Live in Brussels, 13 to 14 October 2026
Walk out
with the NIS2 evidence trail your auditor will ask for
1.5 daysThe Resilience Cycle is the mechanism: identify the weak points, engineer the controls, produce the evidence, in that order, so the audit reads what you built. A day and a half live, two instructors, one on the technical build and one on the regulatory translation, so the two halves of NIS2 agree.
- Why a CVSS-ranked patch list fails a NIS2 audit, and the ranking that passes (module 1)
- The one indicator that turns a SOC dashboard into something a board can sign (module 3)
- What starts the 24-hour reporting clock when the breach is your supplier's, not yours (module 3)
Training operators since
Professionals trained
Countries
Average course score, year on year
The audit does not read your intentions
NIS2 is in force. Essential entities face fines of up to EUR 10 million or 2% of worldwide turnover, and management bodies carry personal accountability for approving the measures.
The clock is shorter than most incident plans: early warning within 24 hours, notification within 72, final report within a month. When the breach is at a supplier, the obligation is still yours.
Most teams have the controls. What they do not have is the evidence trail that proves them, in the order an auditor reads it. That is what this masterclass builds, and you leave with the first pass done.
Directive (EU) 2022/2555, Articles 20, 23 and 34.
No payment on this page. The Apis team confirms your seat by email.
The Resilience Cycle for NIS2 Readiness
A masterclass taking you through the full journey to operational NIS2 readiness, from identifying weaknesses to producing audit-ready evidence.
Four things you can do on the Monday after
Prioritise vulnerabilities using risk and business impact
Rank what to fix first by what it would cost the business, and the patch queue arrives at your CFO with a price on it.
Build secure-by-design environments aligned with NIS2
Engineer the controls into the build. By the time the audit is scheduled, compliance is already a property of the environment.
Translate technical controls into board-ready indicators
Turn what the SOC measures into what the board can read and sign, so accountability sits where the directive puts it and the CISO stops translating at 11pm.
Manage NIS2-compliant incident response, including third-party breaches
Run the reporting clock and the supplier chain when the incident is not yours but the obligation is, so the 24-hour warning goes out on time and with your name on it.
No payment on this page. The Apis team confirms your seat by email.
Course outline
Resilience Foundations
How modern threats and NIS2 converge into a resilience mandate, and how to prioritise vulnerabilities by risk and business impact.
Building the Resilient Engine
Secure-by-design technical environments aligned with NIS2: technical design, automation and evidence generation.
Governance and NIS2 Assurance
Translating operations into frameworks, metrics and audit-ready documentation, including NIS2-compliant incident response for third-party breaches.
Two instructors. The build and the translation.

Houcem Kolsi
Senior Cybersecurity Instructor and Practitioner. Cloud-native, 5G, risk and compliance
CISSP-certified since 2016, with 18 years hands-on as cloud security architect at Airbus and BNP Paribas, 5G security consultant at Ericsson, and SaaS founder. Over 250 training days delivered to security teams at Airbus, Ericsson, Telia, Telenor, ING Bank, the United Nations and the Central Bank of Kenya. Teaches DORA and NIS2 compliance, SOC 2 evaluation and incident response from real architecture decisions and actual incidents in banking, telecom, aerospace and defence.
- CISSP
- DORA Risk Manager
- AWS Solutions Architect
- Certified Kubernetes Administrator

Nadia Mejri
Director, Growth and AI Security Deployment. SOC, telecom and AI governance specialist
15 years driving business expansion and technical deployment, including AI security for SOCs. Founder of Cyberpath. Tracks the EU AI Act, 5G, NIS2, NIST AI RMF and ISO 27001, 27005 and 42001, and turns them into training for decision-makers and technical leads.
- PECB ISO 27001 / 27005
- NIS2 implementation
- Cyber risk analysis
Built for the people who have to make NIS2 real
Cybersecurity engineers, SOC analysts, cloud architects
And the DevSecOps professionals who build and run the environment NIS2 has to be evidenced from.
CISOs, risk and compliance managers, internal auditors
The people who have to sign the evidence and defend it to a regulator.
IT leaders and project owners
Anyone contributing to NIS2 implementation who needs the technical and regulatory sides to agree.
Also in BrusselsTravelling in? Cybersecurity for 5G runs 14 to 15 October.
NIS2 Readiness gives you the governance and resilience frame. Cybersecurity for 5G gives you the technical depth to apply it to RAN, Core, MEC, slicing and cloud-native. One trip covers both. Two trips cover both and cost you a second flight, a second hotel and the weeks in between.
Same form. Choose "Both Brussels courses" and the team reserves both.
Your seat in three steps
Leave your name and work email
Thirty seconds. No payment, no account.
Apis Training contacts you
Seat availability, invoicing and any group booking, handled by a person.
Walk into the Brussels room on 13 October
Leave on the 14th with a resilience cycle you can run and evidence an auditor can follow.
What people ask first
Is this held in person?
Yes. Live classroom in Brussels: 13 October from 09:00 to 17:00 and 14 October from 09:00 to 13:00. The class is limited to 15 people, and the venue is confirmed to every booked seat before the date.
What does it cost?
Apis Training confirms pricing and invoicing before any seat is committed. Submitting your details costs nothing.
Do I need a technical background?
No. Every session is built for governance and engineering people in the same room. You come with one discipline and leave able to work with the other.
Can I send a team?
Yes, and it works better when governance and engineering come together, because they leave with the same evidence trail. Reserve your own seat now and say how many more you need when Apis Training gets in touch.
Is this a legal certification or audit?
No. It is training that produces audit-ready evidence, not a certificate that stands in for it. The evidence is what the auditor asks for, and you leave with the first pass of yours.
Only fifteen seats available
A day and a half, two instructors, one evidence trail. Leave your name and work email below.
- Prioritise vulnerabilities by risk and business impact
- Turn technical controls into board-ready indicators
- Run NIS2-compliant incident response
