Skip to content

Live in Brussels, 13 to 14 October 2026

Walk out
with the NIS2 evidence trail your auditor will ask for

1.5 days

The Resilience Cycle is the mechanism: identify the weak points, engineer the controls, produce the evidence, in that order, so the audit reads what you built. A day and a half live, two instructors, one on the technical build and one on the regulatory translation, so the two halves of NIS2 agree.

  • Why a CVSS-ranked patch list fails a NIS2 audit, and the ranking that passes (module 1)
  • The one indicator that turns a SOC dashboard into something a board can sign (module 3)
  • What starts the 24-hour reporting clock when the breach is your supplier's, not yours (module 3)

Reserve your seat

Tell us where to send seat availability. The Apis team replies to you, not to a queue.

Which course?

No payment on this page. Seats are confirmed by the Apis team by email.

Apis Training AB uses your name and email to contact you about this course and nothing else. How we handle your data.

1994

Training operators since

300,000+

Professionals trained

80+

Countries

4.8/5

Average course score, year on year

The audit does not read your intentions

NIS2 is in force. Essential entities face fines of up to EUR 10 million or 2% of worldwide turnover, and management bodies carry personal accountability for approving the measures.

The clock is shorter than most incident plans: early warning within 24 hours, notification within 72, final report within a month. When the breach is at a supplier, the obligation is still yours.

Most teams have the controls. What they do not have is the evidence trail that proves them, in the order an auditor reads it. That is what this masterclass builds, and you leave with the first pass done.

Directive (EU) 2022/2555, Articles 20, 23 and 34.

Reserve my seat

No payment on this page. The Apis team confirms your seat by email.

The Resilience Cycle for NIS2 Readiness

A masterclass taking you through the full journey to operational NIS2 readiness, from identifying weaknesses to producing audit-ready evidence.

Dates13 to 14 October 202613 Oct 09:00 to 17:00, 14 Oct 09:00 to 13:00
FormatClassroom, BrusselsVenue confirmed to booked seats
Duration1.5 daysOne full day plus a morning
Delivered byTwo instructorsHoucem Kolsi and Nadia Mejri, together in the room

Four things you can do on the Monday after

Prioritise vulnerabilities using risk and business impact

Rank what to fix first by what it would cost the business, and the patch queue arrives at your CFO with a price on it.

Build secure-by-design environments aligned with NIS2

Engineer the controls into the build. By the time the audit is scheduled, compliance is already a property of the environment.

Translate technical controls into board-ready indicators

Turn what the SOC measures into what the board can read and sign, so accountability sits where the directive puts it and the CISO stops translating at 11pm.

Manage NIS2-compliant incident response, including third-party breaches

Run the reporting clock and the supplier chain when the incident is not yours but the obligation is, so the 24-hour warning goes out on time and with your name on it.

Reserve my seat

No payment on this page. The Apis team confirms your seat by email.

Course outline

Resilience Foundations

How modern threats and NIS2 converge into a resilience mandate, and how to prioritise vulnerabilities by risk and business impact.

Building the Resilient Engine

Secure-by-design technical environments aligned with NIS2: technical design, automation and evidence generation.

Governance and NIS2 Assurance

Translating operations into frameworks, metrics and audit-ready documentation, including NIS2-compliant incident response for third-party breaches.

Two instructors. The build and the translation.

Houcem Kolsi

Houcem Kolsi

Senior Cybersecurity Instructor and Practitioner. Cloud-native, 5G, risk and compliance

CISSP-certified since 2016, with 18 years hands-on as cloud security architect at Airbus and BNP Paribas, 5G security consultant at Ericsson, and SaaS founder. Over 250 training days delivered to security teams at Airbus, Ericsson, Telia, Telenor, ING Bank, the United Nations and the Central Bank of Kenya. Teaches DORA and NIS2 compliance, SOC 2 evaluation and incident response from real architecture decisions and actual incidents in banking, telecom, aerospace and defence.

  • CISSP
  • DORA Risk Manager
  • AWS Solutions Architect
  • Certified Kubernetes Administrator
Nadia Mejri

Nadia Mejri

Director, Growth and AI Security Deployment. SOC, telecom and AI governance specialist

15 years driving business expansion and technical deployment, including AI security for SOCs. Founder of Cyberpath. Tracks the EU AI Act, 5G, NIS2, NIST AI RMF and ISO 27001, 27005 and 42001, and turns them into training for decision-makers and technical leads.

  • PECB ISO 27001 / 27005
  • NIS2 implementation
  • Cyber risk analysis

Built for the people who have to make NIS2 real

Cybersecurity engineers, SOC analysts, cloud architects

And the DevSecOps professionals who build and run the environment NIS2 has to be evidenced from.

CISOs, risk and compliance managers, internal auditors

The people who have to sign the evidence and defend it to a regulator.

IT leaders and project owners

Anyone contributing to NIS2 implementation who needs the technical and regulatory sides to agree.

Two engineers on a rooftop transmission site at duskAlso in Brussels

Travelling in? Cybersecurity for 5G runs 14 to 15 October.

NIS2 Readiness gives you the governance and resilience frame. Cybersecurity for 5G gives you the technical depth to apply it to RAN, Core, MEC, slicing and cloud-native. One trip covers both. Two trips cover both and cost you a second flight, a second hotel and the weeks in between.

Reserve both seats

Same form. Choose "Both Brussels courses" and the team reserves both.

Your seat in three steps

1

Leave your name and work email

Thirty seconds. No payment, no account.

2

Apis Training contacts you

Seat availability, invoicing and any group booking, handled by a person.

3

Walk into the Brussels room on 13 October

Leave on the 14th with a resilience cycle you can run and evidence an auditor can follow.

What people ask first

Is this held in person?

Yes. Live classroom in Brussels: 13 October from 09:00 to 17:00 and 14 October from 09:00 to 13:00. The class is limited to 15 people, and the venue is confirmed to every booked seat before the date.

What does it cost?

Apis Training confirms pricing and invoicing before any seat is committed. Submitting your details costs nothing.

Do I need a technical background?

No. Every session is built for governance and engineering people in the same room. You come with one discipline and leave able to work with the other.

Can I send a team?

Yes, and it works better when governance and engineering come together, because they leave with the same evidence trail. Reserve your own seat now and say how many more you need when Apis Training gets in touch.

Is this a legal certification or audit?

No. It is training that produces audit-ready evidence, not a certificate that stands in for it. The evidence is what the auditor asks for, and you leave with the first pass of yours.

Only fifteen seats available

A day and a half, two instructors, one evidence trail. Leave your name and work email below.

  • Prioritise vulnerabilities by risk and business impact
  • Turn technical controls into board-ready indicators
  • Run NIS2-compliant incident response

Reserve your seat

Which course?

No payment on this page. Seats are confirmed by the Apis team by email.

Apis Training AB uses your name and email to contact you about this course and nothing else. How we handle your data.