EXPOSURE: Empowering Management to Meet NIS2 Requirements
Management’s Role Under NIS2
NIS2 puts the responsibility on management, in plain words:
“The management body of essential and important entities shall approve the cybersecurity risk-management measures taken by entities… and oversee its implementation.”
(NIS2, Article 20(1))
And it goes further:
“Members of the management body shall follow training on a regular basis to gain sufficient knowledge and skills to identify risks and assess cybersecurity risk-management practices and their impact on the operations of the entity.”
(NIS2, Article 20(2))
EXPOSURE is how I get a management team to meet that obligation. Not a briefing. A game where they make the decisions themselves.
What management actually practices in a session
Risk Identification and Assessment
NIS2 expects management to identify and assess security risk. In an EXPOSURE session they:
- Weigh realistic threats against a realistic business
- Sort what matters from what does not
- Live with the consequences of their own prioritization
- Build a feel for which assets are critical and where they are weak
Resource Allocation Decision-Making
Management approves the security budget. EXPOSURE gives them:
- Hands-on practice allocating a limited security budget
- A feel for what controls cost and what they buy
- The trade-offs behind a security investment, and what they do to the business
- A way to make security investment decisions they can defend
Oversight of Implementation
NIS2 makes management oversee how security gets implemented. The session helps by:
- Showing how technical controls connect to business goals
- Making the link between a policy and what actually happens visible
- Showing why security is something you keep adjusting, not something you sign off once
- Giving management and the technical team a shared language
Cross-Functional Collaboration
Security governance does not work inside one department. EXPOSURE gets people to:
- Have real conversations between management and the technical specializts
- Agree on who owns what
- See the business view and the IT view of the same problem
- Treat security as everybody’s job, not IT’s
Workshop Format
A session runs like this:
- FramingWhy this matters for your organization, and what to notice during play
- The gameThree rounds of governance decisions, made by your team
- DebriefWhat the disagreements revealed, mapped to your organization
- What to take backConcrete next steps for the board table
Built around your organization
More than a compliance tick
Want your management team to actually make the calls?
Get in touch and tell me about your management team. We will work out what a session should look like for them.