EXPOSURE: Empowering Management to Meet NIS2 Requirements

Læs på dansk

Management’s Role Under NIS2

NIS2 puts the responsibility on management, in plain words:

“The management body of essential and important entities shall approve the cybersecurity risk-management measures taken by entities… and oversee its implementation.”

(NIS2, Article 20(1))

And it goes further:

“Members of the management body shall follow training on a regular basis to gain sufficient knowledge and skills to identify risks and assess cybersecurity risk-management practices and their impact on the operations of the entity.”

(NIS2, Article 20(2))

EXPOSURE is how I get a management team to meet that obligation. Not a briefing. A game where they make the decisions themselves.

Klaus Agnoletti leading a management security workshop beside a slide listing a company security stack

What management actually practices in a session

Risk Identification and Assessment

NIS2 expects management to identify and assess security risk. In an EXPOSURE session they:

  • Weigh realistic threats against a realistic business
  • Sort what matters from what does not
  • Live with the consequences of their own prioritization
  • Build a feel for which assets are critical and where they are weak

Resource Allocation Decision-Making

Management approves the security budget. EXPOSURE gives them:

  • Hands-on practice allocating a limited security budget
  • A feel for what controls cost and what they buy
  • The trade-offs behind a security investment, and what they do to the business
  • A way to make security investment decisions they can defend

Oversight of Implementation

NIS2 makes management oversee how security gets implemented. The session helps by:

  • Showing how technical controls connect to business goals
  • Making the link between a policy and what actually happens visible
  • Showing why security is something you keep adjusting, not something you sign off once
  • Giving management and the technical team a shared language

Cross-Functional Collaboration

Security governance does not work inside one department. EXPOSURE gets people to:

  • Have real conversations between management and the technical specializts
  • Agree on who owns what
  • See the business view and the IT view of the same problem
  • Treat security as everybody’s job, not IT’s

Workshop Format

A session runs like this:

  • Framing
    Why this matters for your organization, and what to notice during play
  • The game
    Three rounds of governance decisions, made by your team
  • Debrief
    What the disagreements revealed, mapped to your organization
  • What to take back
    Concrete next steps for the board table

Built around your organization

Before the session I talk to whoever is organizing it about your governance setup, your NIS2 readiness and the decisions your board has been sitting on. That shapes how I frame the game and how I run the debrief, so what comes out is about your organization, not a generic one.

More than a compliance tick

Meeting NIS2 is why most teams book it. What they leave with is broader. The team can: • Talk about security risk in business terms • Bring security into strategy instead of bolting it on afterwards • Say which risks the business can live with and which it cannot • Show the rest of the organization that security starts at the top

Want your management team to actually make the calls?

Get in touch and tell me about your management team. We will work out what a session should look like for them.

See all hands-on cybersecurity workshops.

No cookies here

Notice there’s no cookie banner here.
That’s intentional and the site is still GDPR-compliant. I chose to avoid cookies and stick to basic, privacy-friendly stats.
My analytics are cookieless: self-hosted Plausible (EU) and PostHog in cookieless mode, with your IP anonymized. No cross-site tracking, nothing that identifies you.
The one cookie I can set does the opposite of every other cookie: it tells my stats to ignore you completely, and you only get it if you ask.

Everybody wins.