Skip to content

NIS2 — Directive and the KSC Act: compliance for management and IT

Practical training on the requirements of the NIS2 Directive and Poland's National Cybersecurity System (KSC) Act for management boards and IT staff: scope of covered entities, incident reporting deadlines of 24h/72h/1 month, and the personal accountability of board members for overseeing cybersecurity.

Why the board and IT must take this path together

The NIS2 Directive shifted the centre of gravity of cybersecurity: it is no longer solely an IT department problem but an oversight obligation of the management body. It is the board that approves risk-management measures, and its members may bear personal accountability for omissions. At the same time, meeting the requirements — from network segmentation to the incident reporting procedure — rests with the IT team. This training connects both levels so that board decisions are executable and IT work has clear authority and priorities.

Instead of discussing regulations in isolation from practice, we guide participants through the full path: entity classification, gap analysis against the 10 measures from Article 21 of NIS2, a role map and an implementation timeline. The outcome is a concrete compliance-plan skeleton that the organisation can develop after the training — with a clear division of responsibility between the board, CISO, IT, compliance and ICT suppliers.

Incident reporting that withstands scrutiny

The 24h / 72h / 1 month deadlines look simple on a slide, but in practice they require a decision workflow agreed in advance: who detects, who classifies an incident as significant, who notifies the relevant CSIRT and who approves the final report. During the workshop we build such a workflow for a real organisational structure, so that on the day of an incident you do not improvise but act according to a ready procedure.

Benefits

  • Determine whether and as which entity type (essential or important) the organisation falls under the KSC Act implementing NIS2
  • Implement incident reporting procedures within the statutory deadlines of 24h / 72h / 1 month
  • Understand the scope of personal accountability of board members for overseeing risk management measures
  • Translate the 10 minimum risk-management measures from Article 21 of NIS2 into a concrete action plan

Who is this training for?

Board members of companies classified as essential or important entities
IT directors, CISOs and information security managers
Professionals responsible for regulatory compliance and risk management
IT staff preparing the organisation to implement NIS2/KSC requirements

Prerequisites

  • Basic understanding of the company's organisational structure and IT processes
  • No technical cybersecurity background is required

Training program

01

Scope of NIS2 and the KSC Act

  • Essential and important sectors from the NIS2 annexes — how to classify your organisation
  • Essential vs important entities — differences in supervision and penalties
  • Company size thresholds and the entity registration principle
  • Relationship between the NIS2 Directive and Poland's KSC Act and implementing acts
02

Risk-management measures (Article 21 of NIS2)

  • The 10 minimum measures: risk-analysis policies, incident handling, business continuity
  • Supply-chain security and relationships with ICT suppliers
  • Cyber hygiene, staff training and access control
  • Cryptography, multi-factor authentication and secured communications
03

Incident reporting obligations

  • Early warning within 24 hours of detecting a significant incident
  • Incident notification within 72 hours with an initial assessment
  • Final report within 1 month
  • The role of the relevant CSIRT and supervisory authority in the reporting process
04

Board accountability and oversight

  • Obligation of the management body to approve and oversee risk-management measures
  • Personal accountability of board members and consequences of omissions
  • Obligation of regular training for the management team
  • Administrative fines: up to EUR 10M or 2% of turnover (essential entities)
05

Implementation plan for the organisation

  • Gap analysis against NIS2/KSC requirements
  • Role map: board, CISO, IT, compliance, suppliers
  • Timeline and implementation milestones
  • Maintaining compliance: audit, review and updating of measures

Delivery Methods

Online

  • Convenience of participating from anywhere
  • Interactive live sessions with trainer
  • Materials available for 30 days
  • No travel costs

On-site

  • Direct contact with trainer and group
  • Intensive hands-on workshops
  • Networking with other participants
  • Full focus on learning

Frequently asked questions

Does my company fall under NIS2 and the KSC Act?

The obligation applies to essential and important entities operating in the sectors listed in the NIS2 annexes (including energy, transport, banking, financial market infrastructure, healthcare, drinking water and wastewater, digital infrastructure, public administration, space, postal services, waste management, manufacture and distribution of chemicals and food, manufacturing, digital service providers and research). During the training we walk through the sector and company-size criteria to determine your status unambiguously.

What is the difference between an essential and an important entity?

Essential entities are subject to proactive supervision (inspections and audits even without an incident) and higher fines — up to EUR 10M or 2% of global annual turnover. Important entities are subject to reactive supervision (after an incident or evidence of a breach) and fines up to EUR 7M or 1.4% of turnover. Classification depends on the sector and scale of operations.

What are the incident reporting deadlines?

A significant incident requires an early warning to the relevant CSIRT within 24 hours of detection, a full notification with an initial assessment within 72 hours, and a final report within 1 month. During the training we build a ready-to-use reporting workflow tailored to the organisation's structure.

What is the board personally accountable for?

The management body is obliged to approve cybersecurity risk-management measures and oversee their implementation. Board members may bear personal accountability for omissions in this area, and NIS2 also requires them to undergo regular training — which is why this course addresses the board level directly, not just the IT department.

How does this training differ from general NIS2 courses?

We focus on the interface between board decisions and IT execution: we do not merely cover the technical preparation of the organisation, but translate legal obligations into a concrete allocation of roles, an implementation plan and a reporting procedure. It is a compliance path for decision-makers who are personally accountable, supported by practical IT know-how.

Patrycja Petkowska
Patrycja Petkowska Opiekun szkolenia

Request a quote

Funding Options

Check funding options for your company

Up to 80%

Development Services Database

Up to 80% funding for SMEs from EU funds

Check availability
Up to 100%

National Training Fund

Up to 100% funding for employers

Learn more

Trusted by

We train teams at Poland's largest companies

ING Bank - EITT client
mBank - EITT client
PKO Bank Polski - EITT client
PZU - EITT client
Allianz - EITT client
T-Mobile - EITT client
KGHM - EITT client
PGE - EITT client
IKEA - EITT client
InPost - EITT client
Leroy Merlin - EITT client
ZUS - EITT client

Interested in this training?

Contact us - we'll prepare an offer tailored to your organization's needs.

500+ experts
2500+ trainings available
ISO 9001 quality certified
Request Training
Call us +48 22 487 84 90