KOPEXA × GREENSOCKS
§ 38 (3) BSIG · Mandatory training for management
NIS2 mandatory training for company management
Mandatory sessions are rarely fun. But you can't delegate this one. The BSI requires your entire management to complete NIS2 training.
At the Kopexa × Greensocks training you won't feel like you're just ticking off an annoying obligation. Designed by and for people who make decisions, not administer servers, you'll learn — without jargon or IT-speak — what NIS2 means for the members of company management, and how to protect your business from attacks and yourself from personal liability. You verifiably receive the information you need for your duty of care under § 38 BSIG — reducing your personal liability. The training itself is held in German.
- Format
- Online live
- Duration
- 4 hrs (08:30–12:30)
- Language
- German
- Proof
- Certificate of attendance
€199 / participant
Legal framework
Two paragraphs, two audiences — you are explicitly meant
NIS2 has two separate training obligations. One for staff, one for company management personally. Only one of them can be delegated.
§ 30 (2) BSIG
Training obligation — staff
Applies to all employees. Awareness of cyber risks in day-to-day work. Can be organised and delivered by the relevant department.
Delegable
§ 38 (3) BSIG
Training obligation — management
Applies to company management personally — managing directors and board members. Implementing security measures can be delegated. This training obligation cannot. Whoever verifiably completes the training and implements the measures fulfils their duty of care — minimising personal liability in an emergency.
Not delegable
Not sure whether your company is even in scope? The NIS2 scope check gives you clarity in minutes. More about the law on our NIS2 overview.
Format
Live means live — not pre-recorded
Four hours of video workshop with a real trainer, real questions, real discussion. Not an e-learning module running in the background.
What it isn't
- No pre-recorded self-study videos
- No multiple-choice test at the end
- No generic IT slides without management relevance
What it is
- Live session with discussion and Q&A
- A trainer with hands-on experience from ISMS and security projects, who is a managing director himself. And a biker.
- A small group instead of an anonymous webinar audience — max. 15 participants per date
- Documented, verifiable knowledge transfer — as evidence of your duty of care
Contents
Five topic blocks, four hours, one goal
No lecture about firewalls. The focus is on what you, as management, are actually accountable for.
What NIS2 really requires
Operational resilience instead of an „IT law" — putting it in context beyond the headlines.
Understanding risk management
The risk process, the protection goals confidentiality / integrity / availability, and why that's your decision.
Where your company stands today
A rough positioning in the group — no deep audit, but an honest first check. Curious already? Take the scope check.
Management's obligations, concretely
What you're personally accountable for — with a direct link to § 38 BSIG. And: which concrete steps verifiably reduce your liability.
The next steps
What comes after the training if you actually want to implement NIS2 in your company.
At a glance
The facts, in brief
- Duration
- 4 hours
- Time
- 08:30 – 12:30 (CET)
- Format
- Live online · Microsoft Teams
- Language
- German
- Proof of attendance
- Certificate included
- Participants
- max. 15 per date
- Trainer
- Michael Thissen, Greensocks
Trainer & partner
Who runs the training

Michael Thissen — Greensocks
Michael Thissen is the founder of GreenSocks Consulting GmbH. For over 15 years he has supported companies with ISMS, ISO 27001, NIS2 and BCM — from mid-sized businesses to large corporations.
His conviction: cybersecurity is a management matter. NIS2 now makes that mandatory — including personal liability and documented training records for management.
Together with Kopexa he offers exactly the right thing for this: compact management training — no theory overkill, just what leaders need to know and decide — obligations, liability, reporting deadlines, risk control. Verifiably documented.
Down to earth. Pragmatic. Actionable. Biker's honour.
Dates
Choose a date, secure your spot
All dates 08:30 – 12:30 (CET), live online.
27.08.2026
08:30 – 12:30 (CET)
24.09.2026
08:30 – 12:30 (CET)
23.10.2026
08:30 – 12:30 (CET)
26.11.2026
08:30 – 12:30 (CET)
28.01.2027
08:30 – 12:30 (CET)
Price & registration
€199 per participant
€199plus VAT · per participant
- 4-hour live workshop
- Certificate of attendance
- Documentation of the content covered — for your internal duty-of-care records
FAQ
Questions that usually come up first
Next step
Four hours. One certificate. One obligation done. One liability reduced.
€199 per participant. Next date: 27.08.2026.
© Kopexa GmbH × Greensocks