Training programme

Training built around the decisions each role actually makes.

We establish who needs what (from senior management to office staff and field teams) and match the scope to the decisions each of these roles makes.

01 Fit

When this service fits

When different roles need different training rather than one universal course: senior management, office staff and field teams. The KSC act requires the head of a key or important entity to undergo training once per calendar year (art. 8e). On the transitional path it is worth running the first training ahead of time, so that you stay within the deadline for implementing the obligations, that is by 3 April 2027.

02 Scope

What we review

  • Management training: management duties, incident reporting and personal liability. Format is live online classroom or on site at your premises, in variants ranging from a short lecture session to a longer one with a tabletop exercise and a follow-up review call after a few months.
  • E-learning for office staff: cyber awareness modules in Polish, and in the extended variant phishing simulations and a management report with metrics. Educating staff on cybersecurity is one of the measures required by art. 8 of the KSC act.
  • Training for field teams: a toolbox talks package (short shift meetings led by supervisors), posters for technology sites, and optionally mobile microlearning for employees without computer access.

03 Result

What decision the result supports

What remains is a clear scope of audiences, topics and the next step, without an unapproved certificate of attendance.

04 Inputs

What to prepare

  • The roles and audience groups: senior management, office staff, field teams.
  • The context of the obligations, such as your KSC status and the decisions each role makes.
  • Organisational conditions: group sizes, locations and the specifics of the sites, if we are training field teams.

05 Terms

How scope and quotation are set

Scope and quotation depend on the number of audiences and role groups, the formats chosen and the number of locations and conversations required. We establish both after a short scoping call.

06 Limits

What this service does not replace

Training supports meeting the obligations, but it does not replace implementing risk management measures or management decisions. The entity is responsible for meeting the training obligation and for the security of the organisation. We do not issue an unapproved certificate of attendance as proof of compliance.

07 Process

Signal → review → evidence → decision

Signal

Which role needs training and why?

Review

What decisions does that role actually make?

Evidence

What scope and format fit that?

Decision

Where to begin and what to defer?

08 Questions

Questions before starting

  • Is management training an obligation? Yes. The KSC act requires the head of a key or important entity to undergo training once per calendar year (art. 8e).
  • Is e-learning enough for everyone? No. Employees without computer access, such as operators, need a different format, so for field teams we use toolbox talks and materials for the sites.
  • Do you issue a certificate of attendance? We do not promise an unapproved certificate of attendance. We establish a clear scope of audiences, topics and the next step.

09 Contact

Discuss the audience and training scope

To plan the training we need the list of roles and a short description of the situation; we will settle the scope of audiences, topics and the next step together.

Discuss the audience and training scope

Editorial review: CZ Cybersecurity sp. z o.o. Content reviewed: 21 July 2026.