<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>GRC Archives - Relations Security</title>
	<atom:link href="https://relationsec.net/category/grc/feed/" rel="self" type="application/rss+xml" />
	<link>https://relationsec.net/category/grc/</link>
	<description>CyberSecurity Consulting</description>
	<lastBuildDate>Fri, 04 Sep 2026 06:04:25 +0000</lastBuildDate>
	<language>en-US</language>
	<sy:updatePeriod>
	hourly	</sy:updatePeriod>
	<sy:updateFrequency>
	1	</sy:updateFrequency>
	<generator>https://wordpress.org/?v=7.1.3</generator>

<image>
	<url>https://relationsec.net/wp-content/uploads/2024/01/Fichier-1.svg</url>
	<title>GRC Archives - Relations Security</title>
	<link>https://relationsec.net/category/grc/</link>
	<width>32</width>
	<height>32</height>
</image> 
	<item>
		<title>CUI protection is about to stop being a defense-only problem.</title>
		<link>https://relationsec.net/far-cui-rule-nist-800-171-training/</link>
					<comments>https://relationsec.net/far-cui-rule-nist-800-171-training/#respond</comments>
		
		<dc:creator><![CDATA[Klaus Agnoletti]]></dc:creator>
		<pubDate>Fri, 03 Jul 2026 14:19:53 +0000</pubDate>
				<category><![CDATA[GRC]]></category>
		<guid isPermaLink="false">https://relationsec.net/far-cui-rule-nist-800-171-training/</guid>

					<description><![CDATA[<p>The post <a href="https://relationsec.net/far-cui-rule-nist-800-171-training/">CUI protection is about to stop being a defense-only problem.</a> appeared first on <a href="https://relationsec.net">Relations Security</a>.</p>
]]></description>
										<content:encoded><![CDATA[
<div class="et_pb_section et_pb_section_0 et_pb_with_background et_section_regular" >
				
				
				
				
				
				
				<div class="et_pb_row et_pb_row_0">
				<div class="et_pb_column et_pb_column_4_4 et_pb_column_0  et_pb_css_mix_blend_mode_passthrough et-last-child">
				
				
				
				
				<div class="et_pb_module et_pb_text et_pb_text_0  et_pb_text_align_left et_pb_bg_layout_light">
				
				
				
				
				<div class="et_pb_text_inner"><p>For years, protecting Controlled Unclassified Information to the NIST 800-171 standard has mostly meant one audience: defense contractors, and the CMMC program built to enforce it. The proposed FAR CUI rule changes who&#8217;s on the hook. It would extend NIST SP 800-171 to every federal contractor that handles CUI, civilian agencies included, and once the clause lands in your contracts there&#8217;s no phase-in period to catch up.</p>
<h2>What the FAR CUI rule actually does</h2>
<p>The FAR Council published an updated proposed rule on 23 June 2026, with a comment period running to 23 July 2026, and it&#8217;s expected to be finalized before the end of 2026. It would require any contractor whose contract identifies CUI to implement NIST SP 800-171 Revision 3, and a limited set of contractors tied to critical programs or high-value assets would also face the enhanced controls of NIST SP 800-172. The headline here is the scope. This is no longer a Department of Defense requirement. It&#8217;s a whole-of-government one.</p>
<div class="rs-timeline" role="img" aria-label="FAR CUI rule timeline: updated proposed rule published 23 June 2026, comment period closes 23 July 2026, expected to be finalized before end of 2026, and the clause is inserted at contract award with no phase-in.">
<p class="rs-tl-heading">The FAR CUI rule timeline</p>
<div class="rs-tl-track">
<div class="rs-tl-step"><div class="rs-tl-dot"></div><div class="rs-tl-date">23 June 2026</div><div class="rs-tl-label">Updated proposed rule published</div></div>
<div class="rs-tl-step"><div class="rs-tl-dot"></div><div class="rs-tl-date">23 July 2026</div><div class="rs-tl-label">Comment period closes</div></div>
<div class="rs-tl-step"><div class="rs-tl-dot"></div><div class="rs-tl-date">Before end 2026</div><div class="rs-tl-label">Expected to be finalized</div></div>
<div class="rs-tl-step is-terminal"><div class="rs-tl-dot"></div><div class="rs-tl-date">On contract award</div><div class="rs-tl-label">Clause inserted, no phase-in</div></div>
</div>
</div>
<h2>Why &#8220;we have CMMC handled&#8221; is not the same thing</h2>
<p>If you already work with the DoD, CMMC has you thinking about NIST 800-171 through third-party assessment. The FAR CUI rule is the civilian counterpart, and it reaches contractors who have never touched CMMC because they sell to agencies outside defense. The control backbone is the same, but the audience is far larger, and a lot of the newly-covered contractors are starting from a standing stop. One difference cuts the other way. Where CMMC verifies you through a third-party assessor, the FAR CUI rule leans on self-attestation. That sounds lighter, but it just moves the burden of proof onto you, and a false attestation about your own security is not a small thing to sign. If you sell to any federal agency and touch CUI, the same obligations are coming for you. The DoD-specific view is in <a href="https://relationsec.net/cmmc-incident-response-training-game/">why CMMC wants you to test your incident response</a>.</p>
<h2>The part that is about your people, not your GRC tool</h2>
<p>Most of NIST 800-171 is technical implementation, and a policy binder covers the paperwork. But two of its requirements are about human readiness, and those are the ones a document can&#8217;t fake. You have to train your people on their security roles, and you have to test your incident response capability, not just plan it. When a real CUI incident hits, the only question that matters is whether your team can actually run the response, inside the reporting deadlines, without opening the runbook for the first time.</p>
<h2>What readiness looks like</h2>
<p>It looks like the team running the incident, not narrating a plan. That&#8217;s what <a href="https://relationsec.net/malware-monsters/">Malware &amp; Monsters</a> does. It&#8217;s a <a href="https://relationsec.net/serious-games/">tabletop incident response game</a> where the scenario changes because of what the team decides, so you&#8217;re exercising the capability the standard asks you to test, and building the instinct a real CUI incident will demand. There&#8217;s a nice overlap worth naming here: a tabletop exercise is one of the artifacts these rules expect you to be able to produce. Running the game both builds the capability and gives you the evidence that you tested it. It has been run with security teams across Europe and North America.</p>
<p>The FAR CUI rule isn&#8217;t final yet, but the direction is set and there&#8217;s no phase-in waiting for you. The contractors who are ready when the clause appears will be the ones who trained and tested before they had to. If your obligations sit on the European side of the Atlantic instead, the same readiness logic runs through <a href="https://relationsec.net/eu-cyber-regulation-training/">EU cyber regulation training</a>.</p>
<h2>Frequently asked questions</h2>
<h3>What is the FAR CUI rule?</h3>
<p>It is a proposed Federal Acquisition Regulation rule, updated on 23 June 2026, that would require federal contractors whose contracts involve Controlled Unclassified Information to implement NIST SP 800-171 Revision 3. The comment period runs to 23 July 2026 and it is expected to be finalized before the end of 2026.</p>
<h3>Does the FAR CUI rule apply to non-defense contractors?</h3>
<p>Yes, that is the change. It would extend the NIST 800-171 requirement from defense contractors to all federal contractors that handle CUI, across civilian agencies too.</p>
<h3>When does it take effect?</h3>
<p>It is still a proposed rule, expected to be finalized before the end of 2026. Notably, there is no phase-in: once the clause is inserted into a contract, compliance is required from that point.</p>
<h3>How is the FAR CUI rule different from CMMC?</h3>
<p>CMMC is the DoD-specific program that verifies NIST 800-171 compliance through a third-party assessment. The FAR CUI rule applies the same standard across the whole federal government but relies on contractor self-attestation rather than an external assessor. Same control backbone, different audience, different proof.</p></div>
			</div><div class="et_pb_module et_pb_text et_pb_text_1  et_pb_text_align_left et_pb_bg_layout_light">
				
				
				
				
				<div class="et_pb_text_inner"><h2>Want to put this in front of your team?</h2>
<p>I run these as games your board and your responders actually take part in, not another slideshow. Tell me where your team is and what they need to practice, and we will set it up.</p></div>
			</div><div class="et_pb_button_module_wrapper et_pb_button_0_wrapper et_pb_button_alignment_left et_pb_module ">
				<a class="et_pb_button et_pb_button_0 et_pb_bg_layout_light" href="/contact/">Book a session</a>
			</div><div class="et_pb_module et_pb_code et_pb_code_0">
				
				
				
				
				<div class="et_pb_code_inner"><script type="application/ld+json">{  "@context": "https://schema.org",  "@type": "FAQPage",  "mainEntity": [    {      "@type": "Question",      "name": "What is the FAR CUI rule?",      "acceptedAnswer": {        "@type": "Answer",        "text": "It is a proposed Federal Acquisition Regulation rule, updated on 23 June 2026, that would require federal contractors whose contracts involve Controlled Unclassified Information to implement NIST SP 800-171 Revision 3. The comment period runs to 23 July 2026 and it is expected to be finalized before the end of 2026."      }    },    {      "@type": "Question",      "name": "Does the FAR CUI rule apply to non-defense contractors?",      "acceptedAnswer": {        "@type": "Answer",        "text": "Yes, that is the change. It would extend the NIST 800-171 requirement from defense contractors to all federal contractors that handle CUI, across civilian agencies too."      }    },    {      "@type": "Question",      "name": "When does it take effect?",      "acceptedAnswer": {        "@type": "Answer",        "text": "It is still a proposed rule, expected to be finalized before the end of 2026. Notably, there is no phase-in: once the clause is inserted into a contract, compliance is required from that point."      }    },    {      "@type": "Question",      "name": "How is the FAR CUI rule different from CMMC?",      "acceptedAnswer": {        "@type": "Answer",        "text": "CMMC is the DoD-specific program that verifies NIST 800-171 compliance through a third-party assessment. The FAR CUI rule applies the same standard across the whole federal government but relies on contractor self-attestation rather than an external assessor. Same control backbone, different audience, different proof."      }    }  ]}</script></div>
			</div>
			</div>
				
				
				
				
			</div>
				
				
			</div>




<p>The post <a href="https://relationsec.net/far-cui-rule-nist-800-171-training/">CUI protection is about to stop being a defense-only problem.</a> appeared first on <a href="https://relationsec.net">Relations Security</a>.</p>
]]></content:encoded>
					
					<wfw:commentRss>https://relationsec.net/far-cui-rule-nist-800-171-training/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
			</item>
		<item>
		<title>CMMC does not just want an IR plan. It wants you to test it.</title>
		<link>https://relationsec.net/cmmc-incident-response-training-game/</link>
					<comments>https://relationsec.net/cmmc-incident-response-training-game/#respond</comments>
		
		<dc:creator><![CDATA[Klaus Agnoletti]]></dc:creator>
		<pubDate>Fri, 03 Jul 2026 14:14:44 +0000</pubDate>
				<category><![CDATA[GRC]]></category>
		<guid isPermaLink="false">https://relationsec.net/cmmc-incident-response-training-game/</guid>

					<description><![CDATA[<p>The post <a href="https://relationsec.net/cmmc-incident-response-training-game/">CMMC does not just want an IR plan. It wants you to test it.</a> appeared first on <a href="https://relationsec.net">Relations Security</a>.</p>
]]></description>
										<content:encoded><![CDATA[
<div class="et_pb_section et_pb_section_1 et_pb_with_background et_section_regular" >
				
				
				
				
				
				
				<div class="et_pb_row et_pb_row_1">
				<div class="et_pb_column et_pb_column_4_4 et_pb_column_1  et_pb_css_mix_blend_mode_passthrough et-last-child">
				
				
				
				
				<div class="et_pb_module et_pb_text et_pb_text_2  et_pb_text_align_left et_pb_bg_layout_light">
				
				
				
				
				<div class="et_pb_text_inner"><p>CMMC certification is how a company stays eligible for US Department of Defense contracts, and it asks for more than a binder of policies. To reach Level 2 you have to meet the practices in NIST SP 800-171, and two of them are about your people, not your paperwork. You have to train them, and you have to test your incident response capability. A slide deck and a filed plan satisfy neither one, at least not in the way an assessor actually checks.</p>
<h2>What CMMC asks of your people</h2>
<p>Level 2 aligns to the 110 practices of NIST SP 800-171, and sitting among the technical controls are a couple that are squarely about human readiness. The Awareness and Training family requires you to make your people aware of security risks and train them on their specific roles. The Incident Response family goes further than &#8220;have a plan&#8221;: practice 3.6.3 requires you to test the organizational incident response capability. Not document it. Test it. That&#8217;s a verb an auditor can ask you to evidence.</p>
<div class="rs-compare" role="img" aria-label="What CMMC and NIST 800-171 ask, matched to what a tabletop delivers. CMMC asks you to train people on their security roles under the Awareness and Training family, test the incident response capability under practice 3.6.3, and prove it to a third-party assessor. A tabletop delivers this by having the team run the response rather than a slide deck, changing the scenario with what they decide, and producing the evidence you tested it."><p class="rs-cmp-heading">What CMMC asks, what a tabletop delivers</p><div class="rs-cmp-cols"><div class="rs-cmp-col"><div class="rs-cmp-colhead">What CMMC and NIST 800-171 ask</div><div class="rs-cmp-item">Train people on their security roles (Awareness and Training)</div><div class="rs-cmp-item">Test the incident response capability (practice 3.6.3)</div><div class="rs-cmp-item">Prove it to a third-party assessor (NIST 800-171)</div></div><div class="rs-cmp-col rs-cmp-col-deliver"><div class="rs-cmp-colhead">What a tabletop delivers</div><div class="rs-cmp-item">The team runs the response, not a slide deck</div><div class="rs-cmp-item">The scenario changes with what they decide</div><div class="rs-cmp-item">You produce the evidence you tested it</div></div></div></div>
<h2>Why the checklist is the default</h2>
<p>The checklist is the obvious answer, and for good reasons. A lot of CMMC is genuine technical implementation, and a self-assessment or a tabletop template produces the artifact a C3PAO assessor expects to see. If the goal were to show that an IR plan exists, the template would be enough. But the practice doesn&#8217;t ask whether a plan exists. It asks whether the capability works.</p>
<h2>A tested capability is not a filed plan</h2>
<p>An incident response plan nobody has run is a set of assumptions about how your team will behave during a breach involving controlled unclassified information. Who declares the incident. Who talks to the prime contractor and to the government. Whether the runbook still matches the systems you have now. You don&#8217;t find those gaps by reviewing the document, and neither does the assessor. You find them by running it under pressure, before a real incident and a real audit find them for you.</p>
<h2>What testing your IR capability looks like</h2>
<p>It looks like the team working a real incident, making the calls, and living with the consequences on the table instead of in production. That&#8217;s what <a href="https://relationsec.net/malware-monsters/">Malware &amp; Monsters</a> does. It&#8217;s a tabletop incident response game where the scenario changes because of what the team decides, so you&#8217;re exercising the capability CMMC 3.6.3 asks you to test, not narrating a plan. It has been run with security teams across Europe and North America, and it sits in the wider <a href="https://relationsec.net/serious-games/">serious games</a> catalog alongside my other facilitated tabletop exercises.</p>
<p>CMMC is US defense contracting today, but the same NIST 800-171 backbone is about to reach every federal contractor under the <a href="https://relationsec.net/far-cui-rule-nist-800-171-training/">proposed FAR CUI rule</a>. The readiness problem is also exactly the one the EU is now legislating for its own entities. If you operate on both sides of the Atlantic, the EU equivalents are in <a href="https://relationsec.net/eu-cyber-regulation-training/">game-based training for EU cyber regulation</a>.</p>
<h2>Frequently asked questions</h2>
<h3>Does CMMC require incident response testing?</h3>
<p>Yes. CMMC Level 2 aligns to NIST SP 800-171, and practice 3.6.3 requires you to test the organizational incident response capability, not just document a plan.</p>
<h3>Does CMMC require security training?</h3>
<p>Yes. The Awareness and Training practices require you to make personnel aware of security risks and train them on their assigned security roles and responsibilities.</p>
<h3>What is CMMC Level 2?</h3>
<p>Level 2 is the Advanced level of CMMC 2.0, aligned to the 110 practices of NIST SP 800-171, required for contractors that handle Controlled Unclassified Information, and assessed by a third party for most.</p>
<h3>Can a game help with CMMC compliance?</h3>
<p>A game does not certify you, but it directly serves the human practices CMMC checks: it tests your incident response capability and trains your people on their roles, which is exactly what a tabletop like Malware &amp; Monsters is built to do.</p></div>
			</div><div class="et_pb_module et_pb_text et_pb_text_3  et_pb_text_align_left et_pb_bg_layout_light">
				
				
				
				
				<div class="et_pb_text_inner"><h2>Want to put this in front of your team?</h2>
<p>I run these as games your board and your responders actually take part in, not another slideshow. Tell me where your team is and what they need to practice, and we will set it up.</p></div>
			</div><div class="et_pb_button_module_wrapper et_pb_button_1_wrapper et_pb_button_alignment_left et_pb_module ">
				<a class="et_pb_button et_pb_button_1 et_pb_bg_layout_light" href="/contact/">Book a session</a>
			</div><div class="et_pb_module et_pb_code et_pb_code_1">
				
				
				
				
				<div class="et_pb_code_inner"><script type="application/ld+json">{  "@context": "https://schema.org",  "@type": "FAQPage",  "mainEntity": [    {      "@type": "Question",      "name": "Does CMMC require incident response testing?",      "acceptedAnswer": {        "@type": "Answer",        "text": "Yes. CMMC Level 2 aligns to NIST SP 800-171, and practice 3.6.3 requires you to test the organizational incident response capability, not just document a plan."      }    },    {      "@type": "Question",      "name": "Does CMMC require security training?",      "acceptedAnswer": {        "@type": "Answer",        "text": "Yes. The Awareness and Training practices require you to make personnel aware of security risks and train them on their assigned security roles and responsibilities."      }    },    {      "@type": "Question",      "name": "What is CMMC Level 2?",      "acceptedAnswer": {        "@type": "Answer",        "text": "Level 2 is the Advanced level of CMMC 2.0, aligned to the 110 practices of NIST SP 800-171, required for contractors that handle Controlled Unclassified Information, and assessed by a third party for most."      }    },    {      "@type": "Question",      "name": "Can a game help with CMMC compliance?",      "acceptedAnswer": {        "@type": "Answer",        "text": "A game does not certify you, but it directly serves the human practices CMMC checks: it tests your incident response capability and trains your people on their roles, which is exactly what a tabletop like Malware & Monsters is built to do."      }    }  ]}</script></div>
			</div>
			</div>
				
				
				
				
			</div>
				
				
			</div>





<p>The post <a href="https://relationsec.net/cmmc-incident-response-training-game/">CMMC does not just want an IR plan. It wants you to test it.</a> appeared first on <a href="https://relationsec.net">Relations Security</a>.</p>
]]></content:encoded>
					
					<wfw:commentRss>https://relationsec.net/cmmc-incident-response-training-game/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
			</item>
		<item>
		<title>DORA says test your resilience. A document is not a test.</title>
		<link>https://relationsec.net/dora-operational-resilience-testing-tabletop/</link>
					<comments>https://relationsec.net/dora-operational-resilience-testing-tabletop/#respond</comments>
		
		<dc:creator><![CDATA[Klaus Agnoletti]]></dc:creator>
		<pubDate>Fri, 03 Jul 2026 13:57:31 +0000</pubDate>
				<category><![CDATA[GRC]]></category>
		<guid isPermaLink="false">https://relationsec.net/dora-operational-resilience-testing-tabletop/</guid>

					<description><![CDATA[<p>The post <a href="https://relationsec.net/dora-operational-resilience-testing-tabletop/">DORA says test your resilience. A document is not a test.</a> appeared first on <a href="https://relationsec.net">Relations Security</a>.</p>
]]></description>
										<content:encoded><![CDATA[
<div class="et_pb_section et_pb_section_2 et_pb_with_background et_section_regular" >
				
				
				
				
				
				
				<div class="et_pb_row et_pb_row_2">
				<div class="et_pb_column et_pb_column_4_4 et_pb_column_2  et_pb_css_mix_blend_mode_passthrough et-last-child">
				
				
				
				
				<div class="et_pb_module et_pb_text et_pb_text_4  et_pb_text_align_left et_pb_bg_layout_light">
				
				
				
				
				<div class="et_pb_text_inner"><p>DORA made operational resilience testing a legal duty for financial entities across the EU, not an internal best practice. It expects a real testing program and business-continuity arrangements that actually work. Plenty of firms are handling that with a documented plan and a checklist. The document proves you have a plan. It proves nothing about whether the plan works, or whether the people who&#8217;d have to run it can.</p>
<h2>What DORA actually requires</h2>
<p>DORA isn&#8217;t a paperwork exercise dressed up as resilience. Article 11 requires ICT business continuity policies and response and recovery plans that are maintained and tested. Articles 24 to 26 require a program of digital operational resilience testing of your ICT systems, and for the larger entities, advanced threat-led penetration testing. The word doing all the work there is testing. DORA doesn&#8217;t ask you to have a continuity plan. It asks you to prove it holds up.</p>
<div class="rs-compare" role="img" aria-label="What DORA asks, matched to what a tabletop delivers. DORA asks you to maintain and test the continuity and recovery plans under Article 11, run a digital operational resilience testing program under Articles 24 to 26, and prove the plan holds rather than just file it. A tabletop delivers this by running the plan under a real disruption, finding the gaps before an incident does, and exercising the capability rather than documenting it."><p class="rs-cmp-heading">What DORA asks, what a tabletop delivers</p><div class="rs-cmp-cols"><div class="rs-cmp-col"><div class="rs-cmp-colhead">What DORA asks</div><div class="rs-cmp-item">Maintain and test the continuity and recovery plans (Article 11)</div><div class="rs-cmp-item">Run a resilience testing program (Articles 24 to 26)</div><div class="rs-cmp-item">Prove the plan holds, do not just file it</div></div><div class="rs-cmp-col rs-cmp-col-deliver"><div class="rs-cmp-colhead">What a tabletop delivers</div><div class="rs-cmp-item">You run the plan under a real disruption</div><div class="rs-cmp-item">You find the gaps before an incident does</div><div class="rs-cmp-item">You exercise the capability, not document it</div></div></div></div>
<h2>Why firms default to the checklist</h2>
<p>The checklist is the obvious answer, and it&#8217;s obvious for good reasons. It&#8217;s auditable, it&#8217;s cheap, and it produces the artifact a supervisor asks for. If the goal were to show that a plan exists on paper, the checklist would be enough. That&#8217;s just not what DORA is testing for.</p>
<h2>A plan you have never run is a hypothesis</h2>
<p>A continuity plan that&#8217;s never been exercised is a set of assumptions about how people will behave in the worst hour of their year. Who makes the call to fail over. Whether the runbook still matches the systems you actually have now. Whether the business owner and the technical team even agree on what &#8220;recovered&#8221; means. You don&#8217;t find those gaps by reviewing the document. You find them by running it, under time pressure, before a real disruption finds them for you.</p>
<h2>What resilience testing looks like when it works</h2>
<p>It looks like the team running the plan, not reading it. You take your actual continuity plan, put it under a realistic disruption with a clock, and watch where it breaks. That&#8217;s what <a href="https://relationsec.net/failover/">FAILOVER</a> does. It&#8217;s a <a href="https://relationsec.net/serious-games/">business-continuity exercise</a> run against your real plan, not a generic case study, so the gaps you find are the gaps you actually have. It&#8217;s the difference between a plan you filed and a plan you trust.</p>
<p>DORA will keep raising the bar on what counts as testing, and a checklist was never going to tell you whether your organization can actually recover. Test the plan the way you&#8217;d test anything you depend on. Run it.</p>
<p>DORA is one of several EU regimes now demanding tested capability rather than filed documents. <a href="https://relationsec.net/nis2-board-training-game-vs-seminar/">NIS2 makes the same move at board level</a>, and the game-based approach across both sits in <a href="https://relationsec.net/eu-cyber-regulation-training/">training for EU cyber regulation</a>.</p>
<h2>Frequently asked questions</h2>
<h3>Does DORA require operational resilience testing?</h3>
<p>Yes. DORA Articles 24 to 26 require a program of digital operational resilience testing of ICT systems, and Article 11 requires ICT business continuity plans that are maintained and tested. Larger entities also face threat-led penetration testing.</p>
<h3>Is a documented continuity plan enough for DORA?</h3>
<p>No. DORA is explicit that plans must be tested, not just maintained. A documented plan satisfies the paperwork but does not demonstrate the resilience DORA is asking you to prove.</p>
<h3>What counts as a DORA resilience test?</h3>
<p>Exercising your actual ICT continuity and response plans against a realistic disruption, so you find where they break before an incident does. A facilitated business-continuity exercise against your real plan, such as <a href="https://relationsec.net/failover/">FAILOVER</a>, is one way to do it.</p>
<h3>Who does DORA apply to?</h3>
<p>Financial entities in the EU and their critical ICT third-party providers. If you fall under DORA, the operational resilience testing obligation applies to you.</p></div>
			</div><div class="et_pb_module et_pb_text et_pb_text_5  et_pb_text_align_left et_pb_bg_layout_light">
				
				
				
				
				<div class="et_pb_text_inner"><h2>Want to put this in front of your team?</h2>
<p>I run these as games your board and your responders actually take part in, not another slideshow. Tell me where your team is and what they need to practice, and we will set it up.</p></div>
			</div><div class="et_pb_button_module_wrapper et_pb_button_2_wrapper et_pb_button_alignment_left et_pb_module ">
				<a class="et_pb_button et_pb_button_2 et_pb_bg_layout_light" href="/contact/">Book a session</a>
			</div><div class="et_pb_module et_pb_code et_pb_code_2">
				
				
				
				
				<div class="et_pb_code_inner"><script type="application/ld+json">{  "@context": "https://schema.org",  "@type": "FAQPage",  "mainEntity": [    {      "@type": "Question",      "name": "Does DORA require operational resilience testing?",      "acceptedAnswer": {        "@type": "Answer",        "text": "Yes. DORA Articles 24 to 26 require a program of digital operational resilience testing of ICT systems, and Article 11 requires ICT business continuity plans that are maintained and tested. Larger entities also face threat-led penetration testing."      }    },    {      "@type": "Question",      "name": "Is a documented continuity plan enough for DORA?",      "acceptedAnswer": {        "@type": "Answer",        "text": "No. DORA is explicit that plans must be tested, not just maintained. A documented plan satisfies the paperwork but does not demonstrate the resilience DORA is asking you to prove."      }    },    {      "@type": "Question",      "name": "What counts as a DORA resilience test?",      "acceptedAnswer": {        "@type": "Answer",        "text": "Exercising your actual ICT continuity and response plans against a realistic disruption, so you find where they break before an incident does. A facilitated business-continuity exercise against your real plan, such as FAILOVER, is one way to do it."      }    },    {      "@type": "Question",      "name": "Who does DORA apply to?",      "acceptedAnswer": {        "@type": "Answer",        "text": "Financial entities in the EU and their critical ICT third-party providers. If you fall under DORA, the operational resilience testing obligation applies to you."      }    }  ]}</script></div>
			</div>
			</div>
				
				
				
				
			</div>
				
				
			</div>





<p>The post <a href="https://relationsec.net/dora-operational-resilience-testing-tabletop/">DORA says test your resilience. A document is not a test.</a> appeared first on <a href="https://relationsec.net">Relations Security</a>.</p>
]]></content:encoded>
					
					<wfw:commentRss>https://relationsec.net/dora-operational-resilience-testing-tabletop/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
			</item>
		<item>
		<title>NIS2 says train your board. A slide deck will not do it.</title>
		<link>https://relationsec.net/nis2-board-training-game-vs-seminar/</link>
					<comments>https://relationsec.net/nis2-board-training-game-vs-seminar/#respond</comments>
		
		<dc:creator><![CDATA[Klaus Agnoletti]]></dc:creator>
		<pubDate>Fri, 03 Jul 2026 13:51:27 +0000</pubDate>
				<category><![CDATA[GRC]]></category>
		<guid isPermaLink="false">https://relationsec.net/nis2-board-training-game-vs-seminar/</guid>

					<description><![CDATA[<p>The post <a href="https://relationsec.net/nis2-board-training-game-vs-seminar/">NIS2 says train your board. A slide deck will not do it.</a> appeared first on <a href="https://relationsec.net">Relations Security</a>.</p>
]]></description>
										<content:encoded><![CDATA[
<div class="et_pb_section et_pb_section_3 et_pb_with_background et_section_regular" >
				
				
				
				
				
				
				<div class="et_pb_row et_pb_row_3">
				<div class="et_pb_column et_pb_column_4_4 et_pb_column_3  et_pb_css_mix_blend_mode_passthrough et-last-child">
				
				
				
				
				<div class="et_pb_module et_pb_text et_pb_text_6  et_pb_text_align_left et_pb_bg_layout_light">
				
				
				
				
				<div class="et_pb_text_inner"><p>NIS2 turned board-level security training into a legal obligation, not a nice-to-have. Article 20 puts accountability for cyber risk on the management body itself, and Article 20(2) requires those same people to be trained. Most organizations are dealing with that by booking a ninety-minute seminar or an e-learning module. It ticks the box. It does almost nothing for the thing NIS2 actually cares about.</p>
<h2>What NIS2 actually asks of your board</h2>
<p>Article 20 isn&#8217;t a training requirement bolted onto a technical directive. It&#8217;s a governance requirement. The management body has to approve the cyber risk-management measures, oversee how they&#8217;re implemented, and can be held personally liable when they get it wrong. Article 20(2) then says those same managers have to be trained to identify risks and assess the organization&#8217;s cyber risk-management practices. Read that again. The law doesn&#8217;t ask your board to be aware of cyber risk. It asks them to make and defend decisions about it.</p>
<div class="rs-compare" role="img" aria-label="What NIS2 asks of the board, matched to what a board game delivers. NIS2 asks the board to govern and oversee cyber risk and approve the measures under Article 20, be trained to identify risk and assess practice under Article 20(2), and own the measures under Article 21 and the reporting under Article 23. A board game delivers this by making them make the call in the room, defend it under pressure rather than just hear about it, and remember it because they lived it."><p class="rs-cmp-heading">What NIS2 asks, what a board game delivers</p><div class="rs-cmp-cols"><div class="rs-cmp-col"><div class="rs-cmp-colhead">What NIS2 asks of the board</div><div class="rs-cmp-item">Govern, oversee and approve the risk measures (Article 20)</div><div class="rs-cmp-item">Be trained to identify risk and assess practice (Article 20(2))</div><div class="rs-cmp-item">Own the measures and the reporting they oversee (Articles 21 and 23)</div></div><div class="rs-cmp-col rs-cmp-col-deliver"><div class="rs-cmp-colhead">What a board game delivers</div><div class="rs-cmp-item">They make the call, in the room</div><div class="rs-cmp-item">They defend it under pressure, not just hear about it</div><div class="rs-cmp-item">They remember it, because they lived it</div></div></div></div>
<h2>Why the seminar is the default</h2>
<p>The seminar is the obvious answer, and it&#8217;s obvious for good reasons. It&#8217;s cheap, it scales, one expert can brief a whole leadership team in an afternoon, and it leaves you with an attendance record to show an auditor. If the goal were to inform the board that NIS2 exists and that cyber risk is real, the seminar would be exactly the right tool. That&#8217;s just not the goal.</p>
<h2>Information is not instinct</h2>
<p>A board that has sat through a good NIS2 briefing can tell you what the directive says. That&#8217;s not the same as being able to run the meeting where the CISO asks for budget they don&#8217;t want to give. Or the meeting thirty minutes after a breach, where someone has to decide what to tell the regulator inside the seventy-two hour window. Those are decisions made under pressure, with half the information you&#8217;d like and real consequences either way. You don&#8217;t get better at them by being told about them. You get better at them by making them, getting them wrong somewhere it&#8217;s safe to get them wrong, and making them again. That&#8217;s the training the law has in mind, whether it puts it in those words or not.</p>
<h2>What board training looks like when it works</h2>
<p>It looks like the board actually making the calls. You put a real governance decision in front of them, with a clock and a trade-off, and let the consequences play out on the table instead of in production. That&#8217;s what <a href="https://relationsec.net/exposure/">EXPOSURE</a> does. It&#8217;s a <a href="https://relationsec.net/serious-games/">board-governance game</a> built around the decisions NIS2 Article 20 puts on management, run as a facilitated half-day. The board doesn&#8217;t learn about oversight. They practice it.</p>
<p>NIS2 won&#8217;t accept &#8220;we ran a seminar&#8221; as evidence forever. And even if it did, a seminar was never going to change how your board behaves in the room that actually matters. Train them the way you&#8217;d train anyone for a decision that counts. Let them make it.</p>
<p>NIS2 is not the only EU regime raising this bar. <a href="https://relationsec.net/dora-operational-resilience-testing-tabletop/">DORA does the same for operational resilience</a> in financial services, and the wider case for training over slideware runs through <a href="https://relationsec.net/eu-cyber-regulation-training/">game-based training for EU cyber regulation</a>.</p>
<h2>Frequently asked questions</h2>
<h3>Does NIS2 legally require board-level cybersecurity training?</h3>
<p>Yes. NIS2 Article 20(2) requires members of management bodies to undergo training to identify risks and assess cyber risk-management practices, and Article 20(1) makes them accountable for the measures themselves.</p>
<h3>Is a seminar or e-learning enough for NIS2 management training?</h3>
<p>It satisfies the paper obligation but not the intent. NIS2 holds management accountable for decisions, and a seminar transfers information without ever rehearsing the decisions. It is the minimum, not the goal.</p>
<h3>What is the alternative to a NIS2 board seminar?</h3>
<p>A facilitated exercise where the board actually makes the governance decisions under pressure, such as a board-governance game like <a href="https://relationsec.net/exposure/">EXPOSURE</a>, so they practice the accountability the law assigns them.</p>
<h3>Who is legally accountable under NIS2?</h3>
<p>The management body. Article 20 makes them approve and oversee the risk-management measures and allows them to be held liable, which is why their training has to go beyond awareness.</p></div>
			</div><div class="et_pb_module et_pb_text et_pb_text_7  et_pb_text_align_left et_pb_bg_layout_light">
				
				
				
				
				<div class="et_pb_text_inner"><h2>Want to put this in front of your team?</h2>
<p>I run these as games your board and your responders actually take part in, not another slideshow. Tell me where your team is and what they need to practice, and we will set it up.</p></div>
			</div><div class="et_pb_button_module_wrapper et_pb_button_3_wrapper et_pb_button_alignment_left et_pb_module ">
				<a class="et_pb_button et_pb_button_3 et_pb_bg_layout_light" href="/contact/">Book a session</a>
			</div><div class="et_pb_module et_pb_code et_pb_code_3">
				
				
				
				
				<div class="et_pb_code_inner"><script type="application/ld+json">{  "@context": "https://schema.org",  "@type": "FAQPage",  "mainEntity": [    {      "@type": "Question",      "name": "Does NIS2 legally require board-level cybersecurity training?",      "acceptedAnswer": {        "@type": "Answer",        "text": "Yes. NIS2 Article 20(2) requires members of management bodies to undergo training to identify risks and assess cyber risk-management practices, and Article 20(1) makes them accountable for the measures themselves."      }    },    {      "@type": "Question",      "name": "Is a seminar or e-learning enough for NIS2 management training?",      "acceptedAnswer": {        "@type": "Answer",        "text": "It satisfies the paper obligation but not the intent. NIS2 holds management accountable for decisions, and a seminar transfers information without ever rehearsing the decisions. It is the minimum, not the goal."      }    },    {      "@type": "Question",      "name": "What is the alternative to a NIS2 board seminar?",      "acceptedAnswer": {        "@type": "Answer",        "text": "A facilitated exercise where the board actually makes the governance decisions under pressure, such as a board-governance game like EXPOSURE, so they practice the accountability the law assigns them."      }    },    {      "@type": "Question",      "name": "Who is legally accountable under NIS2?",      "acceptedAnswer": {        "@type": "Answer",        "text": "The management body. Article 20 makes them approve and oversee the risk-management measures and allows them to be held liable, which is why their training has to go beyond awareness."      }    }  ]}</script></div>
			</div>
			</div>
				
				
				
				
			</div>
				
				
			</div>





<p>The post <a href="https://relationsec.net/nis2-board-training-game-vs-seminar/">NIS2 says train your board. A slide deck will not do it.</a> appeared first on <a href="https://relationsec.net">Relations Security</a>.</p>
]]></content:encoded>
					
					<wfw:commentRss>https://relationsec.net/nis2-board-training-game-vs-seminar/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
			</item>
	</channel>
</rss>

<!--
Object Caching 13/204 objects using Disk
Page Caching using Disk: Enhanced 

Served from: relationsec.net @ 2026-10-06 22:52:23 by W3 Total Cache
-->