Cybersecurity training for the board and management committees

NIS2 requires cybersecurity training for management bodies; DORA requires the same for the financial sector. A session built for the people who decide budget and carry legal accountability, not for the people who code.

Why a board member does not need the same training as an employee

General awareness training teaches people to recognise a fraudulent email. A board or management committee needs something else: to understand what risk the company is carrying, what legal accountability falls on whoever signs, and what to ask the technical team to know whether the real exposure is covered. Mixing it with workforce training dilutes both — the executive session becomes too basic for the board, or too technical to hold the attention of people who don't code. NIS2 (article 20) and DORA (article 5) treat this as a distinct obligation: they require specific training for the management body, not a shared talk for the whole workforce.

What the session covers

  • Real risk: the kind of incidents companies of the same sector and size suffer, with anonymised cases from our own audits
  • Legal accountability: what personally exposes a director in an incident, and what cyber-risk insurance covers, or does not
  • The NIS2 (article 20) training requirement for the management body
  • The DORA (article 5) training and governance requirement for financial entities
  • What to ask your technical team or cybersecurity provider to know if the current budget covers the real risk
  • How to read a pentest or audit report without needing a technical translation

How we prepare the session

  1. Prior assessment: We understand the sector, the size of the organisation, and whether there are previous audit or incident findings worth bringing into the session, anonymised.
  2. Adaptation to the applicable framework: We adjust the content depending on whether NIS2, DORA, both or neither applies yet, so the session doesn't talk about obligations that don't apply.
  3. 2-3 hour session: On-site or online, with real cases and room for open questions — not a closed slide deck.
  4. Documentation for the auditor: We deliver an attendance record and contents in the format required as evidence for NIS2 article 20 or DORA governance.

What the board receives

  • 2-3 hour session, on-site or online
  • Executive risk summary adapted to the sector
  • Attendance record and contents for the NIS2 or DORA auditor
  • Checklist of questions to evaluate the technical team or provider
  • Recording of the session, where agreed

When this session fits

  • Boards and management committees of companies subject to NIS2 that need to evidence article 20 training
  • Financial entities subject to DORA that need management-body training
  • Leadership teams that need to understand their real exposure to decide cybersecurity budget
  • Companies that have just taken out cyber-risk insurance and want to understand what it covers

Frequently asked questions about leadership training

How much does the session cost?

A 2-3 hour session for the board or management committee, on-site or online, starts from a fixed price per session. It is adjusted by number of attendees and whether it includes extra executive summary material. The first scoping call is free.

Does this count as evidence for NIS2 or DORA?

Yes. NIS2 requires cybersecurity risk management training for management bodies under article 20, and DORA requires something equivalent for the management body of financial entities. We deliver an attendance record and contents in the format an auditor expects to find in the review.

Is this the same as a regulatory compliance gap analysis?

No. A NIS2 or DORA gap analysis assesses whether your controls meet the regulation; this session trains the management body to understand the risk and their accountability. They are complementary services: training usually fits well at the start of a compliance project or right before an audit.

Can the technical team also attend?

The session is built for leadership, but it can open to middle management if the goal is to align criteria before deciding budget. If what you need is in-depth training for the technical team, that is a different session — see our technical training.

Related resources

Request a leadership session