Awareness Training
Serious training. Seriously simple.
- Become compliant with the GDPR, NIS2, and more.
- Certificates, documentation, and compliance.
- 60+ high-quality micro-lessons.
GDPR Awareness Training Requirements
- The controller must implement appropriate organisational measures, e.g. awareness training, to ensure and to demonstrate that processing of personal data is performed in compliance with the GDPR.
- Employees must be able to identify when and how they should process personal data in their job.
Quick Facts on the GDPR
GDPR is the most extensive business regulation to come out of the EU in many years.
Businesses must learn how to handle the GDPR efficiently and competently to secure compliance without compromising day-to-day business activities.
What is personal data?
Personal data is any data that can identify a person.
Examples:
- An email can be used to identify a person.
- A telephone number can be used to identify a person.
- An address can be used to identify a person.
- An IP address can be used to identify a person.
- The national ID number can be used to identify a person.
- The passport number can be used to identify a person.
- A credit card number can be used to identify a person.
Data that adds to what we know about a person is personal data:
- Hobbies
- Interests
- Consumption
- Behavioral patterns
- Accent
- Physical characteristics
Most data processed by companies could be considered personal data.
Who is GDPR for?
GDPR for non-EU companies?
Principles of processing personal data
What is a data controller?
What is a data processor?
Do I need a privacy policy?
How do I become GDPR-compliant?
NIS2 Awareness Training Requirements
- A fundamental requirement of the NIS2 is to make sure that all employees have knowledge of best cybersecurity practices and receive proper cybersecurity training.
- Your organisation's management must approve the risk management and cybersecurity measures implemented to comply with the NIS2, and therefore has a central role in cybersecurity governance.
What is NIS2?
Who does NIS2 apply to?
What are the minimum requirements under NIS2?
The minimum requirements of the NIS2 are the following:
- Policies on risk analysis and information system security.
- Incident handling procedures.
- Business continuity planning, including backup management, disaster recovery, and crisis management.
- Supply chain security, covering relationships with direct suppliers and service providers.
- Security in network and information systems acquisition, development, and maintenance, including vulnerability handling and disclosure.
- Policies and procedures to assess the effectiveness of cybersecurity risk management.
- Basic cyber hygiene practices and regular cybersecurity training.
- Policies and procedures for the use of cryptography and encryption.
- Human resources security, access control policies, and asset management.
- Use of secure authentication and communication tools, such as multi-factor or continuous authentication, and secured voice, video, and text communication.
Risk management, leadership and incident reporting
What are the training requirements for leadership under NIS2?
What are the requirements for training of staff?
Why is training so important under NIS2?
What steps should organisations take now to become NIS2-compliant?
- Identify if the organisation is in scope.
- Appoint a person or team responsible for cybersecurity.
- Review current policies and procedures.
- Fill in any security gaps.
- Set up or improve incident reporting and response plans.
- Start regular cybersecurity training.
- Document everything to show compliance.
- Check with your national cybersecurity authority for local guidance.
How does NIS2 overlap with the GDPR?
Quick Facts on the NIS2
NIS2 is an EU directive that requires organisations classified as critical infrastructure to meet specific cybersecurity requirements.
AI Literacy Training
- The AI Act requires organisations to deliver AI literacy training, ensuring employees gain the skills needed to work safely with AI.
- This requirement applies to anyone, whether just using ChatGPT or a data analyst working with machine learning.
Security Frameworks Training
- Train your team on industry-standard security frameworks including ISO 27001, CIS18, and NIST-CSF to strengthen your organisation's security posture.
- Practical awareness training that helps employees understand and apply security controls in their daily work.
Awareness Training Platform
Serious training. Seriously simple.
Free Version