RISKORIA ADVISING & PROFESSIONAL SERVICES D.O.O. · ZAGREB+385 97 737 1345INFO@RISKORIA.EU

Training and workshops

Training is part of the fourth measure, and several other sub-measures require it too. We keep it concrete and tied to your work.

LEGAL FRAMEWORKREGULATION NN 135/2024, ANNEX IIZKS NN 14/2024

Training is a measure, not good practice

Several sub-measures of Annex II require training expressly, and all of them require a record that it happened.

Sub-measure 4.4 requires regular cyber hygiene training and awareness raising for all employees, and sub-measure 4.3 documented training for those with security duties. Both are binding from the basic level. Sub-measure 11.3 requires training in recognising and reporting suspicious events, also from the basic level.

The management body is not exempt. Sub-measure 1.9 requires awareness raising for those responsible for implementing the measures, through workshops, seminars and training, and is binding from the medium level upwards. Sub-measure 1.2 requires all employees and relevant third parties to be made aware of the security policy.

From the medium level onwards come incident response training for key personnel, sub-measure 4.9, and an annual simulated incident exercise, sub-measure 11.5. Social engineering testing, sub-measure 4.11, stays voluntary at every level, but carrying it out is additionally credited.

All of which means one thing: training that leaves no attendance list, no programme and no date does not exist in front of an auditor. Every programme of ours therefore carries those three things, whatever its length.

Programmes and duration by audience

Examples, scenarios and system names come from your own sector.

AUDIENCEDURATIONCONTENTSUB-MEASURE
Management body1 hourResponsibility under Article 29, deadlines, what you sign and what is expected of you at a meeting1.9
IT team2 to 4 hoursThe measures in practice, which record covers which control, and what an auditor interview looks like4.3
All employees1 to 2 hoursRecognising deception and fraud, passwords, multi-factor sign-in and reporting a suspicious message4.4 and 11.3
Measure owners2 hoursHow to keep records, what needs a date, and how to answer the question of where your evidence is4.3
Key incident personnel2 to 3 hoursThe first hour, triage, significance assessment and reporting within the 24 and 72 hour deadlines4.9
Simulation exercise2 to 3 hoursManagement and IT together, a short scenario, minutes and a lessons learned list11.5
Simulated email deceptionBy programmeA campaign, response measurement, a short lesson for those who clicked, and the documentation4.11
Artificial intelligence at work1 to 2 hoursA module for organisations that actually use such systems, alongside the literacy requirement of the AI ActAI Act, Art. 4

Sub-measure 4.11 is voluntary at every level, but carrying it out is additionally credited in self-assessment and audit. Which sub-measure binds you at which level is set out on the thirteen measures page.

How we work

Five steps from tailoring the programme to a record that goes into the evidence set.

01

Tailoring the programme to your sector

Before the workshop we ask which systems you use, what your processes look like and what has already happened. The scenarios and examples come from there, because generic examples do not stick.

PRE-WORKSHOP QUESTIONNAIRETAILORED PROGRAMME
02

Delivery, in person or remote

We do both, but for the management body and for exercises we recommend in person. The discussion that brings the most value rarely happens remotely.

MATERIALSATTENDANCE LISTDATE AND DURATION
03

Knowledge check and measurement

A short check at the end, not for a grade but for a record of effect and to see what did not land. With simulated deception, the response rate is measured before and after.

CHECK RESULTSBEFORE AND AFTER COMPARISON
04

A record that goes into the evidence set

An attendance list with signatures or electronic confirmation, the programme, the date and the duration. Alongside it a short note on which sub-measure it covers, so nobody has to look for it later.

DELIVERY RECORDMAPPING TO SUB-MEASURE
05

A repetition plan

At least once a year for everyone, with a short refresher on joining and on changing role. More often for higher-risk roles such as finance and IT. The plan goes into the obligations calendar so it does not depend on anyone remembering.

ANNUAL PLANREFRESHER ON JOININGOBLIGATIONS CALENDAR

Frequently asked questions

The questions we are asked most often before we start.

Is training mandatory?

It is. Employee training and education are part of the fourth measure, human resources security and digital identities, and are binding from the basic level. Awareness raising for responsible persons is required by the first measure, so the management body is covered too, not just employees.

How do we prove it took place?

With an attendance list, the programme and the date. Without those, the measure does not exist in front of an auditor, however many sessions you held. That is why we attach a note to each record stating which sub-measure it covers.

How often does it need repeating?

At least once a year, with a short refresher on joining and on changing role. More often for higher-risk roles such as finance and IT. The annual simulation exercise is a separate obligation from the medium level upwards.

How long is a workshop?

One hour for the management body, two to four hours for the IT team, one to two hours for employees, and two to three hours for a simulation exercise. Beyond that, more time rarely adds value and attention drops.

Do you deliver remotely?

We do, but for the management body and for exercises we recommend in person. The discussion that brings the most value rarely happens remotely.

Do you tailor the programme to our sector?

That is exactly what we do. The examples, scenarios and system names come from your own field. A short questionnaire therefore always goes out before the workshop.

Do you run simulated email deception?

We do, by agreement with the management body and under a clear rule that the results are not used for disciplinary action. Sub-measure 4.11 is voluntary at every level, but carrying it out is additionally credited.

Is artificial intelligence part of the programme?

It is, as one module, where the organisation actually uses such systems. Since 2 February 2025 the AI Act has required a sufficient level of AI literacy among the staff of providers and of entities deploying such systems. There is no direct fine for it, but it is taken into account in supervision.

Do you issue certificates to participants?

We do, on request. For audit evidence an attendance list with a date is enough, but a certificate helps where a personal training record is also required.

Can we run the training ourselves with your materials?

You can, and for repeat cycles that is often the cheapest option. We then produce the programme, the materials and a record template, and your own person delivers the sessions. As a rule we run the first cycle so you can see how it looks.

Where to go next

The measures training touches most directly.

Let us arrange a workshop for your team.

Half an hour, no obligation. Tell us who the participants are and what lies ahead, and we will propose a programme and a duration.

Book a callINFO@RISKORIA.EU · +385 97 737 1345