Course Description
NIS2 raises the cybersecurity floor for essential and important entities across energy, transport, water, health and digital infrastructure — and it reaches organisations providing services in the EU regardless of where they are headquartered. It requires registration, risk management measures, incident reporting on tight deadlines, supply chain security, and — explicitly — cybersecurity training.
This course develops NIS2 capability for infrastructure operators. Participants learn the Directive's scope and entity classification, governance and management accountability, the required risk management measures, incident reporting deadlines and thresholds, supply chain security obligations, business continuity requirements, supervision and enforcement, and the relationship to the Cyber Resilience Act, CER and sector rules.
What you will achieve
By the end of this training course, participants will be able to:
- Determine whether an entity falls within NIS2 scope and its classification
- Explain governance and management accountability requirements
- Implement the required cybersecurity risk management measures
- Apply incident reporting deadlines and thresholds
- Address supply chain security obligations
- Meet business continuity and crisis management requirements
- Understand supervision, audit and enforcement
- Relate NIS2 to CRA, CER and sector-specific rules
How the course is delivered
The course combines the NIS2 framework with practical scoping, measure selection and incident reporting exercises for infrastructure operators. Participants work through classification, gap analysis and reporting scenarios.
The programme is oriented to operators of physical infrastructure — energy, utilities, transport — where IT and OT converge and where cyber incidents produce physical consequences.
Designed for
This training course is ideal for:
- Cybersecurity and IT leaders in energy, transport and utilities
- Risk and compliance professionals
- OT and industrial control system managers
- Executives accountable for cyber risk
- Anyone in scope of NIS2
Daily programme
- NIS2 objectives and structure
- Essential and important entities
- Extraterritorial reach and registration
- Governance and management accountability
- Cybersecurity risk management measures
- Supply chain security
- Incident reporting: thresholds and deadlines
- Business continuity and crisis management
- Supervision, audit and enforcement
- Penalties
- Relationship to CRA, CER and sector rules
- Gap analysis workshop
Certification & accreditation
BII Certificate of Completion
BII Certificate of Completion Upon successful completion, participants receive a BII Development Institute Certificate of Completion with a unique reference code that is independently verifiable. Our certificates are recognised internationally and reflect successful completion of your chosen programme.