threat_intelligence1723 wordsRead on Arc Codex

NIS-2: Why practical relevance is crucial in management training

(This text was translated from English into German with the help of AI.) Critical systems fail, customers report problems and the head of IT declares a state of emergency. In the event of a cyberattack, fast and structured action is essential to limit the impact. Management must be prepared for such a scenario, because without an emergency plan, an attack can threaten the very existence of the company. IT security has long been a business-critical factor and is no longer solely the responsibility of the IT department. Under NIS-2, cybersecurity becomes a management responsibility for affected companies: their management bodies must understand risks, make informed decisions and be able to oversee the implementation of appropriate protective measures. In this interview, Mirko Radojicic, Senior Consultant at G DATA CyberDefense, explains how G DATA’s NIS-2 training for management bodies is structured. He also explains why G DATA relies on interactive workshops and real-world attack scenarios, and how experience from incident response engagements is incorporated into the training. Before we get into the topic: What do you do at G DATA? Mirko Radojicic: As a Senior Consultant, I support companies in developing their IT security and implementing regulatory requirements such as NIS-2. This includes NIS-2 gap analyses and security assessments, among other things. Based on the results, we work with the companies to develop concrete measures and support them in implementing those measures. Another part of my work is training members of management bodies. Participants benefit not only from our knowledge of NIS-2, but also from the experience of our Computer Security Incident Response Team (CSIRT). G DATA has been supporting companies during real cyberattacks for many years and assists them as part of incident response engagements. The insights gained from these engagements feed directly into our workshops. From practical experience, we know how attackers operate, which vulnerabilities they exploit and what challenges companies face in a real incident. This knowledge is precisely what helps make abstract NIS-2 requirements tangible and transfer them into day-to-day business using concrete examples. Would you describe NIS-2 as a paradigm shift? Mirko Radojicic: Yes, particularly in terms of responsibility. The decisive change is not simply that affected companies have to implement additional security measures. Cybersecurity explicitly becomes the responsibility of management bodies. It is less a paradigm shift in terms of technical measures than a shift in responsibility. Management bodies of affected companies must ensure that appropriate risk management measures are implemented and oversee their implementation. To do so, they need to be able to assess cyber risks and their potential impact on their own company. This is no longer just about firewalls, updates or antivirus software. The focus is on the resilience of the entire company, crisis management, restoring operations, supply chain security, handling security incidents and the question of whether the measures taken are actually effective. If critical IT systems fail, the entire business operation may come to a standstill in the worst case. That is precisely why management also needs to address cybersecurity. What do management bodies need to understand or do in the context of NIS-2? Mirko Radojicic: Management bodies are not expected to become IT security experts. However, they must be able to assess cyber risks and, on that basis, make understandable and informed decisions. To do this, they need to understand which processes, systems and services are particularly critical to their company, which outages would be manageable and which could jeopardize business operations. It is equally important to consider dependencies on service providers, cloud providers and suppliers, as well as the potential economic and operational consequences of a cyberattack. Management bodies of affected companies are also responsible for ensuring that appropriate risk management measures are implemented and must oversee their implementation. This also includes having the effectiveness of these measures reviewed regularly. In addition, they are required to attend training on a regular basis. Among other things, they should demand answers to the following questions: - What are the key cyber risks our company is exposed to? - How quickly would we detect an attack? - How long can we maintain our most important business processes? - Do we have emergency and recovery plans? - When were these plans last tested under realistic conditions? Why is being technically well positioned not enough for effective cyber defense? Mirko Radojicic: In our experience, many companies are already well positioned technically. The greatest need for improvement often lies not in the technology at all, but in processes, responsibilities and documentation. NIS-2 requires not only appropriate technical protective measures, but also that affected companies assess their individual risks, define clear responsibilities, implement suitable measures and review their effectiveness. Backups are a good example. Many companies back up their data regularly. What matters, however, is whether the data can actually be restored completely and in time in an emergency. That is why, in addition to backup management, NIS-2 explicitly addresses recovery following an emergency and crisis management. The same applies to responsibilities. If a company answers the question of who is responsible for a data backup with, “Whoever happens to be there does it,” that is not enough. Clearly defined roles, transparent processes and robust documentation are required. The processes must also work when individual people are unavailable. Ultimately, technology can only provide effective protection when it is embedded in reliable organizational structures. Why is the workshop format of your training so important? Mirko Radojicic: Our training sessions are deliberately designed as interactive workshops. At the beginning, we explain the regulatory requirements arising from NIS-2 and the BSI Act. My colleague Dr. Matthias Zuchowski provides the fundamental regulatory context. I then explore this further from the perspective of my consulting practice, particularly with regard to risk management and the question of how the requirements can be effectively integrated into existing governance, decision-making and business processes. This combination of sound regulatory context and practical consulting expertise has proven particularly effective in our training sessions. The exchange among participants is at least as important. How often do you get the opportunity to discuss cybersecurity in depth with other members of management bodies? That is exactly why we create a confidential setting. At the outset, we agree that the content of the discussions will not be shared externally. This allows participants to speak openly about their own challenges, ask questions at any time and contribute their experiences. We work with specific questions and discuss possible approaches together. Particularly when management representatives from different companies come together, valuable discussions arise about the challenges they face and how they handle certain situations. We see this open exchange especially at our in-person events on the G DATA Campus in Bochum. The discussion often continues over lunch as well. Different business backgrounds meet similar challenges, and all participants benefit from that. It is important to mention that we also conduct the training online if attending an in-person session in Bochum is not an option. A third option is for us to conduct the training at the company’s own premises. Why do you work with realistic attack scenarios? Mirko Radojicic: Many NIS-2 requirements initially seem very abstract. Terms such as risk management or business continuity are quickly mentioned. But what do they mean in concrete terms for your own company? The real challenge is to translate these regulatory requirements into operational practice. That is precisely why we work with realistic attack scenarios. For example, we start with a Monday morning: employees arrive at the company and can no longer access critical systems. The phone rings, customers report problems and shortly afterwards the head of IT is at the door. From that moment on, we consider the situation together with the participants: What happens now? Who needs to be informed? Who makes which decisions? Which business processes need to be restored first? How does the company communicate with customers and other stakeholders? And what should already have been prepared in advance? An example like this quickly reveals whether responsibilities have been clarified, procedures have been prepared and the right information is available. This makes the NIS-2 requirements tangible and easier to translate into concrete measures for the company itself. How can you recognize good NIS-2 training? Mirko Radojicic: Good NIS-2 training does not merely explain regulatory requirements; it also helps participants apply them to their own company. That is why we tailor our training, among other things, to the industry, business model and critical business processes of the participating companies. At the same time, we place great emphasis on presenting the content in an understandable way, illustrating it with realistic examples and discussing it together. By the end, management bodies should be better able to assess cyber risks, ask the right questions and make informed judgments about which measures are relevant to their company. Good training therefore does more than convey knowledge; it provides concrete guidance for decisions in day-to-day business. What should management bodies take away from a training session? Mirko Radojicic: No company can completely eliminate all cyber risks. The key is therefore to manage risks consciously and be prepared for a real incident. Companies that have clarified responsibilities, created emergency plans and thought through possible scenarios in advance can act much faster and in a more structured way when an incident occurs. That is exactly what NIS-2 is about: not perfection, but appropriate and effective measures that enable affected companies to reduce their risks and strengthen their ability to act. Thank you for the conversation. When will the next G DATA management training session take place? The next G DATA NIS-2 training session for management bodies will take place on October 13, 2026. Afterwards, participants will receive a certificate documenting their participation and the training content covered. To keep their knowledge up to date, management bodies should refresh the training after no more than three years. In the event of significant changes, such as a change in management, new business processes or a changed risk situation, an earlier refresher may be advisable. Anyone who would like to learn about the requirements of the NIS-2 Directive independently of the mandatory training can also find an e-learning course on the cybersecurity directive in the G DATA Academy. Across six modules, the course covers the legal foundations, risk management requirements, and organizational and technical measures under NIS-2. It also addresses reporting obligations for security incidents and regulatory supervision.

How it works

Once you click Generate, Ollama reads this article and crafts 5 comprehension questions. Your answers are graded against the article content — general knowledge won't be enough. Score 70+ to count toward your certificate.

Questions are cached — you'll always get the same 5 for this article.