Who else needs NIS2 training besides the management board?
The KSC Act requires the entity’s staff to be aware of their cybersecurity duties and to know the internal rules (Article 8d(4)). It names the head of the entity and the person entrusted with their duties. Depth for everyone else is differentiated by the organisation itself — by the tasks under Articles 8 and 11, by system access and by risk.



