Bottom line: 29,500 German companies are required to train their executives in cybersecurity and document these trainings.
The NIS2 Directive obliges nearly 30,000 German companies to train their executives in cybersecurity. This is part of enhanced requirements to strengthen network and information security.
Under NIS2 regulation, 29,500 companies in Germany must systematically train their executives in cybersecurity. The training obligation applies to companies in critical sectors such as energy, water, transport, health, finance, as well as digital infrastructure and services. The objective is to ensure that senior management can identify security risks and respond appropriately.
For CISOs, this means a structured training program with documented content and regular refreshers. The trainings must demonstrate that executives understand fundamentals of IT security, the risk landscape of their organization, and their personal responsibility. Training is an organizational matter: CISOs must develop concepts, align content, and document compliance.
Implementation should be completed by the compliance deadline. CISOs should first develop a training concept with clear target audiences, content modules, and documentation processes, then evaluate training providers or build internal programs, and finally schedule regular refresher training.
Source: news.google.com · Published 27 July 2026
Lumi AI News — AI-assisted curation pursuant to Art. 50 EU AI Act. Paraphrasing and classification by Lumi News Pipeline v1.7.3.