NIS2 & Cybersecurity
Practical workshop for schools and public entities with emphasis on exercises, simulations and group work.
Who is the workshop for?
The workshop is designed for people who do not have deep technical knowledge of cybersecurity, but who need to manage or make decisions about it. No prior knowledge is required. 65% of the time is devoted to practical exercises, so there is no time to be bored.
What will you take away?
- Know whether NIS2 applies to you and exactly what you need to do
- Recognise phishing emails, SMS scams and phone fraud
- Learn how to set up passwords and MFA correctly
- Practise incident response in a real-life simulation
- Leave with a concrete action plan for your organisation
- Understand sanctions and the personal liability of the statutory body
Why does this matter?
Act No. 264/2025 Coll. on cybersecurity (NIS2 transposition), effective 1 November 2025, dramatically expands the scope of obligated entities – from tens to thousands of organisations. Schools, municipalities and public institutions are now required to implement security measures. Personal liability rests with the statutory body (director, mayor) and penalties can reach up to CZK 250 million or 2% of turnover.
Workshop parameters
Format
Workshop, approx. 35% theory, 65% exercises and discussions
Target audience
School management, directors, IT admins, officials, secretaries, data protection officers
Equipment
Projector, flipchart, printed materials
Workshop programme
| Blok | Téma |
|---|---|
| Block 1 | Introduction and context: why this matters |
| Block 2 | Who is covered by the law, self-classification |
| Block 3 | Obligations under the Cybersecurity Act in practice |
| Block 4 | Phishing and social engineering, practical laboratory |
| Block 5 | Passwords, MFA & cyber hygiene |
| Block 6 | Incident response, simulation |
| Block 7 | Action plan for your organisation |