icon icon

Cybersecurity for managers of essential and important entities – obligations in accordance with Article 8e of the KSC

icon

Training process

Training needs analysis

If you have specific requirements regarding the training programme, we will carry out a training needs analysis for you. This will guide us on which aspects of the programme should receive greater emphasis, so that the training programme meets your specific needs.

What will you gain?

icon

Article 8e duties - You will understand your duties as a manager of an essential or important entity under Article 8e of the KSC Act, making it easier to assign accountability and avoid costly gaps.

icon

Turning rules into action - You will learn how to translate KSC requirements into concrete organizational decisions, documentation, and oversight activities instead of relying on vague statements or intent.

icon

Security oversight - You will improve how you oversee cybersecurity in your organization by knowing what to expect from IT teams, security staff, and external providers supporting key services.

icon

Entity priorities - You will structure the areas that need management attention most, including risk, business continuity, incidents, and critical assets, so your decisions become more focused and timely.

icon

Incident readiness - You will understand your role in incident response and which management decisions matter most in a crisis, before a technical issue escalates into service disruption or reputational damage.

icon

Stronger compliance - You will gain a practical view of how to prepare your organization to meet legal, audit, and supervisory expectations without building unnecessary procedures detached from reality.

icon

Informed management decisions - You will make cybersecurity decisions based on legal duties and actual risk, rather than depending only on technical recommendations presented without business context.

icon

Shared language with experts - You will communicate more effectively with security, IT, and compliance specialists because you will understand the key terms, roles, and expectations tied to KSC obligations.

Training programme

1. KSC and NIS2 – new obligations of essential and important entities

  • the most important assumptions of the NIS2 Directive and the amended Act on the National Cybersecurity System,
  • essential entity and important entity – who the new requirements apply to,
  • principles for identifying the organization's status,
  • obligations related to entry and updating data in the register of essential and important entities,
  • change of data and loss of the status of an essential or important entity,
  • deadlines for fulfilling obligations arising from the KSC,
  • the role of competent authorities for cybersecurity and CSIRT.

2. Responsibility of the manager of a key or important entity

  • the manager's responsibility for the implementation of cybersecurity obligations,
  • the scope of responsibility of members of collective bodies,
  • the possibility of entrusting part of the obligations to other persons and the manager's responsibility,
  • the most important obligations of the manager resulting from Art. 8d KSC,
  • making decisions regarding cybersecurity,
  • supervision over the organization's implementation of obligations,
  • ensuring the organization's compliance with KSC and internal regulations,
  • the consequences of failure to perform obligations.

3. Information security management system – obligations of the organization and the manager

  • obligation to implement an information security management system,
  • identification of systems, processes and resources essential for the provision of services,
  • defining responsibility for cybersecurity,
  • cybersecurity risk management,
  • selection of adequate technical, operational and organizational measures,
  • documenting security principles and procedures,
  • monitoring the effectiveness of the applied safeguards,
  • periodic review and improvement of the security system.

4. Cybersecurity risk management

  • identification of threats and vulnerabilities,
  • assessment of the probability and effects of threats occurring,
  • determining the level of acceptable risk,
  • making decisions regarding the method of dealing with risk,
  • security of infrastructure, networks and information systems,
  • vulnerability and update management,
  • access security and identity management,
  • multifactor authentication and permission control,
  • encryption and protection of data and information.

5. Supply chain security and cooperation with suppliers

  • risks resulting from cooperation with technology and service suppliers,
  • cybersecurity in the procurement process,
  • assessment of suppliers and service providers,
  • security requirements in contracts,
  • supervision of external entities,
  • security of ICT services and services provided by third parties,
  • responding to incidents occurring on the suppliers' side.

6. Organization of cybersecurity and staff responsibility

  • assignment of tasks in the field of cybersecurity,
  • defining roles, responsibilities and authorizations,
  • supervising the implementation of assigned tasks,
  • requirements for persons carrying out tasks in the field of information systems security,
  • verification of persons allowed to perform specific tasks,
  • ensuring staff competence and awareness,
  • internal cybersecurity regulations,
  • building a security culture in the organization.

7. Resource planning and cybersecurity financing

  • the manager's responsibility for ensuring adequate resources,
  • planning adequate financial resources for the implementation of KSC obligations,
  • determining priorities for security investments,
  • making decisions in a situation of a limited budget,
  • the relationship between the level of risk and expenditure on cybersecurity,
  • documenting management decisions.

8. Contemporary threats and real attack scenarios

  • current cybersecurity threat landscape,
  • phishing and spear phishing,
  • ransomware,
  • user account takeover,
  • supply chain attacks,
  • social engineering and user manipulation,
  • the most common organizational and technical errors,
  • the impact of a cybersecurity incident on the organization's operations.

9. Workshop – analysis of a real cyberattack scenario

  • analysis of a phishing message,
  • identification of attack symptoms,
  • user account takeover scenario,
  • course of a sample ransomware attack,
  • analysis of the attack vector and its escalation,
  • determining potential business consequences,
  • decisions that the organization's manager should make,
  • actions of the organization in the first hours after detecting the incident.

10. Handling and reporting incidents in accordance with the KSC

  • organization of the incident handling process,
  • identification and classification of the incident,
  • division of responsibilities during incident handling,
  • obligations related to incident reporting,
  • deadlines and stages of reporting,
  • scope of information provided in reports,
  • cooperation with the competent CSIRT,
  • updating information concerning the incident,
  • final report and post-incident actions,
  • documenting the course of the incident.

11. Crisis management and business continuity

  • ensuring the continuity of the organization's operations,
  • business continuity and disaster recovery plans,
  • backups and data recovery,
  • response to failures and large-scale incidents,
  • internal and external communication in a crisis situation,
  • management roles in a major incident situation,
  • decision-making under time pressure,
  • conclusions and corrective actions after the incident.

12. Information obligations and cooperation with users and authorities

  • information obligations resulting from the KSC,
  • informing about cyber threats and incidents,
  • communication with service recipients,
  • cooperation with the authority competent for cybersecurity,
  • cooperation with the competent CSIRTs,
  • preparing the organization for an inspection or summons from the authority,
  • ensuring the availability of the required documentation and information.

13. Audits, control and documentation of compliance

  • preparation of the organization for control of the implementation of KSC obligations,
  • the role of documentation in demonstrating compliance,
  • reviews and assessment of the effectiveness of the safeguards applied,
  • obligations related to the security audit,
  • identification of non-conformities and planning of corrective actions,
  • supervision of the implementation of recommendations,
  • reporting the state of cybersecurity to the management.

14. ISO 27001 and the system approach to security

  • basic assumptions of ISO 27001,
  • the relationship between the information security management system and the requirements of the KSC,
  • risk management based on the system approach,
  • roles, procedures, policies and security controls,
  • continuous improvement of the cybersecurity system.

15. Cybersecurity and the use of AI

  • main risks related to the use of AI and LLMs,
  • protection of data provided to AI tools,
  • information leaks and uncontrolled use of data,
  • prompt injection and other AI-related threats,
  • use of AI by cybercriminals,
  • deepfake and new forms of social engineering,
  • rules for the safe use of AI tools by employees,
  • AI governance in the organization,
  • basic assumptions of ISO 42001.

16. Workshop for the manager – assessment of the organization's readiness to meet KSC requirements

  • analysis of a sample organization in terms of KSC obligations,
  • identification of the most important organizational and technical gaps,
  • definition of the responsibility of the manager and persons carrying out tasks,
  • identification of key risks,
  • definition of actions requiring priority implementation,
  • creation of a list of corrective actions,
  • determination of priorities and responsibilities.

17. Checklist of the manager of a key or important entity

  • what decisions the manager should make,
  • what tasks should be formally assigned,
  • what procedures and documents should function in the organization,
  • what information should reach the management,
  • what activities should be regularly supervised,
  • what obligations concern incident reporting,
  • how to document the fulfillment of obligations,
  • how to prepare the organization for an audit or inspection,
  • the most important actions to implement after the training.

What are the prerequisites for participating in the training?

icon

Management role - You should understand the scope of your managerial responsibility and how decisions are made in your organization so you can relate KSC duties to real leadership tasks.

icon

Cybersecurity basics - You should be familiar with core terms such as incident, risk, vulnerability, and business continuity so you can follow the discussed duties and management decisions with ease.

icon

Knowledge of your organization - You should know your organization’s main processes, services, and assets so you can properly assess which areas may fall under heightened requirements and oversight.

icon

Compliance awareness - You should have basic awareness of regulatory or control requirements affecting your organization so you can better understand the importance of obligations under the KSC Act.