← Back to knowledge base

Which security topics matter most for executives and boards?

Practical guidance on security topics for executives and boards for organizations that want to improve secure behavior structurally.

Recently updated

From insight to action

See how to turn this topic into a practical awareness program with training, phishing simulations and clear management reporting.

Founder & Security Awareness Specialist · 2LRN4

Since NIS2 entered into force in 2024-2025, the question of which security topics executives should know is no longer an academic one. Board members must approve the cybersecurity measures and oversee their implementation, and can be held personally liable for failing to do so. The training they take should therefore focus not on operational detail but on strategic steering, risk trade-offs and conduct during a crisis. What belongs in 2026?

Why board training differs from employee training

An employee learns how to spot phishing and what to do with a stolen password. A board member learns something else: how to steer on cyber risk, which questions to ask the CISO, how to co-decide during an incident, and what liability they carry when things go wrong. The themes overlap, but the level is fundamentally different.

Under Cbw article 24, board training is legally mandatory for essential and important entities. That responsibility is personal: for a breach demonstrably caused by insufficient cyber governance, the individual board member can be held accountable alongside the organisation. That changes what a board member must be able to do: ask questions, decide under uncertainty, and escalate when needed.

Good board training is therefore not a shortened employee course. It is a separate learning path covering strategic topics, focused on decision-making and oversight rather than recognising a suspicious email.

The seven topics that belong in 2026

Together, these seven topics form a workable curriculum for board training under Cbw article 24:

  • Cyber governance and liability. What is the legal role of a board member under the Cbw, DORA and the GDPR, what decisions are expected from the board, and what documentation do you need to show you fulfilled your duty?
  • Risk analysis and acceptance. What type of cyber risk does the organisation run, which measures are in place, and what residual risk is consciously accepted? The board does not make technical decisions but signs off on the risk framework.
  • The threat landscape at a high level. What are ransomware, BEC, AI-generated phishing and supply-chain attacks, and what damage have they typically caused at comparable organisations?
  • Incident response at board level. What happens in the first 24 hours after a major incident, which decisions sit with the board (whether to pay, customer communication, supervisor notification), and how do you rehearse that in advance?
  • Compliance landscape. Think of the Cbw, DORA, the GDPR, the AI Act and, in healthcare, NEN 7510. Which of these apply, what reporting duties exist, and how does the board report on compliance?
  • AI governance. The EU AI Act has been in force since February 2025: which AI systems run in the organisation, what risk classification do they have, and how do you ensure AI literacy among staff?
  • Board reporting. Which cyber indicators recur every quarter, how do you interpret a phishing report rate or a vulnerability scan, and which trends call for steering?

What does not belong in board training

A few topics regularly show up in board training even though they demonstrably should not.

Technical detail on attack chains, for one. A board member does not need to know how a buffer overflow works or what an SQL injection does, but does need to know that the CISO has measures against that category of attack and how often they are tested.

The same goes for operational incident procedures. The playbook for who does what hour by hour after ransomware sits with IT and the CSIRT; the board needs to know the headline and its own role, not the full runbook.

Phishing simulations at board level without context also add little. Board members tested with a phishing email learn little from it: their agendas are too dense and they delegate triage. A tabletop exercise on a ransomware scenario at the board table teaches far more.

Tabletop exercises: the most powerful component

The most effective component of board training is not e-learning but a tabletop exercise. A specialist facilitator lays out a scenario ("on a Friday evening you receive notification that customer data has been leaked on a known leak platform") and the board walks through the decisions that follow in real time: whom to inform, whether to pay, who speaks, and how to communicate with the supervisor.

Tabletops deliver three things other training forms do not. First, you discover where the decision process stalls: who has mandate, who is missing, and what information is lacking. Second, you practise collaborating under pressure, which differs fundamentally from collaborating in routine. Third, you build a shared language: after a tabletop, everyone knows what a "P1 incident" or the "containment phase" means.

A reasonable cadence is two tabletops per year for the board, with varying scenarios (ransomware, a data breach, AI misuse or a compromised supplier), combined with annual e-learning for the strategic foundations.

Communication and spokesmanship in a crisis

An often undervalued part of board training is external communication during and after an incident. This is unfamiliar ground for many board members: they are used to steering on certainty, and in a cyber incident that certainty is gone.

Three principles work in practice: keep it short, be honest, and speak with one voice. That means one spokesperson and no conflicting messages from departments. Be open about what you know (the date, the attack type and the affected group) and clear about what you do not yet know ("we are still investigating"). Avoid technical jargon towards the public; towards supervisors, more detail is wise.

Under the Cbw, an early warning is mandatory within 24 hours, followed by a fuller notification within 72 hours. Do not wait for all the facts; report what you know now and supplement it as more becomes known. Preparation helps here too: a pre-agreed communication framework, covering which topics to mention and which not, greatly accelerates the first 24 hours.

How to anchor this in an awareness programme

Board training only works when it is structural rather than one-off. A practical setup looks like this.

Start with an annual base module of 45 to 60 minutes on governance, the threat landscape, compliance and board reporting. For the Dutch context, add the components of Cbw article 24, the GDPR notification duty and, for financial institutions, DORA.

Add two tabletop exercises per year with varying scenarios, facilitated by an external party for objectivity, and document the outcomes for audit.

Have the CISO send the board a short quarterly letter with the state of cyber risk, an incident overview and ongoing changes: not a thick report, but half an A4 page. It builds familiarity with the subject between formal training moments.

Finally, keep a demonstrable record: who completed which training and when, in which version, and who attended the tabletop exercises. Under Cbw article 24, this is your evidence that you met your duty of care, both organisationally and personally.

From explanation to action

See how 2LRN4 turns this topic into a workable security awareness programme with measurable results.

View the NIS2 page

Related articles

Sources

FAQ

What topics belong in board training under Cbw article 24?

Cyber governance and liability, risk analysis and acceptance, the high-level threat landscape, board-level incident response, the compliance landscape (Cbw, DORA, GDPR, AI Act), AI governance, and board reporting. Operational detail does not belong on that list.

How does board training differ from employee training?

An employee learns recognition and action; a board member learns steering, deciding and oversight. It covers the same themes at a different level: not "how do I spot phishing" but "how do I know our phishing measures work".

What is a tabletop exercise?

A structured simulation in which the board walks through a crisis scenario at the board table, with a facilitator who builds up the scenario step by step and has the board make decisions on the spot. It is the most effective element of board training; most organisations run two per year.

Should board members know how ransomware works?

At a high level, yes: what the effect is, what damage it causes and which decisions follow. Technical detail is not needed; the board steers on categories of risk rather than individual attack methods.

What is the difference between Cbw article 24 and the general Cbw training duty?

Article 24 targets board members specifically: they must be personally trained on cyber risk and governance. The general duty (article 21) covers all staff. Both apply at the same time in essential and important entities.

How often should a board be trained?

At least one formal base training per year, supplemented with two tabletop exercises and a short quarterly CISO update. That comfortably meets the Cbw duty-of-care standard and keeps the board sharp between formal moments.

What is the personal liability under Cbw article 24?

Board members can be held personally liable for relevant harm caused by failure to meet the board training duty and the broader cyber governance obligations. Documentation of completed training is then the main evidence in your defence.

Next step

Use this article as the foundation and then see how 2LRN4 turns this topic into audience segmentation, training and reporting.