Training
Cyber hygiene and risk for management
Cybersecurity risk as a matter of decision, not a technical subject.
Objective
What this training is for
NIS2 holds company leadership directly accountable. The management body must approve risk management measures, oversee their application and ensure regular training, for itself and for employees. These are obligations that cannot be delegated outside management.
This training exists so those decisions are made on the basis of information rather than instinct. It treats cybersecurity risk in the language management already thinks in: what can stop the company, what being stopped costs, what has to be decided now and what can wait.
It is not a session about the law. It is a session about your company, with its own risk on the table.
What is covered
- Cybersecurity risk in management language
- Cyber hygiene: the minimum that prevents most incidents
- What management actually has to approve and oversee
- When it goes wrong: who decides, who communicates and within what deadlines
What you are left with
- A clear reading of the company's real risk and of the gaps still to be decided
- Criteria to tell what is urgent from what can wait
- A participation record, which serves as evidence of the training control
Frequently asked questions
About this training
Does management really need cybersecurity training?
Yes, and it is not a recommendation. Decree-Law 125/2025 determines that the management body ensures regular cybersecurity training for itself and for employees. It is an obligation of management, alongside approving risk management measures and overseeing their application.
Do we need any IT background?
No. The session is designed for people who decide, not for people who configure systems. There is no untranslated technical jargon, and the subject is handled in terms of business impact, cost and decision.
Are three hours enough?
They are enough for what this training sets out to do, which is to give management decision criteria and a reading of its own risk. They are not enough to train whoever will implement the controls, and that is what the technical training is for.
Does the training replace a compliance diagnosis?
No. The training prepares management to decide; the diagnosis maps the company control by control. They work well together, and the session gains a great deal when there is already a diagnosis to discuss.
The other courses
For the other levels of the company
Want this training for your team?
State how many people you have and you get a fixed written quote, with no commitment.