NIS2 for Boardrooms EN
Boardroom training on NIS2 and the Dutch Cybersecurity Act, focused on board responsibility, governance, risk steering and crisis management.
At a glance
- Provider
- Provided directly by ICT Improve
- Trainer
- Experienced specialist from our own team
- Training type
- Classroom
- Duration
- 1 day
- Language
- English
- Enrolment
- Individual
- Themes
- Security, Regulatory
After this training, you will be able to:
- Understand and explain the impact of NIS2 and the Dutch Cybersecurity Act (Cyberbeveiligingswet, CBW) at board level
- Address the explicit responsibility and liability of the board and individual board members
- Position cybersecurity effectively within governance, strategy and risk management
- Assess cyber risks in relation to business continuity and societal impact
- Demonstrably fulfil and steer the duty of care
- Fulfil the board’s role effectively during incidents and crises
- Translate supervision, reporting obligations and compliance requirements into board-level decision-making
- Provide direction on supplier and supply chain risks
- Collaborate effectively with CISO, risk, IT and compliance without getting lost in operational detail
Course outline
Introduction and boardroom context
- Why cybersecurity is a boardroom topic
- The changing role of the board and supervision
Impact of NIS2 and the Dutch Cybersecurity Act
- Governance and accountability
- Duty of care and board liability
- Scope and classification of organisations
Threat landscape
- Development of threats, including state actors, cybercrime and supply chain attacks
- Impact on the organisation and society
- Supply chain dependencies and geopolitical forces
Risk management at board level
- Definition of risk: threat × exposure × impact
- Risk appetite and risk tolerance
- Prioritising risks in relation to business objectives
- Governance and responsibilities
Supply chain and duty of care
- Supply chain responsibility as a legal obligation
- Risks related to suppliers and MSP environments
- Contractual and board-level assurance
Incident management and reporting obligations
- NIS2 reporting timelines: 24 hours, 72 hours and final report
- Role of the board during incidents
- Steering the crisis organisation
Crisis management in the boardroom
- Gold-Silver-Bronze model
- Nose in, fingers out principle
- Decision-making under pressure
- Crisis communication