The Mining Chamber of Industry and Commerce invites representatives of industrial companies to a training session on the new cybersecurity requirements arising from the National Cybersecurity System (KSC), the NIS2 Directive, and the Cyber Resilience Act.
The new regulations significantly expand the scope of responsibility for companies, their management, as well as manufacturers, importers, and distributors of equipment and software. These obligations now extend beyond securing IT infrastructure to include industrial systems, production continuity, supply chain security, incident response, and vulnerability management for products containing digital components.
During the training, participants will learn whether and to what extent their company may be subject to the new regulations, as well as what steps need to be taken to properly prepare the organization for the new requirements.
Scope of the Training
The program includes, among other things:
- the interrelationships between the KSC, NIS2, and the Cyber Resilience Act;
- criteria for determining whether a company is a critical or important entity;
- management’s responsibility for the organization’s cybersecurity;
- risk management and the implementation of an information security management system;
- supply chain security and cooperation with third parties;
- policies for handling and reporting incidents;
- business continuity, backups, and system recovery;
- identification of critical industrial systems and assets;
- IT and OT network segmentation and secure remote access;
- monitoring, updates, and vulnerability management;
- obligations of manufacturers, importers, and distributors under the CRA;
- technical documentation, conformity assessment, and CE marking;
- preparation of a gap analysis and a practical implementation plan for the new requirements.
What will the participants gain?
During the training, participants will learn how to:
- assess whether the organization is subject to KSC and NIS2;
- define the scope of responsibilities for the company and its management;
- identify the most significant organizational and technical risks;
- identify systems and processes critical to production continuity;
- prepare the organization to respond to cyber incidents;
- streamline cooperation with suppliers, subcontractors, and service providers;
- verify requirements for machinery, equipment, and software;
- conduct a preliminary vulnerability assessment;
- set priorities and prepare a plan to bring the company into compliance with the new requirements.
Who is it for?
This training is specifically designed for:
- members of management boards and senior management;
- individuals responsible for cybersecurity, IT, and OT;
- authorized representatives and management system specialists;
- employees of legal, compliance, and audit departments;
- individuals responsible for business continuity and risk management;
- production, maintenance, and automation managers;
- manufacturers and suppliers of industrial machinery, equipment, and systems;
- individuals responsible for technology procurement and supplier relations.
Consultations Regarding Specific Companies
The training will conclude with a discussion and Q&A session, during which participants will have the opportunity to present their own case studies and get answers to questions related to the specific nature of their organizations and industries.
This is an opportunity not only to learn about the new requirements, but also to determine which obligations may apply to a specific company, identify the most significant gaps, and figure out where to begin the compliance process.
We invite you to participate in this training and help your company prepare for the new cybersecurity requirements.
Date and Location of the Training
17 września br. w godz. 10:00 – 15:00
Katowice
Price:
GIPH members: 450 PLN net + VAT
Other companies: 550 PLN net + VAT
Submissions
We ask anyone interested in participating in the workshops to fill out the registration form and send it to biuro@giph.com.pl by September 4 of this year.