Training programme
Training built around the decisions each role actually makes.
We establish who needs what (from senior management to office staff and field teams) and match the scope to the decisions each of these roles makes.
01 Fit
When this service fits
When different roles need different training rather than one universal course: senior management, office staff and field teams. The KSC act requires the head of a key or important entity to undergo training once per calendar year (art. 8e). On the transitional path it is worth running the first training ahead of time, so that you stay within the deadline for implementing the obligations, that is by 3 April 2027.
02 Scope
What we review
- Management training: management duties, incident reporting and personal liability. Format is live online classroom or on site at your premises, in variants ranging from a short lecture session to a longer one with a tabletop exercise and a follow-up review call after a few months.
- E-learning for office staff: cyber awareness modules in Polish, and in the extended variant phishing simulations and a management report with metrics. Educating staff on cybersecurity is one of the measures required by art. 8 of the KSC act.
- Training for field teams: a toolbox talks package (short shift meetings led by supervisors), posters for technology sites, and optionally mobile microlearning for employees without computer access.
03 Result
What decision the result supports
What remains is a clear scope of audiences, topics and the next step, without an unapproved certificate of attendance.
04 Inputs
What to prepare
- The roles and audience groups: senior management, office staff, field teams.
- The context of the obligations, such as your KSC status and the decisions each role makes.
- Organisational conditions: group sizes, locations and the specifics of the sites, if we are training field teams.
05 Terms
How scope and quotation are set
Scope and quotation depend on the number of audiences and role groups, the formats chosen and the number of locations and conversations required. We establish both after a short scoping call.
06 Limits
What this service does not replace
Training supports meeting the obligations, but it does not replace implementing risk management measures or management decisions. The entity is responsible for meeting the training obligation and for the security of the organisation. We do not issue an unapproved certificate of attendance as proof of compliance.
07 Process
Signal → review → evidence → decision
Which role needs training and why?
What decisions does that role actually make?
What scope and format fit that?
Where to begin and what to defer?
08 Questions
Questions before starting
- Is management training an obligation? Yes. The KSC act requires the head of a key or important entity to undergo training once per calendar year (art. 8e).
- Is e-learning enough for everyone? No. Employees without computer access, such as operators, need a different format, so for field teams we use toolbox talks and materials for the sites.
- Do you issue a certificate of attendance? We do not promise an unapproved certificate of attendance. We establish a clear scope of audiences, topics and the next step.
09 Contact
Discuss the audience and training scope
To plan the training we need the list of roles and a short description of the situation; we will settle the scope of audiences, topics and the next step together.
Discuss the audience and training scopeEditorial review: CZ Cybersecurity sp. z o.o. Content reviewed: 21 July 2026.