An Edge Built on Knowledge and Experience
§ 38 BSIG — Training Obligation

NIS2 Training for Executive Management

§ 38 BSIG personally obligates managing directors and board members to complete regular cybersecurity training — with a duty to provide evidence to the BSI.

Technical & Legal Expertise Experience From Numerous NIS2 Projects Based in Sindelfingen
§ 38 BSIG

Executive Training Obligation — What the Law Requires

The training obligation under § 38 BSIG is not a bureaucratic add-on. It reflects the recognition that cybersecurity is shaped top-down: without competence at the top, responsible governance of cyber risk cannot be ensured.

BSI Guidance, April 2026

What Executives Need to Know

In its guidance of April 2026, the BSI specified which content an NIS2-compliant executive training must cover. Four topic areas are central.

Cyber Threat Landscape

Current attack scenarios, typical attack vectors against companies of your size and industry, ransomware risks.

Risk Assessment & Decision-Making

How cyber risks are assessed and factored into business decisions — budget responsibility and prioritisation.

Legal Obligations & Liability

Personal liability under § 38 BSIG, the fine framework, reporting obligations, and consequences of non-compliance.

Crisis Response & Communication

The role of executive management in an actual incident: decision-making paths, external communication, contact with authorities.

Related Topics

Further NIS2 Topics

NIS2 Training for Your Executive Management

We offer tailored executive training that fulfils § 38 BSIG and is practically aligned with your industry and company situation.

Request Training
Tilsiter Str. 6 · D-71065 Sindelfingen, Germany · +49 (0) 7031.4181-860 · contact@consuvation.com