{"id":4111,"date":"2026-08-18T09:00:00","date_gmt":"2026-08-18T07:00:00","guid":{"rendered":"https:\/\/www.lablogic.pl\/?p=4111"},"modified":"2026-09-27T19:59:29","modified_gmt":"2026-09-27T17:59:29","slug":"who-needs-nis2-training-besides-the-board","status":"publish","type":"post","link":"https:\/\/www.lablogic.pl\/en\/who-needs-nis2-training-besides-the-board\/","title":{"rendered":"Who else needs NIS2 training besides the management board?"},"content":{"rendered":"\n<p class=\"ll-art-meta wp-block-paragraph\"><a href=\"https:\/\/www.lablogic.pl\/en\/michal-rutkowski\/\"><strong>Micha\u0142 Rutkowski<\/strong><\/a> \u2022 for boards and HR teams \u2022 published August 18, 2026 \u2022 updated September 12, 2026 \u2022 8 min read<\/p>\n\n\n\n<div class=\"wp-block-columns ll-art-shell is-layout-flex wp-container-core-columns-is-layout-7387b849 wp-block-columns-is-layout-flex\">\n<div class=\"wp-block-column ll-art-rail is-layout-flow wp-block-column-is-layout-flow\">\n<div class=\"wp-block-group ll-art-railinner is-layout-constrained wp-block-group-is-layout-constrained\">\n\n\n\n<\/div>\n<\/div>\n\n\n\n<div class=\"wp-block-column ll-art-main is-layout-flow wp-block-column-is-layout-flow\">\n<div class=\"wp-block-group ll-art-answer is-layout-constrained wp-block-group-is-layout-constrained\">\n<h2 id=\"krotka-odpowiedz\" class=\"wp-block-heading\">Short answer<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">Apart from the head of the entity, the Polish Act on the National Cybersecurity System (KSC) names only one more role. It is the person entrusted with the head\u2019s duties in the area of cybersecurity. For everyone else the obligation is built differently. The Act sets out neither positions nor frequency, but it does describe a result \u2014 staff must be aware of their cybersecurity duties and know the entity\u2019s internal rules (Article 8d(4)). Baseline awareness of cybersecurity duties and internal rules covers the entity\u2019s staff. Depth and frequency are differentiated by role, access and risk, while persons performing the tasks under Articles 8 and 11 are identified separately.<\/p>\n<\/div>\n\n\n\n<h2 id=\"dlaczego\" class=\"wp-block-heading\">Why the question comes up at all<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">Two training obligations in the same Act are built in completely different ways. The first has an addressee, a cycle and a proof. The head of an essential or important entity completes training once each calendar year, and participation in it is documented (Article 8e). The second obligation has none of those three elements. Cybersecurity education for the entity\u2019s staff is one of the elements of the information security management system (Article 8(1)(2)(i)), alongside basic cyber hygiene practices (point (j)). Neither a deadline nor a list of positions stands next to them.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">The second source of doubt lies in the difference between the directive and the Act. Directive (EU) 2022\/2555 imposes a training obligation on the members of management bodies, while towards employees it merely \u201cencourages\u201d entities to offer similar training (Article 20(2)). The Polish legislator went further and wrote staff education into the catalogue of measures an entity has to implement. Anyone who reads the directive alone concludes that training beyond the board is voluntary. That conclusion does not follow from the national Act.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">The third reason is organisational. The question about the circle of people usually comes up once training for the head of the entity is already in the calendar. That is when it turns out there is no ready list for the rest of the organisation.<\/p>\n\n\n\n<div class=\"wp-block-group ll-art-zdanie is-layout-constrained wp-block-group-is-layout-constrained\">\n\n<p class=\"wp-block-paragraph\">Remember<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">The organisational chart will not replace a list of the roles to be trained, because duties under the Act are distributed differently than positions.<\/p>\n\n<\/div>\n\n\n\n<h2 id=\"co-ustalic\" class=\"wp-block-heading\">What to establish before deciding<\/h2>\n\n\n\n<h3 class=\"wp-block-heading\">Who besides the head of the entity is named in the Act<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">Article 8e(1) names two roles. They are the head of an essential or important entity and the person entrusted with the head\u2019s duties in the area of cybersecurity. Both are subject to the same annual cycle and the same scope set out in paragraph 2. Both must have documented participation in training.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">The second role is often overlooked, because in many organisations it exists in fact rather than formally. Someone runs the subject day to day and prepares materials for the board, but the entrustment has never been recorded. Entrustment requires that person\u2019s consent and does not relieve the head of the entity of responsibility (Article 8c(3)). The practical conclusion is simple. If the entrustment exists, both sides are trained. If it does not, the first thing to settle is whether it should.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">The scope of training for these two roles is set out in <a href=\"https:\/\/www.lablogic.pl\/en\/what-should-nis2-training-for-the-board-cover\/\">What should NIS2 training for the board cover?<\/a>. It is the scope of the head of the entity\u2019s responsibility, not a programme for specialists.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\">Who performs the tasks under Articles 8 and 11<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">This is the most useful criterion for selecting groups, because the Act uses it for an entirely different purpose. Before a person is admitted to tasks under Article 8 or Article 11, the organisation must obtain from them a certificate from the National Criminal Register confirming no conviction for offences against the protection of information (Article 8f(1)). Meeting that obligation requires a list of named individuals.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">That same list is the natural starting point for a training plan. It covers the people who perform the tasks of the information security management system and those involved in handling and reporting incidents. In a medium-sized organisation this is usually a dozen or so people from several different departments, not a single team.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Two things are worth checking at this point. Whether the list covers the people who actually perform the activities, not only the formal owners of areas. And whether it covers deputies as well, because incident duties run regardless of holidays and staff turnover.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\">The people designated for contact with the national cybersecurity system<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">An essential or important entity designates at least two people responsible for maintaining contact with the entities of the national cybersecurity system (Article 9(1)(1)). One person is enough only for micro and small enterprises and for an important entity that is a public entity (Article 9(2) and (3)). Once entered in the register, the entity begins using the ICT system through which it submits its reports (Article 9(1)(4)).<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">The Act does not provide a separate training obligation for these people. The task itself, however, determines the scope of preparation. It is about operating the reporting system and about the deadlines counted from detection of a significant incident. This is a practical assessment, not the content of a provision. It is an assessment that is easy to defend, though, because a contact person without that knowledge will not perform the task they were designated for.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\">Which roles follow from the catalogue of measures itself<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">The Act lists the elements of the information security management system in Article 8(1)(2). Each of them has an owner in the organisation, and a substantial part of them sits outside the IT department. The table below assigns the elements to roles and indicates what the preparation of those people covers. It is a practical assessment based on the typical structure of a medium-sized and large organisation, not a catalogue that follows from the provision.<\/p>\n\n\n\n<figure class=\"wp-block-table ll-art-table\"><table><thead><tr><th>Element of the system (Article 8(1)(2))<\/th><th>Who usually decides<\/th><th>What the preparation covers<\/th><\/tr><\/thead><tbody><tr><td>Human resources security (point (d))<\/td><td>HR department and line managers<\/td><td>Hiring, change of role and departure of an employee; the criminal record check before admission to tasks under Article 8f<\/td><\/tr><tr><td>Security and continuity of the ICT supply chain (point (e))<\/td><td>Procurement and contract owners<\/td><td>Supplier assessment criteria under Article 8(2) and security clauses in contracts<\/td><\/tr><tr><td>Security in the acquisition, development and maintenance of the system (point (b))<\/td><td>Development and maintenance teams, project leads<\/td><td>Security requirements in the project and testing of the system before go-live<\/td><\/tr><tr><td>Asset management and access control policies (points (m) and (n))<\/td><td>Access administrators, managers approving requests<\/td><td>Least privilege, access reviews, revoking rights after a change of role<\/td><\/tr><tr><td>Business continuity and recovery plans (point (f))<\/td><td>Process owners<\/td><td>The role of the process in providing the service, the conditions for invoking the plan, taking part in tests<\/td><\/tr><tr><td>Staff education and cyber hygiene (points (i) and (j))<\/td><td>All staff who use the system<\/td><td>Recognising events, the internal reporting path, the rules in force<\/td><\/tr><\/tbody><\/table><\/figure>\n\n\n\n<p class=\"wp-block-paragraph\">The table shows why a list of groups built from the organisational chart is usually incomplete. The first three rows concern departments that are not the first to come up in a conversation about cybersecurity, yet they are responsible for decisions that are hard to reverse after the fact.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\">Where the boundary of \u201call staff\u201d runs<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">The information security management system is implemented in the information system used in processes that affect the provision of the service (Article 8(1)). That narrows the scope of the management system itself. The head\u2019s duty under Article 8d(4) is framed more broadly and speaks of the entity\u2019s staff.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">The narrowing works only where the organisation can point to the boundary of the system. Where support processes use the same infrastructure and the same accounts, that boundary effectively does not exist. Covering all staff is then a simpler solution than proving who falls outside the system.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">It is worth noting separately that the Act speaks of the entity\u2019s \u201cstaff\u201d, not of employees. People working on a basis other than an employment contract use the same systems and make the same mistakes. The dividing criterion is the scope of tasks and access, not the type of contract.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\">An important entity that is a public entity has a different point of reference<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">An important entity that is a public entity does not apply Article 8(1); it applies the requirements of Annex 4 to the Act (Article 8(3)). The same provision covers some universities to the extent that they carry out public tasks. On the subject that interests us here, the annex is more specific than the general provisions.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Part I of the annex lists training for people involved in the processing of information as a measure that minimises the occurrence of incidents (point 17). It also sets out the subject scope. These are the types of cyber threats, basic cyber hygiene practices, responding to an incident, and awareness of the consequences of breaching information security rules. A separate point requires cyber hygiene practices to be applied by employees who use information systems, including by the head of the entity (point 14). The whole system is reviewed at least once a year (Part III of the annex).<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">For this group of entities the answer is therefore closest to being ready-made. The circle is marked out by involvement in the processing of information, and the subject scope is written out in the annex.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\">What to do about the provider\u2019s staff<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">An entity performs its tasks through its own structures responsible for cybersecurity or under a contract with a managed cybersecurity services provider (Article 14). The choice of model does not change the addressee of the obligations towards its own staff. The entity is responsible for the awareness of its own people.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">What remains to be settled is the interface between the two sides. Someone on the entity\u2019s side receives information from the provider, assesses it and triggers the decision to report. That person needs preparation regardless of the provider\u2019s competence, because the addressee of the reporting obligation remains the essential or important entity.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\">When the list has to be ready<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">Entities that met the qualification criteria on April 3, 2026 have twelve months to meet the obligations set out in the chapter on essential and important entities, that is until April 3, 2027 (Article 33(1) of the amending act of January 23, 2026). An entity that meets the criteria later has twelve months from that moment (Article 16 of the KSC Act). Staff education belongs to the same chapter as the other elements of the system.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">The list of groups, however, comes into being earlier and almost as a by-product. It is the by-product of two other pieces of work. The first is establishing the scope of the information security management system, the second is identifying the people who perform the tasks under Articles 8 and 11. An organisation that is <a href=\"https:\/\/www.lablogic.pl\/en\/nis2-ksc\/\">still establishing the scope of its obligations and its state of readiness<\/a> will not build a credible list of groups before that is settled.<\/p>\n\n\n\n<h2 id=\"bledy\" class=\"wp-block-heading\">Most common mistakes<\/h2>\n\n\n\n<ul class=\"wp-block-list ll-art-errors\">\n<li><strong>One course for everyone treated as the whole obligation.<\/strong> A module on passwords and phishing covers cyber hygiene, not the tasks of the people who perform Articles 8 and 11.<\/li>\n\n\n\n<li><strong>A list of groups built from the organisational chart.<\/strong> The starting point is the scope of the system and the division of tasks, not the structure of departments.<\/li>\n\n\n\n<li><strong>Leaving out the person entrusted with the head\u2019s duties.<\/strong> The Act names them alongside the head of the entity in Article 8e(1).<\/li>\n\n\n\n<li><strong>Excluding procurement and HR because \u201cthey are not technical roles\u201d.<\/strong> Supplier assessment and admitting a person to tasks are activities set out in the Act.<\/li>\n\n\n\n<li><strong>Assuming that a contract with a provider removes the obligation towards your own staff.<\/strong> What changes is the model for performing the tasks, not the addressee of the obligations.<\/li>\n\n\n\n<li><strong>Training the people under Articles 8 and 11 without a list of names first.<\/strong> The same list is needed for the criminal record check, so it comes into being in the organisation either way.<\/li>\n\n\n\n<li><strong>Repeating the content of the head\u2019s training in training for staff.<\/strong> The scope under Article 8e(2) concerns responsibility for meeting obligations, not an employee\u2019s day-to-day activities.<\/li>\n<\/ul>\n\n\n\n<h2 id=\"wnioski\" class=\"wp-block-heading\">Conclusions and next steps<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">The Act answers this indirectly, and that is exactly why the answer is often missed. It names one role beyond the head of the entity. The circle of the remaining people is something the organisation derives itself \u2014 from the scope of its own system, from the division of tasks and from involvement in handling incidents. The result of that work is both a training plan and evidence that the result required by Article 8d(4) has been planned deliberately.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">The order below puts that exercise in place.<\/p>\n\n\n\n<ol class=\"wp-block-list\">\n<li>Check whether anyone has been entrusted with the head\u2019s duties in the area of cybersecurity and whether there is a record of it. That person is subject to the training obligation together with the head of the entity.<\/li>\n\n\n\n<li>List by name the people who perform the tasks under Articles 8 and 11, together with their deputies. The list is needed for the criminal record check anyway.<\/li>\n\n\n\n<li>Add the people designated for contact with the entities of the national cybersecurity system.<\/li>\n\n\n\n<li>Go through the catalogue of measures in Article 8(1)(2) and assign to each element the role that actually decides about it.<\/li>\n\n\n\n<li>Differentiate the scope and depth of training by tasks and access, not by the type of contract.<\/li>\n\n\n\n<li>In an important entity that is a public entity, set the result against points 14 and 17 of Annex 4.<\/li>\n\n\n\n<li>Write down how you will know that the result under Article 8d(4) has been achieved \u2014 otherwise a year later all that will be left is an attendance list.<\/li>\n<\/ol>\n\n\n\n<h2 class=\"wp-block-heading\">Related materials<\/h2>\n\n\n\n<ul class=\"wp-block-list\">\n<li><strong><a href=\"https:\/\/www.lablogic.pl\/en\/what-should-nis2-training-for-the-board-cover\/\">What should NIS2 training for the board cover?<\/a><\/strong> \u2014 the scope of the mandatory training for the head of the entity and for the person entrusted with their duties.<\/li>\n\n\n\n<li><strong><a href=\"https:\/\/www.lablogic.pl\/en\/how-to-measure-training-effectiveness\/\">How do you know that training produced a real effect?<\/a><\/strong> \u2014 how to check the result required by Article 8d(4).<\/li>\n\n\n\n<li><strong><a href=\"https:\/\/www.lablogic.pl\/en\/what-to-do-after-detecting-an-incident\/\">What to do after detecting an incident?<\/a><\/strong> \u2014 the sequence of the first day, that is the material for the groups named in points two and three.<\/li>\n\n\n\n<li><strong><a href=\"https:\/\/www.lablogic.pl\/en\/how-to-document-training-as-evidence\/\">How to document training so that it serves as evidence for the authority?<\/a><\/strong> \u2014 how to record the training of the head of the entity and other staff so that it can be demonstrated to the authority.<\/li>\n<\/ul>\n\n\n\n<h2 class=\"wp-block-heading\">Sources<\/h2>\n\n\n\n<ul class=\"wp-block-list ll-art-sources\">\n<li>Act of July 5, 2018 on the National Cybersecurity System, Article 8, Articles 8c\u20138f, Article 9, Article 14, Article 16 and Annex 4, consolidated text \u2014 Chancellery of the Sejm, ISAP: <a href=\"https:\/\/isap.sejm.gov.pl\/isap.nsf\/DocDetails.xsp?id=WDU20180001560\" target=\"_blank\" rel=\"noreferrer noopener\">isap.sejm.gov.pl<\/a> (in Polish)<\/li>\n\n\n\n<li>Act of January 23, 2026 amending the Act on the National Cybersecurity System and certain other acts (Journal of Laws 2026, item 252), Article 33 \u2014 Journal of Laws: <a href=\"https:\/\/dziennikustaw.gov.pl\/D2026000025201.pdf\" target=\"_blank\" rel=\"noreferrer noopener\">dziennikustaw.gov.pl<\/a> (in Polish)<\/li>\n\n\n\n<li>Directive (EU) 2022\/2555 of the European Parliament and of the Council (NIS 2), Article 20(2) and Article 21(2)(g) \u2014 EUR-Lex: <a href=\"https:\/\/eur-lex.europa.eu\/legal-content\/EN\/TXT\/?uri=CELEX:32022L2555\" target=\"_blank\" rel=\"noreferrer noopener\">eur-lex.europa.eu<\/a><\/li>\n\n\n\n<li>Amendment of the KSC Act \u2014 questions and answers (update of June 2026), question 3.8 on training for staff \u2014 Ministry of Digital Affairs: <a href=\"https:\/\/www.gov.pl\/attachment\/c19a078f-60ca-49ab-ac19-f743f8f64903\" target=\"_blank\" rel=\"noreferrer noopener\">gov.pl<\/a> (in Polish)<\/li>\n\n\n\n<li>Amendment of the KSC Act \u2014 obligations of essential and important entities \u2014 Ministry of Digital Affairs: <a href=\"https:\/\/www.gov.pl\/web\/cyfryzacja\/nowelizacja-ustawy-o-krajowym-systemie-cyberbezpieczenstwa-ksc---obowiazki-podmiotow-kluczowych-i-waznych\" target=\"_blank\" rel=\"noreferrer noopener\">gov.pl<\/a> (in Polish)<\/li>\n<\/ul>\n\n\n\n<div class=\"wp-block-group ll-art-cta is-layout-constrained wp-block-group-is-layout-constrained\">\n<h2 class=\"wp-block-heading ll-nietoc\">Let us match the training to the roles in your organisation<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">If the list of groups does not exist yet, it is worth starting by setting the tasks under Articles 8 and 11 against the people who actually perform them. That comparison defines the programme for each group separately. Training and workshops are built on it.<\/p>\n\n\n\n<div class=\"wp-block-buttons is-layout-flex wp-block-buttons-is-layout-flex\">\n<div class=\"wp-block-button\"><a class=\"wp-block-button__link wp-element-button\" href=\"https:\/\/www.lablogic.pl\/en\/training\/\">Training and workshops<\/a><\/div>\n<\/div>\n<\/div>\n<\/div>\n<\/div>\n","protected":false},"excerpt":{"rendered":"<p>The head of the entity ensures that staff are aware of cybersecurity obligations (Article 8d(4) of the KSC Act). The Act requires annual training of the head and of the person entrusted with the head\u2019s duties in that area (Article 8e(1)). Other people are best selected by their tasks under Articles 8 and 11.<\/p>\n","protected":false},"author":2,"featured_media":5562,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"site-sidebar-layout":"default","site-content-layout":"","ast-site-content-layout":"default","site-content-style":"default","site-sidebar-style":"default","ast-global-header-display":"","ast-banner-title-visibility":"","ast-main-header-display":"","ast-hfb-above-header-display":"","ast-hfb-below-header-display":"","ast-hfb-mobile-header-display":"","site-post-title":"","ast-breadcrumbs-content":"","ast-featured-img":"","footer-sml-layout":"","ast-disable-related-posts":"","theme-transparent-header-meta":"","adv-header-id-meta":"","stick-header-meta":"","header-above-stick-meta":"","header-main-stick-meta":"","header-below-stick-meta":"","astra-migrate-meta-layouts":"default","ast-page-background-enabled":"default","ast-page-background-meta":{"desktop":{"background-color":"var(--ast-global-color-5)","background-image":"","background-repeat":"repeat","background-position":"center center","background-size":"auto","background-attachment":"scroll","background-type":"","background-media":"","overlay-type":"","overlay-color":"","overlay-opacity":"","overlay-gradient":""},"tablet":{"background-color":"","background-image":"","background-repeat":"repeat","background-position":"center center","background-size":"auto","background-attachment":"scroll","background-type":"","background-media":"","overlay-type":"","overlay-color":"","overlay-opacity":"","overlay-gradient":""},"mobile":{"background-color":"","background-image":"","background-repeat":"repeat","background-position":"center center","background-size":"auto","background-attachment":"scroll","background-type":"","background-media":"","overlay-type":"","overlay-color":"","overlay-opacity":"","overlay-gradient":""}},"ast-content-background-meta":{"desktop":{"background-color":"var(--ast-global-color-4)","background-image":"","background-repeat":"repeat","background-position":"center center","background-size":"auto","background-attachment":"scroll","background-type":"","background-media":"","overlay-type":"","overlay-color":"","overlay-opacity":"","overlay-gradient":""},"tablet":{"background-color":"var(--ast-global-color-4)","background-image":"","background-repeat":"repeat","background-position":"center center","background-size":"auto","background-attachment":"scroll","background-type":"","background-media":"","overlay-type":"","overlay-color":"","overlay-opacity":"","overlay-gradient":""},"mobile":{"background-color":"var(--ast-global-color-4)","background-image":"","background-repeat":"repeat","background-position":"center center","background-size":"auto","background-attachment":"scroll","background-type":"","background-media":"","overlay-type":"","overlay-color":"","overlay-opacity":"","overlay-gradient":""}},"ll_stan_prawny":"August 2026","footnotes":""},"categories":[75],"tags":[],"class_list":["post-4111","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-workshops"],"aioseo_notices":[],"aioseo_head":"\n\t\t<!-- All in One SEO 5.0.2.1 - aioseo.com -->\n\t<meta name=\"description\" content=\"The KSC Act names only the head of the entity and the person entrusted with their duties. See how to derive the remaining groups from Articles 8 and 11.\" \/>\n\t<meta name=\"robots\" content=\"max-image-preview:large\" \/>\n\t<meta name=\"author\" content=\"Micha\u0142 Rutkowski\"\/>\n\t<link rel=\"canonical\" href=\"https:\/\/www.lablogic.pl\/en\/who-needs-nis2-training-besides-the-board\/\" \/>\n\t<meta name=\"generator\" content=\"All in One SEO (AIOSEO) 5.0.2.1\" \/>\n\t\t<meta property=\"og:locale\" content=\"en_US\" \/>\n\t\t<meta property=\"og:site_name\" content=\"LabLogic - Micha\u0142 Rutkowski | DPO, GDPR, NIS2 and cybersecurity in practice\" \/>\n\t\t<meta property=\"og:type\" content=\"article\" \/>\n\t\t<meta property=\"og:title\" content=\"Who to train on NIS2 besides the board\" \/>\n\t\t<meta property=\"og:description\" content=\"The Act names two roles; the rest you derive from Articles 8 and 11.\" \/>\n\t\t<meta property=\"og:url\" content=\"https:\/\/www.lablogic.pl\/en\/who-needs-nis2-training-besides-the-board\/\" \/>\n\t\t<meta property=\"og:image\" content=\"https:\/\/www.lablogic.pl\/wp-content\/uploads\/2026\/09\/ll-og-who-needs-nis2-training-besides-the-board-en-1.jpg\" \/>\n\t\t<meta property=\"og:image:secure_url\" content=\"https:\/\/www.lablogic.pl\/wp-content\/uploads\/2026\/09\/ll-og-who-needs-nis2-training-besides-the-board-en-1.jpg\" \/>\n\t\t<meta property=\"og:image:width\" content=\"1200\" \/>\n\t\t<meta property=\"og:image:height\" content=\"630\" \/>\n\t\t<meta property=\"article:section\" content=\"Training and workshops\" \/>\n\t\t<meta property=\"article:tag\" content=\"nis2\" \/>\n\t\t<meta property=\"article:tag\" content=\"ksc\" \/>\n\t\t<meta property=\"article:tag\" content=\"training\" \/>\n\t\t<meta property=\"article:tag\" content=\"compliance\" \/>\n\t\t<meta property=\"article:published_time\" content=\"2026-08-18T07:00:00+00:00\" \/>\n\t\t<meta property=\"article:modified_time\" content=\"2026-09-27T17:59:29+00:00\" \/>\n\t\t<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n\t\t<meta name=\"twitter:title\" content=\"Who to train on NIS2 besides the board\" \/>\n\t\t<meta name=\"twitter:description\" content=\"The Act names two roles; the rest you derive from Articles 8 and 11.\" \/>\n\t\t<meta name=\"twitter:image\" content=\"https:\/\/www.lablogic.pl\/wp-content\/uploads\/2026\/09\/ll-og-who-needs-nis2-training-besides-the-board-en-1.jpg\" \/>\n\t\t<script type=\"application\/ld+json\" class=\"aioseo-schema\">\n\t\t\t{\"@context\":\"https:\\\/\\\/schema.org\",\"@graph\":[{\"@type\":\"Article\",\"@id\":\"https:\\\/\\\/www.lablogic.pl\\\/en\\\/who-needs-nis2-training-besides-the-board\\\/#article\",\"name\":\"NIS2 training for employees \\u2014 who else has to be trained\",\"headline\":\"Who else needs NIS2 training besides the management board?\",\"author\":{\"@id\":\"https:\\\/\\\/www.lablogic.pl\\\/#michal-rutkowski\"},\"publisher\":{\"@id\":\"https:\\\/\\\/www.lablogic.pl\\\/#organization\"},\"image\":{\"@type\":\"ImageObject\",\"url\":\"https:\\\/\\\/www.lablogic.pl\\\/wp-content\\\/uploads\\\/2026\\\/09\\\/ll-og-who-needs-nis2-training-besides-the-board-en-1.jpg\",\"width\":1200,\"height\":630,\"caption\":\"Who else needs NIS2 training? \\u2014 LabLogic article graphic by Micha\\u0142 Rutkowski\"},\"datePublished\":\"2026-08-18T09:00:00+02:00\",\"dateModified\":\"2026-09-27T19:59:29+02:00\",\"inLanguage\":\"en-US\",\"mainEntityOfPage\":{\"@id\":\"https:\\\/\\\/www.lablogic.pl\\\/en\\\/who-needs-nis2-training-besides-the-board\\\/#webpage\"},\"isPartOf\":{\"@id\":\"https:\\\/\\\/www.lablogic.pl\\\/en\\\/who-needs-nis2-training-besides-the-board\\\/#webpage\"},\"articleSection\":\"Training and workshops\"},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\\\/\\\/www.lablogic.pl\\\/en\\\/who-needs-nis2-training-besides-the-board\\\/#breadcrumblist\",\"itemListElement\":[{\"@type\":\"ListItem\",\"@id\":\"https:\\\/\\\/www.lablogic.pl\\\/en\\\/#listItem\",\"position\":1,\"name\":\"LabLogic\",\"item\":\"https:\\\/\\\/www.lablogic.pl\\\/en\\\/\",\"nextItem\":{\"@type\":\"ListItem\",\"@id\":\"https:\\\/\\\/www.lablogic.pl\\\/en\\\/baza-wiedzy\\\/workshops\\\/#listItem\",\"name\":\"Training and workshops\"}},{\"@type\":\"ListItem\",\"@id\":\"https:\\\/\\\/www.lablogic.pl\\\/en\\\/baza-wiedzy\\\/workshops\\\/#listItem\",\"position\":2,\"name\":\"Training and workshops\",\"item\":\"https:\\\/\\\/www.lablogic.pl\\\/en\\\/baza-wiedzy\\\/workshops\\\/\",\"nextItem\":{\"@type\":\"ListItem\",\"@id\":\"https:\\\/\\\/www.lablogic.pl\\\/en\\\/who-needs-nis2-training-besides-the-board\\\/#listItem\",\"name\":\"Who else needs NIS2 training besides the management board?\"},\"previousItem\":{\"@type\":\"ListItem\",\"@id\":\"https:\\\/\\\/www.lablogic.pl\\\/en\\\/#listItem\",\"name\":\"LabLogic\"}},{\"@type\":\"ListItem\",\"@id\":\"https:\\\/\\\/www.lablogic.pl\\\/en\\\/who-needs-nis2-training-besides-the-board\\\/#listItem\",\"position\":3,\"name\":\"Who else needs NIS2 training besides the management board?\",\"previousItem\":{\"@type\":\"ListItem\",\"@id\":\"https:\\\/\\\/www.lablogic.pl\\\/en\\\/baza-wiedzy\\\/workshops\\\/#listItem\",\"name\":\"Training and workshops\"}}]},{\"@type\":\"Organization\",\"@id\":\"https:\\\/\\\/www.lablogic.pl\\\/#organization\",\"name\":\"LabLogic\",\"description\":\"DPO, GDPR, NIS2 and cybersecurity in practice\",\"url\":\"https:\\\/\\\/www.lablogic.pl\\\/en\\\/\",\"email\":\"m.rutkowski@lablogic.pl\",\"telephone\":\"+48586231777\",\"foundingDate\":\"2004\",\"logo\":{\"@type\":\"ImageObject\",\"url\":\"https:\\\/\\\/www.lablogic.pl\\\/wp-content\\\/uploads\\\/2026\\\/08\\\/cropped-lablogic-site-icon-512.png\",\"@id\":\"https:\\\/\\\/www.lablogic.pl\\\/en\\\/who-needs-nis2-training-besides-the-board\\\/#organizationLogo\",\"width\":512,\"height\":512},\"image\":{\"@id\":\"https:\\\/\\\/www.lablogic.pl\\\/en\\\/who-needs-nis2-training-besides-the-board\\\/#organizationLogo\"},\"sameAs\":[\"https:\\\/\\\/www.linkedin.com\\\/in\\\/michal-rutkowski-iod\"],\"additionalType\":\"https:\\\/\\\/schema.org\\\/ProfessionalService\",\"legalName\":\"LabLogic Consulting Micha\\u0142 Rutkowski\",\"address\":{\"@type\":\"PostalAddress\",\"streetAddress\":\"ul. Wolno\\u015bci 15\",\"postalCode\":\"81-327\",\"addressLocality\":\"Gdynia\",\"addressRegion\":\"pomorskie\",\"addressCountry\":\"PL\"},\"vatID\":\"PL9580972114\",\"taxID\":\"9580972114\",\"areaServed\":{\"@type\":\"Country\",\"name\":\"Poland\"},\"knowsAbout\":[\"GDPR\",\"Data Protection Officer (DPO)\",\"NIS2 Directive\",\"Polish National Cybersecurity System Act (KSC)\",\"Cybersecurity incident and data breach response\",\"EU AI Act\",\"ISO\\\/IEC 27001\",\"Information security management\"],\"founder\":{\"@id\":\"https:\\\/\\\/www.lablogic.pl\\\/#michal-rutkowski\"},\"hasOfferCatalog\":{\"@type\":\"OfferCatalog\",\"name\":\"Services\",\"itemListElement\":[{\"@type\":\"Offer\",\"itemOffered\":{\"@type\":\"Service\",\"name\":\"External Data Protection Officer (DPO)\",\"url\":\"https:\\\/\\\/www.lablogic.pl\\\/en\\\/external-dpo\\\/\"}},{\"@type\":\"Offer\",\"itemOffered\":{\"@type\":\"Service\",\"name\":\"NIS2 and KSC implementation support\",\"url\":\"https:\\\/\\\/www.lablogic.pl\\\/en\\\/nis2-ksc\\\/\"}},{\"@type\":\"Offer\",\"itemOffered\":{\"@type\":\"Service\",\"name\":\"Incident and data breach response\",\"url\":\"https:\\\/\\\/www.lablogic.pl\\\/en\\\/incident-response\\\/\"}},{\"@type\":\"Offer\",\"itemOffered\":{\"@type\":\"Service\",\"name\":\"GDPR and NIS2 training\",\"url\":\"https:\\\/\\\/www.lablogic.pl\\\/en\\\/training\\\/\"}},{\"@type\":\"Offer\",\"itemOffered\":{\"@type\":\"Service\",\"name\":\"AI Act: roles, obligations and preparation\",\"url\":\"https:\\\/\\\/www.lablogic.pl\\\/en\\\/ai-act\\\/\"}}]}},{\"@type\":\"Person\",\"@id\":\"https:\\\/\\\/www.lablogic.pl\\\/#michal-rutkowski\",\"url\":\"https:\\\/\\\/www.lablogic.pl\\\/michal-rutkowski\\\/\",\"name\":\"Micha\\u0142 Rutkowski\",\"image\":{\"@type\":\"ImageObject\",\"@id\":\"https:\\\/\\\/www.lablogic.pl\\\/#michal-rutkowski-portret\",\"url\":\"https:\\\/\\\/www.lablogic.pl\\\/wp-content\\\/uploads\\\/2026\\\/08\\\/michal-rutkowski-iod-dpo-rodo-nis2-lablogic.webp\",\"width\":864,\"height\":1080,\"caption\":\"Micha\\u0142 Rutkowski\"},\"sameAs\":[\"https:\\\/\\\/www.linkedin.com\\\/in\\\/michal-rutkowski-iod\"],\"jobTitle\":\"Data Protection Officer (DPO), NIS2\\\/KSC and cybersecurity advisor\",\"description\":\"Data protection and cybersecurity practitioner, owner of LabLogic. Since 2004 he has supported medium and large organisations: audits, implementations, incidents and training.\",\"email\":\"m.rutkowski@lablogic.pl\",\"knowsAbout\":[\"GDPR\",\"Data Protection Officer (DPO)\",\"NIS2 Directive\",\"Polish National Cybersecurity System Act (KSC)\",\"Cybersecurity incident and data breach response\",\"EU AI Act\",\"ISO\\\/IEC 27001\",\"Information security management\"],\"worksFor\":{\"@id\":\"https:\\\/\\\/www.lablogic.pl\\\/#organization\"}},{\"@type\":\"WebPage\",\"@id\":\"https:\\\/\\\/www.lablogic.pl\\\/en\\\/who-needs-nis2-training-besides-the-board\\\/#webpage\",\"url\":\"https:\\\/\\\/www.lablogic.pl\\\/en\\\/who-needs-nis2-training-besides-the-board\\\/\",\"name\":\"NIS2 training for employees \\u2014 who else has to be trained\",\"description\":\"The KSC Act names only the head of the entity and the person entrusted with their duties. See how to derive the remaining groups from Articles 8 and 11.\",\"inLanguage\":\"en-US\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/www.lablogic.pl\\\/en\\\/#website\"},\"breadcrumb\":{\"@id\":\"https:\\\/\\\/www.lablogic.pl\\\/en\\\/who-needs-nis2-training-besides-the-board\\\/#breadcrumblist\"},\"author\":{\"@id\":\"https:\\\/\\\/www.lablogic.pl\\\/#michal-rutkowski\"},\"creator\":{\"@id\":\"https:\\\/\\\/www.lablogic.pl\\\/#michal-rutkowski\"},\"image\":{\"@type\":\"ImageObject\",\"url\":\"https:\\\/\\\/www.lablogic.pl\\\/wp-content\\\/uploads\\\/2026\\\/09\\\/ll-og-who-needs-nis2-training-besides-the-board-en-1.jpg\",\"@id\":\"https:\\\/\\\/www.lablogic.pl\\\/en\\\/who-needs-nis2-training-besides-the-board\\\/#mainImage\",\"width\":1200,\"height\":630,\"caption\":\"Who else needs NIS2 training? \\u2014 LabLogic article graphic by Micha\\u0142 Rutkowski\"},\"primaryImageOfPage\":{\"@id\":\"https:\\\/\\\/www.lablogic.pl\\\/en\\\/who-needs-nis2-training-besides-the-board\\\/#mainImage\"},\"datePublished\":\"2026-08-18T09:00:00+02:00\",\"dateModified\":\"2026-09-27T19:59:29+02:00\"},{\"@type\":\"WebSite\",\"@id\":\"https:\\\/\\\/www.lablogic.pl\\\/en\\\/#website\",\"url\":\"https:\\\/\\\/www.lablogic.pl\\\/en\\\/\",\"name\":\"Micha\\u0142 Rutkowski - LabLogic\",\"alternateName\":\"LabLogic\",\"description\":\"DPO, GDPR, NIS2 and cybersecurity in practice\",\"inLanguage\":\"en-US\",\"publisher\":{\"@id\":\"https:\\\/\\\/www.lablogic.pl\\\/#organization\"}}]}\n\t\t<\/script>\n\t\t<!-- All in One SEO -->\n\n","aioseo_head_json":{"title":"NIS2 training for employees \u2014 who else has to be trained","description":"The KSC Act names only the head of the entity and the person entrusted with their duties. See how to derive the remaining groups from Articles 8 and 11.","canonical_url":"https:\/\/www.lablogic.pl\/en\/who-needs-nis2-training-besides-the-board\/","robots":"max-image-preview:large","keywords":"","webmasterTools":{"miscellaneous":""},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"Article","@id":"https:\/\/www.lablogic.pl\/en\/who-needs-nis2-training-besides-the-board\/#article","name":"NIS2 training for employees \u2014 who else has to be trained","headline":"Who else needs NIS2 training besides the management board?","author":{"@id":"https:\/\/www.lablogic.pl\/#michal-rutkowski"},"publisher":{"@id":"https:\/\/www.lablogic.pl\/#organization"},"image":{"@type":"ImageObject","url":"https:\/\/www.lablogic.pl\/wp-content\/uploads\/2026\/09\/ll-og-who-needs-nis2-training-besides-the-board-en-1.jpg","width":1200,"height":630,"caption":"Who else needs NIS2 training? \u2014 LabLogic article graphic by Micha\u0142 Rutkowski"},"datePublished":"2026-08-18T09:00:00+02:00","dateModified":"2026-09-27T19:59:29+02:00","inLanguage":"en-US","mainEntityOfPage":{"@id":"https:\/\/www.lablogic.pl\/en\/who-needs-nis2-training-besides-the-board\/#webpage"},"isPartOf":{"@id":"https:\/\/www.lablogic.pl\/en\/who-needs-nis2-training-besides-the-board\/#webpage"},"articleSection":"Training and workshops"},{"@type":"BreadcrumbList","@id":"https:\/\/www.lablogic.pl\/en\/who-needs-nis2-training-besides-the-board\/#breadcrumblist","itemListElement":[{"@type":"ListItem","@id":"https:\/\/www.lablogic.pl\/en\/#listItem","position":1,"name":"LabLogic","item":"https:\/\/www.lablogic.pl\/en\/","nextItem":{"@type":"ListItem","@id":"https:\/\/www.lablogic.pl\/en\/baza-wiedzy\/workshops\/#listItem","name":"Training and workshops"}},{"@type":"ListItem","@id":"https:\/\/www.lablogic.pl\/en\/baza-wiedzy\/workshops\/#listItem","position":2,"name":"Training and workshops","item":"https:\/\/www.lablogic.pl\/en\/baza-wiedzy\/workshops\/","nextItem":{"@type":"ListItem","@id":"https:\/\/www.lablogic.pl\/en\/who-needs-nis2-training-besides-the-board\/#listItem","name":"Who else needs NIS2 training besides the management board?"},"previousItem":{"@type":"ListItem","@id":"https:\/\/www.lablogic.pl\/en\/#listItem","name":"LabLogic"}},{"@type":"ListItem","@id":"https:\/\/www.lablogic.pl\/en\/who-needs-nis2-training-besides-the-board\/#listItem","position":3,"name":"Who else needs NIS2 training besides the management board?","previousItem":{"@type":"ListItem","@id":"https:\/\/www.lablogic.pl\/en\/baza-wiedzy\/workshops\/#listItem","name":"Training and workshops"}}]},{"@type":"Organization","@id":"https:\/\/www.lablogic.pl\/#organization","name":"LabLogic","description":"DPO, GDPR, NIS2 and cybersecurity in practice","url":"https:\/\/www.lablogic.pl\/en\/","email":"m.rutkowski@lablogic.pl","telephone":"+48586231777","foundingDate":"2004","logo":{"@type":"ImageObject","url":"https:\/\/www.lablogic.pl\/wp-content\/uploads\/2026\/08\/cropped-lablogic-site-icon-512.png","@id":"https:\/\/www.lablogic.pl\/en\/who-needs-nis2-training-besides-the-board\/#organizationLogo","width":512,"height":512},"image":{"@id":"https:\/\/www.lablogic.pl\/en\/who-needs-nis2-training-besides-the-board\/#organizationLogo"},"sameAs":["https:\/\/www.linkedin.com\/in\/michal-rutkowski-iod"],"additionalType":"https:\/\/schema.org\/ProfessionalService","legalName":"LabLogic Consulting Micha\u0142 Rutkowski","address":{"@type":"PostalAddress","streetAddress":"ul. Wolno\u015bci 15","postalCode":"81-327","addressLocality":"Gdynia","addressRegion":"pomorskie","addressCountry":"PL"},"vatID":"PL9580972114","taxID":"9580972114","areaServed":{"@type":"Country","name":"Poland"},"knowsAbout":["GDPR","Data Protection Officer (DPO)","NIS2 Directive","Polish National Cybersecurity System Act (KSC)","Cybersecurity incident and data breach response","EU AI Act","ISO\/IEC 27001","Information security management"],"founder":{"@id":"https:\/\/www.lablogic.pl\/#michal-rutkowski"},"hasOfferCatalog":{"@type":"OfferCatalog","name":"Services","itemListElement":[{"@type":"Offer","itemOffered":{"@type":"Service","name":"External Data Protection Officer (DPO)","url":"https:\/\/www.lablogic.pl\/en\/external-dpo\/"}},{"@type":"Offer","itemOffered":{"@type":"Service","name":"NIS2 and KSC implementation support","url":"https:\/\/www.lablogic.pl\/en\/nis2-ksc\/"}},{"@type":"Offer","itemOffered":{"@type":"Service","name":"Incident and data breach response","url":"https:\/\/www.lablogic.pl\/en\/incident-response\/"}},{"@type":"Offer","itemOffered":{"@type":"Service","name":"GDPR and NIS2 training","url":"https:\/\/www.lablogic.pl\/en\/training\/"}},{"@type":"Offer","itemOffered":{"@type":"Service","name":"AI Act: roles, obligations and preparation","url":"https:\/\/www.lablogic.pl\/en\/ai-act\/"}}]}},{"@type":"Person","@id":"https:\/\/www.lablogic.pl\/#michal-rutkowski","url":"https:\/\/www.lablogic.pl\/michal-rutkowski\/","name":"Micha\u0142 Rutkowski","image":{"@type":"ImageObject","@id":"https:\/\/www.lablogic.pl\/#michal-rutkowski-portret","url":"https:\/\/www.lablogic.pl\/wp-content\/uploads\/2026\/08\/michal-rutkowski-iod-dpo-rodo-nis2-lablogic.webp","width":864,"height":1080,"caption":"Micha\u0142 Rutkowski"},"sameAs":["https:\/\/www.linkedin.com\/in\/michal-rutkowski-iod"],"jobTitle":"Data Protection Officer (DPO), NIS2\/KSC and cybersecurity advisor","description":"Data protection and cybersecurity practitioner, owner of LabLogic. Since 2004 he has supported medium and large organisations: audits, implementations, incidents and training.","email":"m.rutkowski@lablogic.pl","knowsAbout":["GDPR","Data Protection Officer (DPO)","NIS2 Directive","Polish National Cybersecurity System Act (KSC)","Cybersecurity incident and data breach response","EU AI Act","ISO\/IEC 27001","Information security management"],"worksFor":{"@id":"https:\/\/www.lablogic.pl\/#organization"}},{"@type":"WebPage","@id":"https:\/\/www.lablogic.pl\/en\/who-needs-nis2-training-besides-the-board\/#webpage","url":"https:\/\/www.lablogic.pl\/en\/who-needs-nis2-training-besides-the-board\/","name":"NIS2 training for employees \u2014 who else has to be trained","description":"The KSC Act names only the head of the entity and the person entrusted with their duties. See how to derive the remaining groups from Articles 8 and 11.","inLanguage":"en-US","isPartOf":{"@id":"https:\/\/www.lablogic.pl\/en\/#website"},"breadcrumb":{"@id":"https:\/\/www.lablogic.pl\/en\/who-needs-nis2-training-besides-the-board\/#breadcrumblist"},"author":{"@id":"https:\/\/www.lablogic.pl\/#michal-rutkowski"},"creator":{"@id":"https:\/\/www.lablogic.pl\/#michal-rutkowski"},"image":{"@type":"ImageObject","url":"https:\/\/www.lablogic.pl\/wp-content\/uploads\/2026\/09\/ll-og-who-needs-nis2-training-besides-the-board-en-1.jpg","@id":"https:\/\/www.lablogic.pl\/en\/who-needs-nis2-training-besides-the-board\/#mainImage","width":1200,"height":630,"caption":"Who else needs NIS2 training? \u2014 LabLogic article graphic by Micha\u0142 Rutkowski"},"primaryImageOfPage":{"@id":"https:\/\/www.lablogic.pl\/en\/who-needs-nis2-training-besides-the-board\/#mainImage"},"datePublished":"2026-08-18T09:00:00+02:00","dateModified":"2026-09-27T19:59:29+02:00"},{"@type":"WebSite","@id":"https:\/\/www.lablogic.pl\/en\/#website","url":"https:\/\/www.lablogic.pl\/en\/","name":"Micha\u0142 Rutkowski - LabLogic","alternateName":"LabLogic","description":"DPO, GDPR, NIS2 and cybersecurity in practice","inLanguage":"en-US","publisher":{"@id":"https:\/\/www.lablogic.pl\/#organization"}}]},"og:locale":"en_US","og:site_name":"LabLogic - Micha\u0142 Rutkowski | DPO, GDPR, NIS2 and cybersecurity in practice","og:type":"article","og:title":"Who to train on NIS2 besides the board","og:description":"The Act names two roles; the rest you derive from Articles 8 and 11.","og:url":"https:\/\/www.lablogic.pl\/en\/who-needs-nis2-training-besides-the-board\/","og:image":"https:\/\/www.lablogic.pl\/wp-content\/uploads\/2026\/09\/ll-og-who-needs-nis2-training-besides-the-board-en-1.jpg","og:image:secure_url":"https:\/\/www.lablogic.pl\/wp-content\/uploads\/2026\/09\/ll-og-who-needs-nis2-training-besides-the-board-en-1.jpg","og:image:width":1200,"og:image:height":630,"article:section":"Training and workshops","article:tag":["nis2","ksc","training","compliance"],"article:published_time":"2026-08-18T07:00:00+00:00","article:modified_time":"2026-09-27T17:59:29+00:00","twitter:card":"summary_large_image","twitter:title":"Who to train on NIS2 besides the board","twitter:description":"The Act names two roles; the rest you derive from Articles 8 and 11.","twitter:image":"https:\/\/www.lablogic.pl\/wp-content\/uploads\/2026\/09\/ll-og-who-needs-nis2-training-besides-the-board-en-1.jpg"},"aioseo_meta_data":{"post_id":"4111","title":"NIS2 training for employees \u2014 who else has to be trained","description":"The KSC Act names only the head of the entity and the person entrusted with their duties. See how to derive the remaining groups from Articles 8 and 11.","keywords":null,"keyphrases":{"focus":{"keyphrase":"NIS2 training for employees","score":61},"additional":[{"keyphrase":"who to train under NIS2","score":69},{"keyphrase":"KSC training obligation","score":69},{"keyphrase":"staff cybersecurity education","score":69},{"keyphrase":"training for the head of the entity","score":63}]},"primary_term":null,"canonical_url":null,"og_title":"Who to train on NIS2 besides the board","og_description":"The Act names two roles; the rest you derive from Articles 8 and 11.","og_object_type":"article","og_image_type":"default","og_image_url":null,"og_image_width":null,"og_image_height":null,"og_image_custom_url":null,"og_image_custom_fields":null,"og_video":"","og_custom_url":null,"og_article_section":"Training and workshops","og_article_tags":[{"label":"NIS2","value":"NIS2"},{"label":"KSC","value":"KSC"},{"label":"training","value":"training"},{"label":"compliance","value":"compliance"}],"twitter_use_og":true,"twitter_card":"summary_large_image","twitter_image_type":"default","twitter_image_url":null,"twitter_image_custom_url":null,"twitter_image_custom_fields":null,"twitter_title":null,"twitter_description":null,"schema":{"blockGraphs":[],"customGraphs":[],"default":{"data":{"Article":[],"Course":[],"Dataset":[],"FAQPage":[],"Movie":[],"Person":[],"Product":[],"ProductReview":[],"Car":[],"Recipe":[],"Service":[],"SoftwareApplication":[],"WebPage":[]},"graphName":"Article","isEnabled":true},"graphs":[]},"schema_type":"default","schema_type_options":null,"pillar_content":false,"robots_default":true,"robots_noindex":false,"robots_noarchive":false,"robots_nosnippet":false,"robots_nofollow":false,"robots_noimageindex":false,"robots_noodp":false,"robots_notranslate":false,"robots_max_snippet":"-1","robots_max_videopreview":"-1","robots_max_imagepreview":"large","priority":0,"frequency":"default","local_seo":null,"breadcrumb_settings":null,"limit_modified_date":false,"ai":{"faqs":[],"keyPoints":[],"schemas":[],"titles":[],"descriptions":[],"socialPosts":{"email":{"subject":"","preview":"","content":""},"linkedin":[],"twitter":[],"facebook":[],"instagram":[]}},"created":"2026-08-19 21:13:52","updated":"2026-09-27 18:01:44","seo_analyzer_scan_date":null,"focus_keyword":"NIS2 training for employees","additional_keywords":[{"word":"who to train under NIS2","score":69,"items":{"introductionKeyword":{"score":3},"keyphraseLength":{"score":9},"keyphraseDensity":{"score":4},"functionWordsInKeyphrase":{"score":9},"textCompetingLinks":{"score":9},"imageKeyphrase":{"score":3}}},{"word":"KSC training obligation","score":69,"items":{"introductionKeyword":{"score":3},"keyphraseLength":{"score":9},"keyphraseDensity":{"score":4},"functionWordsInKeyphrase":{"score":9},"textCompetingLinks":{"score":9},"imageKeyphrase":{"score":3}}},{"word":"staff cybersecurity education","score":69,"items":{"introductionKeyword":{"score":3},"keyphraseLength":{"score":9},"keyphraseDensity":{"score":4},"functionWordsInKeyphrase":{"score":9},"textCompetingLinks":{"score":9},"imageKeyphrase":{"score":3}}},{"word":"training for the head of the entity","score":63,"items":{"introductionKeyword":{"score":3},"keyphraseLength":{"score":6},"keyphraseDensity":{"score":4},"functionWordsInKeyphrase":{"score":9},"textCompetingLinks":{"score":9},"imageKeyphrase":{"score":3}}}],"truseo_locale":null},"spectra_blocks_featured_image_url":{"thumbnail":{"url":"https:\/\/www.lablogic.pl\/wp-content\/uploads\/2026\/09\/ll-og-who-needs-nis2-training-besides-the-board-en-1-150x150.jpg","width":150,"height":150},"medium":{"url":"https:\/\/www.lablogic.pl\/wp-content\/uploads\/2026\/09\/ll-og-who-needs-nis2-training-besides-the-board-en-1-300x158.jpg","width":300,"height":158},"medium_large":{"url":"https:\/\/www.lablogic.pl\/wp-content\/uploads\/2026\/09\/ll-og-who-needs-nis2-training-besides-the-board-en-1-768x403.jpg","width":768,"height":403},"large":{"url":"https:\/\/www.lablogic.pl\/wp-content\/uploads\/2026\/09\/ll-og-who-needs-nis2-training-besides-the-board-en-1-1024x538.jpg","width":1024,"height":538},"full":{"url":"https:\/\/www.lablogic.pl\/wp-content\/uploads\/2026\/09\/ll-og-who-needs-nis2-training-besides-the-board-en-1.jpg","width":1200,"height":630}},"spectra_blocks_author_info":{"display_name":"Micha\u0142 Rutkowski","avatar_url":"https:\/\/secure.gravatar.com\/avatar\/29f5af5a0ce65a4307813722032192bdf08e740cbda98b61aa73b548422ff768?s=96&d=mm&r=g","author_link":"https:\/\/www.lablogic.pl\/en\/author\/michal-rutkowski\/","description":"Micha\u0142 Rutkowski \u2014 praktyk ochrony danych i cyberbezpiecze\u0144stwa, w\u0142a\u015bciciel LabLogic. Od 2004 roku pracuje na styku technologii, ochrony danych i zarz\u0105dzania ryzykiem. Pe\u0142ni funkcj\u0119 zewn\u0119trznego IOD\/DPO, prowadzi audyty RODO, kwalifikacj\u0119 i wdro\u017cenia NIS2 oraz ustawy o KSC, wspiera organizacje przy incydentach i naruszeniach ochrony danych, szkoli zarz\u0105dy, kadr\u0119 kierownicz\u0105 oraz zespo\u0142y IT i compliance. Pracuje ze \u015brednimi i du\u017cymi organizacjami, w tym z sektora finansowego i bran\u017c regulowanych."},"_links":{"self":[{"href":"https:\/\/www.lablogic.pl\/en\/wp-json\/wp\/v2\/posts\/4111","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.lablogic.pl\/en\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.lablogic.pl\/en\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.lablogic.pl\/en\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/www.lablogic.pl\/en\/wp-json\/wp\/v2\/comments?post=4111"}],"version-history":[{"count":5,"href":"https:\/\/www.lablogic.pl\/en\/wp-json\/wp\/v2\/posts\/4111\/revisions"}],"predecessor-version":[{"id":5696,"href":"https:\/\/www.lablogic.pl\/en\/wp-json\/wp\/v2\/posts\/4111\/revisions\/5696"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.lablogic.pl\/en\/wp-json\/wp\/v2\/media\/5562"}],"wp:attachment":[{"href":"https:\/\/www.lablogic.pl\/en\/wp-json\/wp\/v2\/media?parent=4111"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.lablogic.pl\/en\/wp-json\/wp\/v2\/categories?post=4111"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.lablogic.pl\/en\/wp-json\/wp\/v2\/tags?post=4111"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}