significant incident
- Incident notification within 72 hours with an initial assessment
- Final report within 1 month
- The role of the relevant CSIRT and supervisory authority in the reporting process
Board accountability and oversight
- Obligation of the management body to approve and oversee risk-management measures
- Personal accountability of board members and consequences of omissions
- Obligation of regular training for the management team
- Administrative fines: up to EUR 10M or 2% of turnover (essential entities)
Implementation plan for the organisation
- Gap analysis against NIS2/KSC requirements
- Role map: board, CISO, IT, compliance, suppliers
- Timeline and implementation milestones
- Maintaining compliance: audit, review and updating of measures
Delivery Methods
Online
- Convenience of participating from anywhere
- Interactive live sessions with trainer
- Materials available for 30 days
- No travel costs
On-site
- Direct contact with trainer and group
- Intensive hands-on workshops
- Networking with other participants
- Full focus on learning
Frequently asked questions
Does my company fall under NIS2 and the KSC Act?
The obligation applies to essential and important entities operating in the sectors listed in the NIS2 annexes (including energy, transport, banking, financial market infrastructure, healthcare, drinking water and wastewater, digital infrastructure, public administration, space, postal services, waste management, manufacture and distribution of chemicals and food, manufacturing, digital service providers and research). During the training we walk through the sector and company-size criteria to determine your status unambiguously.
What is the difference between an essential and an important entity?
Essential entities are subject to proactive supervision (inspections and audits even without an incident) and higher fines — up to EUR 10M or 2% of global annual turnover. Important entities are subject to reactive supervision (after an incident or evidence of a breach) and fines up to EUR 7M or 1.4% of turnover. Classification depends on the sector and scale of operations.
What are the incident reporting deadlines?
A significant incident requires an early warning to the relevant CSIRT within 24 hours of detection, a full notification with an initial assessment within 72 hours, and a final report within 1 month. During the training we build a ready-to-use reporting workflow tailored to the organisation's structure.
What is the board personally accountable for?
The management body is obliged to approve cybersecurity risk-management measures and oversee their implementation. Board members may bear personal accountability for omissions in this area, and NIS2 also requires them to undergo regular training — which is why this course addresses the board level directly, not just the IT department.
How does this training differ from general NIS2 courses?
We focus on the interface between board decisions and IT execution: we do not merely cover the technical preparation of the organisation, but translate legal obligations into a concrete allocation of roles, an implementation plan and a reporting procedure. It is a compliance path for decision-makers who are personally accountable, supported by practical IT know-how.
Request a quote
Funding Options
Check funding options for your company
Development Services Database
Up to 80% funding for SMEs from EU funds
Check availabilityNational Training Fund
Up to 100% funding for employers
Learn moreTrusted by
We train teams at Poland's largest companies
Interested in this training?
Contact us - we'll prepare an offer tailored to your organization's needs.