Cybersecurity for everyone – how NIS2, CRA, and data protection affect us
Navigating EU regulations: NIS2, Cyber Resilience Act, DORA, AI Act, and GDPR explained in simple terms
Contents
Compass EU regulations
- Overview: NIS2, CRA, DORA, AI Act, GDPR – objectives, areas of application, interrelationships.
- Regulation vs. directive: differences and practical consequences.
NIS2 in practice
- Governance, risk management, reporting channels, supply chain sourcing.
- Organization, roles, documentation.
Cyber Resilience Act (CRA)
- Security requirements for networked products/software.
- Secure by design/default, updates, vulnerability management.
DORA (financial sector)
- ICT risk, testing, third-party management, incident reporting.
- Also relevant for service providers/suppliers.
AI Act & Data Protection Interfaces
- Risk classes, obligations, technical/organizational measures.
- GDPR reference: Legal basis, DPIA, transparency.
Practical transfers & quick start
- VIVA reduction.
- "3 golden rules": patching, backups, awareness.
Global context
- Monopoly tendencies, dependencies, European sovereignty.
Learning environment
In your online learning environment, you will find useful information, downloads and extra services for this training course once you have registered.
Your benefit
- Clear overview of NIS2, CRA, DORA, AI Act, and GDPR—including interfaces.
- Specific priorities and initial steps for IT, organization, product, and compliance.
- Checklists/quick checks for documentation-compliant implementation.
- Comprehensible classification of global developments and EU sovereignty.
- Practical guidelines: patching, backups, awareness.
Methods
Keynote speeches, interactive discussions, practical case studies, Q&A sessions, working with checklists/tools, moderated networking.
Recommended for
The training at specialists and managers from the fields of IT, law, compliance, data protection, and organization, as well as executives, project managers, and product managers who have to deal with the effects of European regulations on their business practices. It is particularly relevant for companies without their own legal department or with basic information needs who are looking for timely, sound guidance and want to develop a networked understanding of their regulatory tasks.
42353
Start dates and details
Tuesday, 09.06.2026
09:00 am - 5:00 pm
Tuesday, 01.09.2026
09:00 am - 5:00 pm
- one joint lunch per full seminar day,
- Catering during breaks and
- extensive working documents.
Wednesday, 14.10.2026
09:00 am - 5:00 pm
Wednesday, 27.01.2027
09:00 am - 5:00 pm
Monday, 15.03.2027
09:00 am - 5:00 pm
- one joint lunch per full seminar day,
- Catering during breaks and
- extensive working documents.
- one joint lunch per full seminar day,
- Catering during breaks and
- extensive working documents.
