Boardroom Training Cyberbeveiligingswet (Cbw/NIS2)
Duration: 8 hours, per participant on-premise. Max amount of participants: 15
Boardroom Training Cybersecurity Act (Cbw/NIS2)
From legal obligation to executive resilience.
Cybersecurity is an executive responsibility.
The Cybersecurity Act (Cbw/NIS2) explicitly places responsibilities on board members. Consequently, cybersecurity is not solely the responsibility of IT or the CISO. The board must be able to understand cyber risks, assess and approve appropriate measures, and oversee their implementation.
Do you know your key cyber risks? Which risks does your organization accept? Are cybersecurity investments proportionate? Do you have a grip on your critical suppliers? And can you demonstrate to a regulator that you are exercising actual oversight?
The Boardroom Training on the Cybersecurity Act (Cbw/NIS2) translates these obligations into concrete board-level decision-making.
Understand → Assess → Decide → Oversee → Be Accountable
For whom?
- Executive Board and Supervisory Board
- Executives of essential and important entities
- Directors/higher management
The CISO may participate alongside the board. Participation by the CIO, DPO/Privacy Officer, Risk Manager, or other officials supporting the board is also possible.
What does this training offer you?
- Interpreting key obligations under the Cybersecurity Act (Cbw) and NIS2 from an executive perspective
- Understanding your personal responsibility as an executive
- Translating cyber risks into business and continuity risks
- Assessing whether security measures are appropriate and proportionate
- Making decisions regarding cybersecurity investments and risk acceptance
- Overseeing critical suppliers and supply chain risks
- Asking the right questions of the CISO, Security Office, CIO, and management
- Evaluating cybersecurity KPIs, KRIs, and audit results
- Determining when a residual risk requires executive escalation
- Demonstrably fulfilling executive responsibilities
Practical information
- Duration: 2 sessions (8 hours total)
- Format: One full training day or two boardroom sessions
- Recommended group size: 6–12 participants
- Available as an open enrollment course, in-company training, or at one of ID Control’s training locations across the country.
Part 1
Cybersecurity is not an IT issue but an executive responsibility. In this session, executives learn exactly what the Cybersecurity Act and NIS2 require of them, including the implications of personal liability. Through interactive exercises (comparing Executive Board decisions vs. management decisions, investment dilemmas), participants discover how to balance continuity of care, risks, and the duty of care. The focus is not on technical depth, but on asking the right executive questions to gain a grip on digital risks.
Part 2
This part brings the theory to life with a realistic cyber crisis simulation: a ransomware attack directly impacts the EHR and healthcare delivery. Under time pressure, executives make decisions regarding continuity, mandatory reporting, privacy, communication, and ransom payments. In addition, participants work on their own dashboards, governance structures, and concrete action lists for their respective organizations. The result is a practical framework for executive action that can be implemented immediately.
The training is delivered by cybersecurity and information security professionals with proven track records as CISOs. The trainer understands the importance of risk management and digital resilience, ensuring these topics are given greater prominence on the agenda. It helps participants gain a firm grasp of dependencies, with a focus on:
CISO • Cybersecurity • Cbw/NIS2 • Privacy • Governance • Risk Management • Security Auditing • Incident Management • Business Continuity • Responsible AI
This approach allows us to address the Cybersecurity Act through the lens of practical executive risk management.