Mandatory NIS2 Training for All Staff
The course, which is part of the training program defined under the Cybersecurity Training Plan required by EU Directive 2022/2555 (NIS2), is mandatory for all staff, regardless of employment type or contract duration (including temporary workers, PhD students, collaborators, students/interns, affiliates, etc.) and covers the following basic and cross-cutting topics:
Cybersecurity Principles: basic principles, continuous updates, who to contact
Threats: what they are and how to defend against them
Regulations: ISO27001, NIS2, GDPR
Password Management: attacks, defenses, password managers
MFA and SSO: why and how they work; SPID, CIE, PEC: what they are and how to use them
Endpoint Security: basic hygiene, remote working
Social Engineering (SE) and Phishing: basic techniques, how to defend yourself, phishing examples
AI: current status, security issues
The course is delivered in 8 short video modules (few minutes each, in Italian with English subtitles) for a total duration of approximately one hour. Once you have watched all the videos, you will need to complete an assessment test consisting of 17 multiple-choice questions. Passing the test will generate a personalized certificate confirming the completion of the course and your basic knowledge of the subject.
Deadline: September 30th, 2026 - For employees hired on or after October 1, 2026, training must be completed within 2 months of their start date