NIS 2

The target audience for training
- CISO,
- DSI,
- IT engineers,
- Project managers,
- Security auditors and IT regulatory lawyers, or anyone else involved in the security of their organisation.
What you will learn
At the end of the course, trainees will be able to strengthen the resilience of their organisation's information systems thanks to the NIS2 legislation.
Training programme
- Duration: 2 days
Day 1
Day 1 - Morning: Introduction to the NIS2 directive and its context
- Objectives and challenges of the NIS2 directive.
- Comparison between NIS1 and NIS2: major changes.
- Scope: essential service operators (ESOs), major entities and critical suppliers.
- Role of the competent national authorities and ENISA.
- Case study: analysis of a cybersecurity incident that led to the implementation of NIS2.
- Interactive quiz (30 min) on LMS with group correction to validate and consolidate what has been learnt.
Day 1 - Afternoon: Organisational and technical requirements
- Governance and executive responsibilities: legal obligations and civil/criminal liabilities.
- Implementation of an NIS2-compliant risk management policy.
- Minimum technical measures: access management, logging, incident detection, business continuity .
- e-Hygiene obligations and supply chain security.
- Practical exercise: NIS2 compliance self-diagnosis of a typical organisation.
- Interactive quiz (30 min) on LMS with group correction to validate and consolidate what has been learnt.
Day 2
Day 2 - Morning: Incident management and reporting
- NIS2 incident management process.
- Deadlines and procedures for compulsory notification to the competent authorities (preliminary report, final report).
- Organisation of incident response: internal coordination, crisis communication, relations with partners.
- Link with ISO/IEC 27035 and good incident management practices.
- Case study: analysis of an incident management plan linked to NIS2.
- Interactive quiz (30 min) on LMS with group correction to validate and consolidate what has been learnt.
Day 2 - Afternoon: Compliance and operational integration
- NIS2 compliance stages :
- Initial gap assessment.
- Implementation roadmap.
- Control and compliance audits .
- Relations with service providers: contractual clauses, supervision of critical third parties.
- Finishing and monitoring safety indicators (KRI/KPI).
- Practical exercise: building an NIS2 compliance plan.
- Interactive quiz (30 min) on LMS with group correction to validate and consolidate what has been learnt.
Trainer profile
Expert consultant-trainer in regulatory compliance and digital resilience, whose technical, professional and teaching skills have been rigorously assessed and validated as part of our internal selection procedures.
Teaching methods and resources
The training is based on a balanced combination of theoretical and practical approaches, guaranteeing both the acquisition of knowledge and its rational application:
- Structured theoretical input, illustrated by practical examples and adapted to the participants' professional context.
- Practical exercises at each e-tap to help you assimilate the knowledge.
- Case studies to link the different skill blocks.
- Strong interaction between the trainers and the trainees, making the echanges more concrete and in correlation with the trainees' expectations.
- Full educational documentation, supplied in digital format.
- Course evaluation questionnaire at the end of the course, analysed by our teaching team.
- Certificate of acquired skills sent to the trainee at the end of the course.
- End-of-training certificate sent at the same time as the invoice to the company or funding organisation, confirming that the trainee has fully attended the session.
Training objectives
- Understanding NIS2 legislation
- Integrate the requirements of NIS2 legislation into your organisation.
Assessment method
- Practical exercises at every stage of the course.
- A case study linking the different skill blocks.
- Quiz at the end of each day's training.
- Self-assessment of knowledge acquired by the trainee via a questionnaire.
Training prerequisites
Basic knowledge of cybersecurity and information systems security.
- Language : French
- Level : Fundamental
- Certification body : ACG CYBERACADEMY
- Certification: No
- Accessibility : Yes
- Duration: 2 days
Important information:
Our courses are not registered with the Répertoire National des Certifications Professionnelles (RNCP), but they do comply with the requirements of the Répertoire Spécifique (RS).