ith security

Comprehensive Cybersecurity Training for Businesses

The NIS2 Directive is just like the GDPR was a few years ago—many people think it doesn’t apply to them until they face their first audit or data breach. Our cybersecurity training isn’t a boring legal lecture—it’s a survival guide for your business.

ith-cybersecuirty-hero-image

TRAINING PACKAGES

Choose a plan that's right for your organization

Each program is tailored to the specific needs of the sector and is based on the ITH specialists’ many years of engineering experience.

2 HOURS

Basic Security Training

The perfect introduction for all employees. Raising awareness of everyday risks.

  • Due Diligence in Data Protection—Legal Basis
  • Password Creation and Multi-Factor Authentication (MFA)
  • Recognizing Phishing
  • No limit on the number of participants—the ability to train the entire organization at once
6 HOURS

Premium Security Training

Advanced incident response procedures and crisis management for IT and security personnel, as well as executive management.

  • Attack simulations—deepfakes, spoofing
  • Documentation as evidence of due diligence before the supervisory authority
  • "Before" and "After" Knowledge Tests
  • +1 hour of consultation in areas requiring improvement

SCOPE OF TRAINING

8 subject areas—from law to the psychology of attack

Our training programs combine theory with practice. The practical aspects of the courses help employees understand that their day-to-day decisions matter to the safety of the entire company.

zakres-szkolenia-1

The NIS2 Directive and the National Cybersecurity System

Understanding the relationship between EU and national regulations, as well as the responsibilities of key and important entities.

zakres-szkolenia-2

Responsibilities of the Board of Directors and Management

Direct financial responsibility of the management board. We’ll teach you how to approve security strategies without a Ph.D. in computer science.

zakres-szkolenia-3

Risk Management and Business Continuity

Asset identification, vulnerability assessment, and BCP and DRP plans that are resilient to ransomware attacks.

zakres-szkolenia-4

Incident response procedures

Critical steps following the detection of a breach. Reporting to the NASK/MON/GOV CSIRT within the statutory deadlines.

zakres-szkolenia-5

Data Protection and Information Security

Encryption, MFA, DLP systems. Configuring Microsoft 365 (SharePoint, Teams) for compliance.

zakres-szkolenia-6

Supply Chain Security

Vendor audits, contract provisions. Your company may be held liable for suppliers who have access to your systems.

zakres-szkolenia-7

The Psychology of Cyberattacks - AI, Deepfakes, Spoofing

Business Email Compromise, fraudulent transfer requests, phone number spoofing. Two-factor verification procedure.

zakres-szkolenia-8

Security Documentation and Policies

Password and MFA policies, disaster recovery plans, incident reporting procedures, and a record of processed data. Ready-made templates.

NIS2 DIRECTIVE

The NIS2 Directive and Its Significance for Polish Businesses

The NIS2 Directive is an EU regulation aimed at improving cybersecurity in EU member states, expanding on the previous NIS Directive. In Poland, its implementation is directly linked to amendments to the provisions governing the national cybersecurity system, which imposes a range of obligations on thousands of new entities. Its importance cannot be overstated—this regulation makes digital resilience a measurable market standard.

Understanding the NIS2 Directive requires looking at the organization as a whole. It’s not just about software, but above all about risk management and appropriate Procedures. New regulations require companies to implement adequate security measures, which must be continuously monitored by the supervisory authority. Every regulated entity must demonstrate that it is taking concrete steps to minimize risks.

ith-cybersecurity-dyrektywa-nis2-zdj
ith-odp-zarzadu-img

LIABILITY

Responsibilities of the Board of Directors and Management

One of the most important aspects of the new regulations is the management board’s direct responsibility for the state of security measures. The NIS2 Directive clearly states that members of decision-making bodies can no longer delegate security responsibilities solely to “IT specialists.” Management must actively participate in processes such as threat identification and the approval of business continuity strategies.

Non-compliance with the provisions of the NIS2 Directive and the amended Act on the National Cybersecurity System may have severe consequences. Members of the management board may be held personally financially liable for cybersecurity failures. That is why it is so important for individuals at the highest levels of decision-making to participate in this training, gaining practical knowledge on how to oversee the implementation of security policies and what responsibilities they bear.

Don't risk fines. Check whether NIS2 applies to your company

DOCUMENTATION

Information Security Documentation and Policies

Implementing security measures is only half the battle. The other half is documenting them. The obligations under the NIS2 Directive include creating and regularly updating information security policies.

During training sessions, when reviewing documentation, we focus on:

  • password and MFA policies;
  • disaster recovery plans;
  • incident reporting procedures;
  • a register of processed data sets.

We won’t leave you with a blank page. We’ll provide you with ready-made designs and templates that you can easily customize for your business.

RISK MANAGEMENT

Risk Management and Business Continuity

Effective risk management is at the heart of a secure organization. This process encompasses not only IT systems but also the management of physical and information assets. Every participant in the training program learns how important it is to properly identify resources and assess their vulnerability to cyber threats.

As part of the training, we place great emphasis on developing and testing business continuity plans. The continuity of business processes in the face of a ransomware attack or an IT system failure is a matter of survival for many companies. The NIS2 Directive introduces obligations regarding the implementation of technical and organizational measures designed to ensure the security of IT systems within organizations.

Key elements of business continuity management:

  • regular backups and verification (Veeam, Synology C2);
  • precise incident response procedures;
  • contingency plans in the event that key services are unavailable;
  • 24/7 continuous monitoring of systems for anomalies.

Prepare Your Organization for NIS2

icons8-documents-96 1

Incident Response Procedures, Reporting

Companies usually find out just how badly their procedures have failed when the screen goes black and a ransom demand appears. Our training programs are...

Read more
icons8-it-100 1

Information Security

Data security cannot be managed in isolation from technology. During the training, experts demonstrate how to properly configure the Microsoft 365 environment (including SharePoint and...

Read more
icons8-web-shield-100 1

National Cybersecurity System

The national cybersecurity system is becoming increasingly robust, and the responsibilities of key entities are being monitored more rigorously. Participating in this training helps you...

Read more
icons8-light-bulb-100 1

Staff Awareness

Training must include all employees, and its purpose is to raise awareness of risks and improve the ability to respond to incidents. Without a high...

Read more
icons8-audit-100 1

Monitoring, Oversight, and Compliance Audits

24/7 monitoring? It’s not a luxury. It’s a necessity. Hackers don’t work from 8:00 a.m. to 4:00 p.m. If your system doesn’t detect an anomaly...

Read more
icons8-logistics-96 1

Supply Chain Management

The NIS 2 Directive places a strong emphasis on the security of service providers. Every subcontractor with access to your IT systems must be vetted....

Read more

A safe workplace starts with informed employees

The goal of these training sessions is to prepare organizations for compliance audits and to increase their overall resilience against cyberattacks. Don’t let your company become an easy target. Training should be ongoing and regularly updated to address new and evolving threats.Secure your organization in accordance with the highest standards. Choose a training package tailored to your needs and gain peace of mind in the face of new regulations.

They trusted us

ITH
ITH
ITH
ITH
ITH

Let's talk about your company's needs

Check out what else we have for you!

Write to us

Support
Maintenance

ITH NOC
Management Center
Infrastructure ITH
Open all week, 24 hours a day

Solutions
for you

ITH sales team
Open Monday through Friday from 9:00 a.m. to 8:00 p.m.

    Expand This offer does not constitute an offer within the meaning of the Civil Code. This offer is intended solely for business customers. All prices listed are net prices. * Pursuant to Article 23 of the Act of August 23, 1997, on the Protection of Personal Data (Journal of Laws of 2016, No. 922 of June 28, 2016, consolidated text), I hereby consent to the processing of my personal data provided in the form above (i.e., Tax Identification Number (NIP), phone number, email address) by ITH Sp. z o.o., with its registered office in Warsaw, ul. Nowogrodzka 31, 00-511 Warsaw, registered in the Register of Entrepreneurs of the National Court Register under KRS number 0000469801, Tax ID (NIP): 7010389026, REGON: 146777630, for the purpose of presenting and fulfilling a commercial offer. I have been informed of my right to access the data I have provided, to modify it, and to object to its further processing. The controller of personal data is ITH Sp. z o.o., with its registered office in Warsaw, at ul. Nowogrodzka 31, 00-511 Warsaw, registered in the Register of Entrepreneurs of the National Court Register under KRS number 0000469801, NIP: 7010389026, REGON: 146777630.
    _DSC6603

    FAQ

    In accordance with the NIS2 Directive, critical and important entities must ensure that their management and staff have the appropriate competencies. Regular training is an essential element of risk management.

    Yes, each of our programs includes practical information on phishing, secure passwords, and the protection of data processed in everyday office work.

    In the Standard and Premium packages, each training participant receives a certificate. In addition, we prepare a report for the board of directors, which can serve as evidence of due diligence before the supervisory authority.

    We typically conduct training in the form of interactive online workshops, which allows employees from different locations to participate simultaneously. However, it is possible to arrange in-person training sessions.