How does the German NIS2 law change security training?
The transposition of the EU NIS2 Directive into German law through the amended Federal Office for Information Security Act (BSIG) turns what was once an optional best practice into a binding statutory duty. Under Section 30 (2) no. 7 BSIG, both "important" and "particularly important entities" must implement, document, and monitor continuous security awareness and training measures for their entire workforce. This regulatory shift represents a fundamental transformation in how organizations must approach human-centric risk. Compliance is no longer about hosting an annual, passive video-based session to check a box. It requires a dynamic, operationalized approach that builds genuine, measurable defense capabilities across all communication channels.
- From static annual lessons to continuous, adaptive threat simulations across all organizational layers.
- From generic email-only phishing tests to multi-channel defenses covering SMS, voice, and deepfake video.
- From unmonitored participation to audit-ready logging of every simulation, lesson, and response to prove compliance.
To navigate these strict requirements, DACH Mittelstand Enterprises need a localized framework that satisfies German regulators and the works council (Betriebsrat) alike. For instance, companies like Alexander Bürkle have modernized their defense by moving away from outdated compliance models. By deploying automated simulations tailored to individual threat profiles via the revel8 Platform, security teams can satisfy Section 30 BSIG obligations while building durable operational resilience.
What are the mandatory training requirements for German executives?
Under Section 38 Paragraph 3 of the German BSI Act (BSIG), which transposes Article 20 of the NIS2 Directive into national law, members of the management body of essential and important entities are personally obligated to undergo regular cybersecurity training. This duty applies to managing directors of a GmbH and executive board members of an AG. Crucially, the responsibility is non-delegable: leadership cannot offload these obligations to the internal IT department or external security service providers.
The mandatory training content must empower leaders to independently identify, assess, and manage security risks. It must cover strategic risk identification, technical security measures, and business impact assessments, providing directors with the foundation needed to approve the proactive risk management measures under Section 30 BSIG and actively monitor their execution.
- Strategic Risk Identification: Developing the capability to evaluate organizational risk profiles and evolving AI-driven threat landscapes independently.
- Technical Security Measures: Understanding and approving the specific technical and organizational protocols implemented under Section 30 BSIG.
- Business Impact Assessment: Analyzing the potential operational, financial, and legal consequences of system downtime and data breaches.
- Documented Proof of Attendance: Maintaining verifiable, continuous records of regular training to satisfy regulatory audits and protect against personal liability.
Personal liability serves as the central forcing function. Under Section 38 Paragraph 2 BSIG, executives face direct internal liability to their own organization for financial damages resulting from a culpable breach of their oversight and implementation duties. To mitigate this risk and evidence compliance, companies use the Academy within the revel8 Platform to deliver structured, role-specific paths while generating audit-ready logs of every simulation and completed lesson. This automated approach enables organizations like Alexander Bürkle to maintain continuous, documented security training without disrupting operational focus.
Who must be trained and what topics are legally required?
Deepfake voice-cloning attacks are surging, proving that traditional defense mechanisms are failing to keep up with generative AI. To combat this, Germany's NIS2 implementation law, codified in the BSI Act (BSIG), imposes strict training requirements. Specifically, Section 30 Paragraph 2 No 7 BSIG mandates that all employees who have access to corporate IT systems must receive regular, basic training and security awareness-raising measures. This is no longer an optional task for HR, but a legal necessity for companies across Germany.
To satisfy the legal standard of 'state of the art' defense, generic compliance videos are insufficient. Training must actively reflect the actual threat landscape that employees encounter daily. This includes exposing teams to multi-channel social engineering across email, SMS, and messaging apps, as well as highly realistic voice cloning (vishing) and deepfakes. For instance, many modern security incidents originate on non-traditional communication platforms, as explored in the research on messaging app vulnerability. When German organizations such as Alexander Bürkle roll out compliant programs, they build continuous habits rather than relying on a once-a-year compliance checkbox.
- All IT-Enabled Personnel: Every employee with access to corporate IT systems must participate, shifting the focus from isolated departments to the entire organization.
- Management Participation: Under § 38 BSIG, managing directors and board members must also undergo regular training to properly assess cyber risk.
- State-of-the-Art Topics: Training must cover advanced attack vectors including multi-channel social engineering, credential theft, and deepfake vishing.
- Verification and Audit Logs: Organizations must maintain verifiable logs of participation and completed modules to demonstrate compliance during BSI audits.
How can companies run simulations without violating works council rules?
In Germany, running security awareness simulations is not just a technical deployment; it is a co-determination matter. Under Section 87 Paragraph 1 No. 6 of the German Works Constitution Act (BetrVG), any technical system capable of monitoring employee behavior or performance requires the prior approval of the works council. Attempting to roll out simulations without a formalized works agreement (Betriebsvereinbarung) is unlawful and risks stalling the entire compliance initiative.
Addressing works council requirements early during the onboarding process is crucial to prevent negotiations from delaying deployment by weeks. To secure alignment, the simulation platform must protect employee privacy by default rather than as an afterthought. The revel8 Platform solves this through default group-level reporting anonymization, meaning performance data is aggregated and requires a minimum group size of five before any metrics are displayed. This privacy-first approach is exactly how DACH Mittelstand leaders like Alexander Bürkle deploy continuous simulations while maintaining trust with employee representatives.
- Purpose limitation: Ensure simulations are used solely for educational purposes and NIS2 compliance, never for individual performance tracking.
- Exclusion of disciplinary actions: Explicitly ban using simulation results for employment-law consequences or employee warnings.
- Ethical simulation triggers: Avoid deceptive employee-sensitive triggers such as fake bonuses or fake terminations to maintain organizational trust.
- Sovereign DACH data residency: Keep data secure on localized infrastructure like STACKIT in Germany to comply with both GDPR and works council privacy expectations.
By structuring campaigns around collective resilience rather than individual policing, companies can successfully bypass traditional compliance hurdles. The works council transitions from a potential barrier into a key partner for active security training, paving the way for a smooth, legally compliant rollout.
Where must training data be stored to ensure European compliance?
Under the NIS2 Directive and GDPR, digital sovereignty is no longer a theoretical preference but an operational necessity. For European enterprises, storing and processing employee training data within the European Union is critical to eliminate compliance vulnerabilities. Traditional compliance software hosted on overseas cloud platforms exposes organizations to jurisdictional conflicts, such as foreign data access requests under the US CLOUD Act. To maintain true data control, security teams must ensure that their security simulations and employee engagement data remain entirely within a sovereign European infrastructure.
The revel8 Platform addresses this risk directly by hosting its infrastructure on STACKIT, a highly secure, sovereign German cloud. This guarantees that all data processing occurs within a fully GDPR-compliant, European-hosted environment that aligns with the rigorous requirements of NIS2, DORA, and ISO 27001. Additionally, a sovereign setup ensures a strict boundary for artificial intelligence: customer-specific data is processed exclusively within the customer's tenant and is never used to train underlying AI models. This keeps proprietary organizational data completely private while powering adaptive, role-specific simulations.
Selecting a sovereign training infrastructure requires verifying three key operational pillars:
- Complete regional isolation: All data processing, hosting, and backup systems must remain strictly within European data centers, eliminating exposure to extraterrestrial disclosure laws.
- Zero external AI training: Employee performance metrics, simulation results, and custom organizational data must never be exported to train public LLMs or external models.
- Agnostic compliance alignment: Hosting environments must carry certifications that directly support organizational compliance with NIS2, DORA, and ISO 27001 standards.
For instance, organizations like Alexander Bürkle prioritize local compliance to maintain a secure human defense without introducing regulatory friction. By anchoring security awareness programs in a sovereign, German-hosted cloud, organizations protect their employee data while building lasting resilience against sophisticated, AI-driven social engineering.
How do German organizations build an audit-ready implementation plan?
The Bundesamt für Sicherheit in der Informationstechnik (BSI) enforces strict compliance under the amended BSI Act (BSIG), meaning organizations can no longer rely on sporadic training sessions. To satisfy regulatory audits, German companies must maintain detailed, audit-ready logs of every single training simulation, micro-lesson, and employee action. Relying on manual record-keeping or static PDF certificates creates massive administrative overhead and fails to prove active risk mitigation during an audit.
Transitioning to continuous, role-specific playlists, such as the automated Awareness Playlist on the revel8 Platform, offers a reliable, low-overhead path to maintaining compliance. By delivering bite-sized, automated micro-learning in the flow of work, this approach builds lasting security habits without causing employee fatigue. This automated framework allows lean security teams to generate real-time compliance documentation automatically, enabling companies like Alexander Bürkle to keep their defensive posture high every day while ensuring audit preparedness.
Implementing a successful NIS2 alignment relies on a structured approach, outlined in this practical checklist:
- Identify your entity status under the BSIG and register with the BSI to establish regulatory parameters.
- Review works council requirements early to implement group-level reporting with a minimum group size of five for privacy.
- Deploy multi-channel simulations across email, SMS, and voice to match the modern threat landscape.
- Transition from annual training blocks to continuous, automated playlists that adapt to individual risk profiles.
- Centralize your reporting to maintain live, audit-ready logs of all simulation results and training modules.


.avif)


