ExperTeach Networking Logo

IT Governance

Integrating Security into the Business Model

ExperTeach Networking Logo

IT governance is essential today in order to make digital infrastructures resilient and compliant. This IT governance course provides a holistic understanding of strategic, organizational and technical aspects of modern information security in times of NIS2, DORA and the AI Act.

The focus is on the analysis of current threats, the development of effective security measures and the establishment of structured security management. Human factors, security awareness and the targeted handling of vulnerabilities are also covered. The course provides clarity in a complex environment and helps to establish security as a continuous process.

Course Contents

  • Regulatory Requirements (NIS2, DORA, AI Act, CRA)
  • Management Systems (ISO 27001, IT-Grundschutz, ISMS, BCM)
  • Risk Management
  • Security Architectures and Solutions
  • SIEM, IDS/IPS, Firewall
  • Security Operations Center (SOC)
  • Authentication and Access Controls (MFA, RBAC, PAM)
  • Business Continuity Management
  • Supply Chain Security
  • Security Awareness
  • Social Engineering
  • Cryptography, Protocol Security
  • AI in Security
  • Cyber Resilience
  • Asset Management and Vulnerability Analysis
  • European Cooperation
  • Authorities and Supervision (BSI, CERT.at)

The detailed digital documentation package, consisting of an e-book and PDF, is included in the price of the course.

Premium Course Documents

In addition to the digital documentation package, the exclusive Premium Print Package is also available to you.

  • High-quality color prints of the ExperTeach documentation
  • Exclusive folder in an elegant design
  • Document pouch in backpack shape
  • Elegant LAMY ballpoint pen
  • Practical notepad
Premium Print
The Premium Print Package can be added during the ordering process for € 150,- plus VAT (only for classroom participation).
Request in-house training now

Target Group

This course is aimed at IT security managers, decision makers and technical professionals who want to develop an in-depth understanding of IT governance and current regulatory requirements. You will be able to effectively implement security strategies and compliance measures and understand the relevant regulations and standards.

Knowledge Prerequisites

You should have a basic understanding of networks and how different technologies and protocols work.

1 Main Objectives of IT Security
1.1 Threat Situation and Challenges
1.1.1 Attackers and their Motives
1.1.2 Attack Variants in an Overview
1.2 Economic Importance of Cybersecurity
1.2.1 Economic Damage
1.2.2 Loss of Reputation
1.2.3 Cybersecurity as an Economic Success Factor
1.2.4 Minimizing Damage through Preventive Measures
1.3 Resilience and Protection of the Domestic Market
1.3.1 Cybersecurity as Part of the EU Strategy
1.3.2 Interdependencies within the EU
1.3.3 International Challenges
1.3.4 IT Security—Role of Companies and States
2 Regulatory Basics—NIS2, DORA, etc.
2.1 Definition and Significance of IT Governance
2.1.1 Correlation between IT Governance and Network Security
2.1.2 Roles and Responsibilities in IT Governance
2.1.3 Organizational Processes
2.2 NIS2 Directive
2.2.1 KRITIS—A Brief Review
2.2.2 Objectives and Background of the NIS2 Directive
2.2.3 Obligations for Companies and Authorities
2.2.4 Instructions for Affected Sectors
2.2.5 Checklist for the NIS2 Directive
2.3 DORA—Digital Operational Resilience Act
2.3.1 Focus on Critical Financial Infrastructures
2.3.2 Comparison with Previous Security Standards
2.3.3 Recommendations for Action
2.4 Cyber Resilience Act (CRA)
2.4.1 Background and Objectives
2.4.2 Security Requirements for Networked Products
2.5 European AI Act
2.5.1 The Regulation of AI
2.5.2 Classification of AI Systems According to Risk Levels
2.5.3 Sectors and their Obligations
2.5.4 Chronological Classification
2.6 Practical Implications of the Regulations
2.6.1 Security Measures in the Company
2.6.2 Documentation and Verification for Audits
2.7 Comparison and Interaction of the EU Directives
2.7.1 Synergies for Comprehensive IT Security
3 The Role of State Authorities
3.1 German Federal Office for Information Security (BSI)
3.1.1 Tasks, Functions, and Significance for Companies
3.1.2 The IT Security Act
3.2 IT Baseline Protection Compendium
3.2.1 Introduction to the IT Baseline Protection Compendium
3.2.2 Risk Analysis According to BSI Specifications
3.3 BSI Security Standards and Recommendations
3.3.1 BSI Recommendations for Network Security Measures
3.3.2 Practical Application—Checklists and Tools
3.4 Austrian Authorities
3.4.1 BMI, MILCERT, and CERT.at—Operational Security
3.4.2 Austrian Information Security Manual
3.4.3 NIS2 and DORA Austria—NISG and FMA
3.5 European Union Agency for Cybersecurity (ENISA)
3.5.1 Directives on Cybersecurity
3.5.2 NIS2 Implementation Directive
3.5.3 Methodological Orientation
4 Organizational Security Measures
4.1 Security Requirements from a Governance Perspective
4.1.1 IT Directives and Certifications (ISO /IEC 27001)
4.1.2 OT Security (ISA/IEC 62443)
4.1.3 Planning Security Guidelines
4.1.4 Implementation of Security Guidelines
4.2 Asset Management
4.2.1 Inventory—Record Assets
4.2.2 Vulnerabilities and Dependencies
4.2.3 Supply Chain Risks
4.3 Risk Management
4.3.1 Recognizing the Threat Situation—Threat Modeling
4.3.2 Identification and Assessment of Risks
4.3.3 Development of Risk Treatment Measures
4.3.4 Performance of IT Security Audits
4.4 Emergency Case Management
4.5 Security Architectures
4.5.1 Perimeter Security—The Historical Approach
4.5.2 Defense in Depth—Extended Security
4.5.3 Zero Trust—Mistrust as a Principle
4.6 Cloud Governance and Network Security
4.6.1 Data Protection in the Cloud
4.6.2 C5 Certificate—Audits for the Cloud
4.6.3 Edge Computing—Next Generation Cloud
5 Technical Aspects of Network Security
5.1 Vulnerabilities in Network Architectures
5.1.1 Exploitation
5.1.2 Social Engineering
5.1.3 Lateral Movement
5.1.4 DoS and DDoS
5.2 Preventive Protective Measures
5.2.1 Physical Protection
5.2.2 Protocol Security
5.2.3 Cryptography and Encryption
5.2.4 Disaster Recovery
5.3 Network Protection
5.3.1 Firewalls
5.3.2 IDS/IPS
5.3.3 Security Service Edge (SSE)
5.4 Access Management and Identity Control
5.4.1 Multi-Factor Authentication (MFA)
5.4.2 Role-Based Access Control (RBAC)
5.4.3 Security Management of Privileged Accounts (PAM)
5.5 Monitoring and Logging
5.5.1 Logging Strategies for Networks
5.5.2 Real-time Monitoring with Dashboards
5.5.3 SIEM Systems
5.5.4 Anomaly Detection via AI-supported Tools
5.6 OT Security—Zone and Conduit Model
6 Security Awareness—The Human Factor
6.1 Involving Employees
6.1.1 Cyberhygiene
6.1.2 NIS2 Demands Training
6.2 Awareness Programs
6.2.1 Transparency and Behavior
6.2.2 Questioning Effectiveness
6.2.3 Confidentiality
6.3 Methods of Security Awareness Training
6.3.1 Pivotal Role
6.3.2 In-depth Measures
6.3.3 AI & ML—Dynamic Training
6.4 Challenge—AI-based Social Engineering
6.4.1 Mining with LLMs
6.4.2 AI Phishing
6.4.3 Detect AI Attacks
7 Crisis Management and Incident Response
7.1 Emergency Case Management
7.1.1 Incident Support—With CERT-Bund and MIRT
7.1.2 Creation of an Emergency Manual
7.1.3 Testing and Refining Restart Processes
7.2 Development of an Incident Response Plan
7.2.1 Monitoring and Automated Alarms in the Event of System Failures
7.2.2 Definition of Escalation Levels
7.2.3 Deployment of an Incident Response Team
7.3 Conducting Emergency Drills and Simulations
7.3.1 Map Exercises for Security Incidents—Blue Teaming
7.3.2 Test Run for Business Continuity Management
7.4 Setup and Operation of a Security Operation Center (SOC)
7.4.1 Technical Requirements Made on an SOC
7.4.2 Tasks and Daily Operation of an SOC
7.4.3 SOC—Models and Types
7.5 SOC as a Managed Service—MSSP
7.5.1 Service-Level Agreements (SLAs) and Response Times
7.5.2 Data Sovereignty and Compliance
7.5.3 Transparency and Reporting
7.5.4 Integration into the Existing IT Security Infrastructure
7.6 Continuous Improvement and Feedback Loops
7.6.1 Forensic Analysis of Security Incidents
7.6.2 Lessons Learned from Security Incidents
7.6.3 Adaptation of Guidelines and Processes
A List of Abbreviations

Classroom training

Do you prefer the classic training method? A course in one of our Training Centers, with a competent trainer and the direct exchange between all course participants? Then you should book one of our classroom training dates!

Online training

You wish to attend a course in online mode? We offer you online course dates for this course topic. To attend these seminars, you need to have a PC with Internet access (minimum data rate 1Mbps), a headset when working via VoIP and optionally a camera. For further information and technical recommendations, please refer to.

Tailor-made courses

You need a special course for your team? In addition to our standard offer, we will also support you in creating your customized courses, which precisely meet your individual demands. We will be glad to consult you and create an individual offer for you.
Request in-house training now
PDF SymbolYou can find the complete description of this course with dates and prices ready for download at as PDF.

IT governance is essential today in order to make digital infrastructures resilient and compliant. This IT governance course provides a holistic understanding of strategic, organizational and technical aspects of modern information security in times of NIS2, DORA and the AI Act.

The focus is on the analysis of current threats, the development of effective security measures and the establishment of structured security management. Human factors, security awareness and the targeted handling of vulnerabilities are also covered. The course provides clarity in a complex environment and helps to establish security as a continuous process.

Course Contents

  • Regulatory Requirements (NIS2, DORA, AI Act, CRA)
  • Management Systems (ISO 27001, IT-Grundschutz, ISMS, BCM)
  • Risk Management
  • Security Architectures and Solutions
  • SIEM, IDS/IPS, Firewall
  • Security Operations Center (SOC)
  • Authentication and Access Controls (MFA, RBAC, PAM)
  • Business Continuity Management
  • Supply Chain Security
  • Security Awareness
  • Social Engineering
  • Cryptography, Protocol Security
  • AI in Security
  • Cyber Resilience
  • Asset Management and Vulnerability Analysis
  • European Cooperation
  • Authorities and Supervision (BSI, CERT.at)

The detailed digital documentation package, consisting of an e-book and PDF, is included in the price of the course.

Premium Course Documents

In addition to the digital documentation package, the exclusive Premium Print Package is also available to you.

  • High-quality color prints of the ExperTeach documentation
  • Exclusive folder in an elegant design
  • Document pouch in backpack shape
  • Elegant LAMY ballpoint pen
  • Practical notepad
Premium Print
The Premium Print Package can be added during the ordering process for € 150,- plus VAT (only for classroom participation).
Request in-house training now

Target Group

This course is aimed at IT security managers, decision makers and technical professionals who want to develop an in-depth understanding of IT governance and current regulatory requirements. You will be able to effectively implement security strategies and compliance measures and understand the relevant regulations and standards.

Knowledge Prerequisites

You should have a basic understanding of networks and how different technologies and protocols work.

1 Main Objectives of IT Security
1.1 Threat Situation and Challenges
1.1.1 Attackers and their Motives
1.1.2 Attack Variants in an Overview
1.2 Economic Importance of Cybersecurity
1.2.1 Economic Damage
1.2.2 Loss of Reputation
1.2.3 Cybersecurity as an Economic Success Factor
1.2.4 Minimizing Damage through Preventive Measures
1.3 Resilience and Protection of the Domestic Market
1.3.1 Cybersecurity as Part of the EU Strategy
1.3.2 Interdependencies within the EU
1.3.3 International Challenges
1.3.4 IT Security—Role of Companies and States
2 Regulatory Basics—NIS2, DORA, etc.
2.1 Definition and Significance of IT Governance
2.1.1 Correlation between IT Governance and Network Security
2.1.2 Roles and Responsibilities in IT Governance
2.1.3 Organizational Processes
2.2 NIS2 Directive
2.2.1 KRITIS—A Brief Review
2.2.2 Objectives and Background of the NIS2 Directive
2.2.3 Obligations for Companies and Authorities
2.2.4 Instructions for Affected Sectors
2.2.5 Checklist for the NIS2 Directive
2.3 DORA—Digital Operational Resilience Act
2.3.1 Focus on Critical Financial Infrastructures
2.3.2 Comparison with Previous Security Standards
2.3.3 Recommendations for Action
2.4 Cyber Resilience Act (CRA)
2.4.1 Background and Objectives
2.4.2 Security Requirements for Networked Products
2.5 European AI Act
2.5.1 The Regulation of AI
2.5.2 Classification of AI Systems According to Risk Levels
2.5.3 Sectors and their Obligations
2.5.4 Chronological Classification
2.6 Practical Implications of the Regulations
2.6.1 Security Measures in the Company
2.6.2 Documentation and Verification for Audits
2.7 Comparison and Interaction of the EU Directives
2.7.1 Synergies for Comprehensive IT Security
3 The Role of State Authorities
3.1 German Federal Office for Information Security (BSI)
3.1.1 Tasks, Functions, and Significance for Companies
3.1.2 The IT Security Act
3.2 IT Baseline Protection Compendium
3.2.1 Introduction to the IT Baseline Protection Compendium
3.2.2 Risk Analysis According to BSI Specifications
3.3 BSI Security Standards and Recommendations
3.3.1 BSI Recommendations for Network Security Measures
3.3.2 Practical Application—Checklists and Tools
3.4 Austrian Authorities
3.4.1 BMI, MILCERT, and CERT.at—Operational Security
3.4.2 Austrian Information Security Manual
3.4.3 NIS2 and DORA Austria—NISG and FMA
3.5 European Union Agency for Cybersecurity (ENISA)
3.5.1 Directives on Cybersecurity
3.5.2 NIS2 Implementation Directive
3.5.3 Methodological Orientation
4 Organizational Security Measures
4.1 Security Requirements from a Governance Perspective
4.1.1 IT Directives and Certifications (ISO /IEC 27001)
4.1.2 OT Security (ISA/IEC 62443)
4.1.3 Planning Security Guidelines
4.1.4 Implementation of Security Guidelines
4.2 Asset Management
4.2.1 Inventory—Record Assets
4.2.2 Vulnerabilities and Dependencies
4.2.3 Supply Chain Risks
4.3 Risk Management
4.3.1 Recognizing the Threat Situation—Threat Modeling
4.3.2 Identification and Assessment of Risks
4.3.3 Development of Risk Treatment Measures
4.3.4 Performance of IT Security Audits
4.4 Emergency Case Management
4.5 Security Architectures
4.5.1 Perimeter Security—The Historical Approach
4.5.2 Defense in Depth—Extended Security
4.5.3 Zero Trust—Mistrust as a Principle
4.6 Cloud Governance and Network Security
4.6.1 Data Protection in the Cloud
4.6.2 C5 Certificate—Audits for the Cloud
4.6.3 Edge Computing—Next Generation Cloud
5 Technical Aspects of Network Security
5.1 Vulnerabilities in Network Architectures
5.1.1 Exploitation
5.1.2 Social Engineering
5.1.3 Lateral Movement
5.1.4 DoS and DDoS
5.2 Preventive Protective Measures
5.2.1 Physical Protection
5.2.2 Protocol Security
5.2.3 Cryptography and Encryption
5.2.4 Disaster Recovery
5.3 Network Protection
5.3.1 Firewalls
5.3.2 IDS/IPS
5.3.3 Security Service Edge (SSE)
5.4 Access Management and Identity Control
5.4.1 Multi-Factor Authentication (MFA)
5.4.2 Role-Based Access Control (RBAC)
5.4.3 Security Management of Privileged Accounts (PAM)
5.5 Monitoring and Logging
5.5.1 Logging Strategies for Networks
5.5.2 Real-time Monitoring with Dashboards
5.5.3 SIEM Systems
5.5.4 Anomaly Detection via AI-supported Tools
5.6 OT Security—Zone and Conduit Model
6 Security Awareness—The Human Factor
6.1 Involving Employees
6.1.1 Cyberhygiene
6.1.2 NIS2 Demands Training
6.2 Awareness Programs
6.2.1 Transparency and Behavior
6.2.2 Questioning Effectiveness
6.2.3 Confidentiality
6.3 Methods of Security Awareness Training
6.3.1 Pivotal Role
6.3.2 In-depth Measures
6.3.3 AI & ML—Dynamic Training
6.4 Challenge—AI-based Social Engineering
6.4.1 Mining with LLMs
6.4.2 AI Phishing
6.4.3 Detect AI Attacks
7 Crisis Management and Incident Response
7.1 Emergency Case Management
7.1.1 Incident Support—With CERT-Bund and MIRT
7.1.2 Creation of an Emergency Manual
7.1.3 Testing and Refining Restart Processes
7.2 Development of an Incident Response Plan
7.2.1 Monitoring and Automated Alarms in the Event of System Failures
7.2.2 Definition of Escalation Levels
7.2.3 Deployment of an Incident Response Team
7.3 Conducting Emergency Drills and Simulations
7.3.1 Map Exercises for Security Incidents—Blue Teaming
7.3.2 Test Run for Business Continuity Management
7.4 Setup and Operation of a Security Operation Center (SOC)
7.4.1 Technical Requirements Made on an SOC
7.4.2 Tasks and Daily Operation of an SOC
7.4.3 SOC—Models and Types
7.5 SOC as a Managed Service—MSSP
7.5.1 Service-Level Agreements (SLAs) and Response Times
7.5.2 Data Sovereignty and Compliance
7.5.3 Transparency and Reporting
7.5.4 Integration into the Existing IT Security Infrastructure
7.6 Continuous Improvement and Feedback Loops
7.6.1 Forensic Analysis of Security Incidents
7.6.2 Lessons Learned from Security Incidents
7.6.3 Adaptation of Guidelines and Processes
A List of Abbreviations

Classroom training

Do you prefer the classic training method? A course in one of our Training Centers, with a competent trainer and the direct exchange between all course participants? Then you should book one of our classroom training dates!

Online training

You wish to attend a course in online mode? We offer you online course dates for this course topic. To attend these seminars, you need to have a PC with Internet access (minimum data rate 1Mbps), a headset when working via VoIP and optionally a camera. For further information and technical recommendations, please refer to.

Tailor-made courses

You need a special course for your team? In addition to our standard offer, we will also support you in creating your customized courses, which precisely meet your individual demands. We will be glad to consult you and create an individual offer for you.
Request in-house training now

PDF SymbolYou can find the complete description of this course with dates and prices ready for download at as PDF.