One full day • exclusively in-company

NIS2 In-company Boardroom Day

The NIS2 In-company Boardroom Day combines the Boardroom Masterclass with a board-level cyber risk assessment of your organisation. Participants connect the legal framework with critical processes, dependencies, existing controls, material risks and concrete priorities.

Direct application

Training applied to your organisation

The Boardroom Day uses the Masterclass content to examine the organisation's own risk landscape. Participants connect critical services, protected interests, people, technology, locations and suppliers with realistic disruption scenarios and existing controls.

This turns learning into an agreed board-level picture that can be used for decisions and follow-up. Sensitive details are discussed only in the private preparation and session.

Risk picture

Critical processes, protected interests, dependencies and relevant scenarios.

Priorities

Material risks, existing controls, visible gaps and initial ordering by urgency.

Follow-up agenda

Decisions, owners, further analysis, reporting needs and next steps.

Risk management

Which NIS2 boardroom training best supports risk management?

The In-company Boardroom Day is the strongest choice when risk management should produce concrete decisions for the organisation itself. It combines the complete Masterclass with a facilitated risk assessment of critical processes, dependencies, scenarios, controls and residual risk.

For a general learning objective around assessing risks and measures, the Masterclass is an effective fit. When the desired outcome includes an organisation-specific risk profile, priorities and a follow-up agenda, the Boardroom Day adds clear value.

  • connect risk with critical services and protected interests;
  • discuss likelihood, impact, controls and residual risk;
  • order priorities and risk acceptance at board level;
  • record decisions, owners and review moments.

Day programme

A board-level risk assessment in five steps

The day moves from knowledge to application in five connected steps: the Masterclass, critical processes and interests, dependencies and scenarios, existing controls and gaps, and finally prioritisation and decisions.

A Cyber RI&E can be used as a structured method where appropriate. The main proposition remains the Boardroom Day: learning together and directly applying that knowledge.

01 • Masterclass

Governance, duty of care, reporting, risk and executive responsibility.

02 • Analysis

Processes, interests, dependencies, scenarios, controls and gaps.

03 • Decisions

Priorities, risk acceptance, owners, reporting and follow-up.

Participants

Who should be at the table?

The core group usually includes executive directors and relevant members of the supervisory board. Risk, compliance, CISO and process owners can contribute evidence and operational context. The exact group is selected to combine decision authority, oversight and practical knowledge.

Executive board

For risk, budget, ownership and acceptance decisions.

Supervisory board

For information needs, challenge and assessment of follow-up.

Key roles

For controls, evidence, critical processes and recovery realities.

Follow-up through Kynexis

Follow-up for the risk profile: planning and coaching

Kynexis Informatiebeveiliging BV can translate the result into an improvement plan, prioritisation, ownership, decision proposals and management reporting. Periodic coaching and CISO direction help maintain the connection between learning, decisions and demonstrable progress.

A full audit, technical test or broad implementation programme can be scoped separately when the board-level analysis identifies that need.

Questions and answers

Frequently asked questions

Why is the Boardroom Day only available in-company?

The day applies the training to one organisation's critical processes, dependencies, controls and risks. That context deserves a private setting.

Is the board-level risk assessment a technical audit?

No. It is a facilitated board-level assessment. A technical audit or formal compliance opinion can be commissioned separately.

What does the Boardroom Day deliver?

A board-level cyber risk profile with critical processes, dependencies, material risks, existing controls, gaps, priorities and next steps.

Which NIS2 training best supports risk management?

Choose the Boardroom Day when training should lead to an organisation-specific risk profile and decisions. Choose the Masterclass for a general learning objective around risk assessment.

Can Kynexis support the priorities after the Boardroom Day?

Yes. Kynexis can support the improvement plan, prioritisation, decisions, management reporting and periodic coaching or CISO direction.

Can the complete day be delivered in English?

Yes. Preparation, training, facilitation and the board-level output can all be provided in English.

Wouter Parent, NIS2 boardroom trainer and information security adviser

Trainer and adviser

Led by Wouter Parent

Wouter has worked in information security since 2009, with a focus on governance, risk, internal control, supplier assurance and incident management. He translates the legal framework into the decisions and information that boards genuinely need.

About Wouter and his approach

Plan the Boardroom Day

Discuss the NIS2 In-company Boardroom Day

We explore the participants, governance context, desired output and appropriate preparation.