Two days · In-person or online · Building on the kick-off

From an assessment of the current situation to an actionable roadmap.

The implementation workshop transforms your current assessment into a concrete, risk-based roadmap. The goal is not more measures, but effective measures. Compliance is the minimum standard; resilience is the goal.

What to Bring

Six results after two days

Each participant leaves the workshop with a well-defined, personalized roadmap.

01

Prioritize Core Areas

Identify the seven core areas and rank them by risk.

02

Draw up a schedule

90-Day Plan and Comparison with the 6- to 12-Month Checklist.

03

Decide on the implementation approach

Justify whether each measure will be handled in-house, with support, or outsourced.

04

Designing an Incident Response Plan

A functional process consisting of six phases and clearly defined roles.

05

Planning Communication

Building blocks for customers, employees, suppliers, and in the event of a crisis.

06

Ensuring Continuity

The PDCA cycle [Plan, Do, Check, and Act] and quarterly management reviews.

Day 1

Understanding and Prioritizing

From the seven core areas to contract clauses, risk-based prioritization, and critical decisions.

9:00 a.m. to 9:20 a.m.

Review and Evaluation of Homework Assignments

A common starting point based on the preparation.

9:30 a.m. to 11:00 a.m.

The Seven Core Areas of Cybersecurity

Minimum standard for each area.

9:00 a.m. to 9:30 a.m.

Contract Clauses and Real-World Requirements

Seven Common Clauses and Their Definitions.

9:00 a.m. to 9:30 a.m.

Risk-Based Prioritization and Roadmap

Risk vs. Effort: Four Scenarios.

9:00 a.m. to 9:30 a.m.

Critical Decisions and Investments

Do it yourself, get help, or outsource it.

9:00 a.m. to 9:30 a.m.

End-of-Day Closing and Misjudgments

Recognizing Common Fallacies.

Day 2

Act and Embed

From incident response to the 90-day plan and communication, all the way to a customized roadmap.

9:00 a.m. to 9:20 a.m.

Arrival and a Look Back at Day 1

Establish a connection; target image for Day 2.

9:20 a.m. to 10:45 a.m.

Incident Response in an Emergency

Responsiveness Over Perfectionism: Six Phases.

11:00 a.m. to 12:30 p.m.

The 90-Day Plan in Detail

From Goal to Weekly Routine.

1:30 p.m. to 2:45 p.m.

Internal and External Communication

Customers, Employees, Suppliers, and Crisis Situations.

3:00 p.m. to 4:00 p.m.

Continuity and European Sovereignty

The PDCA Cycle and Its Strategic Context.

4:00 p.m. to 5:00 p.m.

Personalized Schedule and Completion

Bring it all together.

From Workshop to Implementation

Your Guide to Your Schedule

The two-day implementation workshop turns your current assessment into a concrete plan. The practical guide will then remain at your disposal as a reference for implementation in your day-to-day operations.

Nonfiction · 1st Edition · On Implementation

Successfully Implement NIS2 in Small and Medium-Sized Businesses!

A practical guide for board members, CEOs, advisory board members, supervisory board members, and interested decision-makers. From legal obligations to ensuring compliance with your major client’s requirements!

Over the course of two days, we’ll develop your personalized roadmap. The book provides the framework that supports this plan: a structured 90-day plan designed to help you gain clarity on the current situation during the first three months and lay the necessary groundwork.

You’ll learn which quick wins can immediately raise your security level and how to remain capable of taking action in an emergency. Responsiveness is more important than perfection. Five detailed real-world examples show how other medium-sized companies have taken this approach.

  • Your 90-Day Plan: Get Off to a Structured Start
  • Quick Wins: What You Can and Should Do Right Away
  • Incident Response: Staying Capable of Taking Action in an Emergency
  • Real-world examples from mechanical engineering, IT, logistics, and the pharmaceutical industry

Dr. Claus Michael Sattler · ISBN 978-3-69250-027-0 · April 2026

„NIS2 erfolgreich im Mittelstand umsetzen!“ mit dem Untertitel „Praxisleitfaden für Vorstände, Geschäftsführer, Beiräte, Aufsichtsräte und interessierte Entscheider – Von der gesetzlichen Pflicht, den Vorgaben Ihres Großkunden zur sicheren Umsetzung!“ von Dr. Claus Michael Sattler, siehe https://www.fzco.eu/978-3-69250-027-0

Seven Core Areas

The Substantive Basis

For each area, you will determine the minimum standard and priority for your company.

Section 1

Access Control

Strong passwords, MFA for external access, rights based on need.

Section 2

Data Backup

The 3-2-1 Rule, an offline copy, and a tested recovery.

Section 3

Vulnerability Management

Software inventory and a standardized patching process.

Section 4

Network Security

Firewall, segmentation, secure remote access.

Section 5

Supplier Management

Security requirements for our own suppliers and proof of compliance.

Section 6

Incident Response

Clear roles, defined reporting channels, and escalation levels.

Area 7 covers employee awareness and training, including regular awareness-raising activities and hands-on training (Sattler 2026, Chapters 3.3.1 through 3.3.7).

What Matters in the End

Effective measures instead of merely going through the motions

A company may be formally compliant but still be unable to operate for days in the event of an attack if it lacks robust contingency plans and tested backups.

6 Phases

Incident Response

Detection, Assessment, Containment, Communication, Remediation, and Lessons Learned.

90 days

Implementation Plan

Three months with a clear focus, broken down into a weekly schedule with designated people in charge.

30,000 to 60,000 T€

Investment over two years

For a typical SME, including consulting, technology, training, and certification. Often results in a positive ROI due to avoided loss of business.