Cybersecurity training is one of the areas where companies most frequently fall short. Either training does not take place at all, or it happens as a one-off event without documentation and without follow-up. Decree No. 409/2025 Coll. (implementing regulation for NIS2) sets out clear requirements. Although NÚKIB offers its own educational resources, these are insufficient to fully meet the obligations.
What courses does NÚKIB offer?
NÚKIB operates an educational section on its website (nukib.gov.cz) featuring several types of materials:
- E-learning courses - free online courses on the fundamentals of cybersecurity, primarily targeted at public administration and staff in security roles
- Methodological guides - guidelines for implementing security measures, risk analysis, developing a security policy and incident management
- Minimum safety requirements - a set of basic recommendations and educational materials for small businesses and individuals
- Conferences and workshops - NÚKIB regularly organises professional events, some of which are free or available for a nominal fee.
- Cybersecurity test - online self-assessment of organisational readiness, available on the NÚKIB website
These sources are valuable and we recommend using them. The problem is that for fulfilment of the legal obligation to train employees Under Decree 409/2025 Coll., this is insufficient. You require a training programme tailored to your organisation, with verifiable attendance and regular renewal.
What does Decree 409/2025 Coll. Require?
The Decree to Act No. 264/2025 Coll. Stipulates that regulated entities must ensure:
- Regular training for all employees - at least once a year, for new employees within 3 months of starting work
- Increased demands on security personnel - The Cyber Security Manager (CSM) must meet qualification requirements and undergo continuous training.
- Management training - statutory bodies must be trained in legal obligations and their personal liability
- Training documentation - attendance records, certificates or other verifiable proof of completion
- Adapting content to roles - IT staff require different training than administrative employees
What must the training cover?
The content of cybersecurity training for employees should cover at least these areas:
Training for all employees
- Recognising phishing emails and SMS messages
- Secure password and password manager
- Multi-factor authentication (MFA)
- Safe remote work and working from home
- Procedure for reporting suspicious behaviour
- Rules for handling sensitive data
- Physical security (clean desk policy, tailgating)
Training for IT and security staff
- Privileged account management
- The basics of vulnerability management
- Response to security incidents
- Deposit policy and renewal
- Network segmentation and monitoring
- NIS2 legal obligations in detail
Forms of cyber security training
Cybersecurity training can be delivered in various forms. Each has its own advantages and suitable applications:
- In-person training - highest efficiency for complex topics, straightforward documentation, but costly and logistically demanding. Suitable for management and IT teams.
- Online e-learning - scalable, cost-effective; employees can complete it at any time. Suitable for company-wide basic training. Good platforms automatically generate certificates.
- Phishing simulation - a practical test showing who would fall for an attacker's trick. Most effective when combined with follow-up training. Excellent for measuring progress over time.
- Micro-learning modules - short videos or quizzes spread throughout the year. They maintain awareness without placing a significant time burden on employees.
Cybersecurity test by NÚKIB
NÚKIB operates an online self-assessment referred to as cybersecurity test. It enables organisations to quickly identify gaps in security preparedness. The test is not a certified audit. It does not issue any certificate for NÚKIB. However, it serves as an excellent initial tool for identifying priorities.
The test results serve well as a basis for planning training: they show in which areas the gaps are greatest and where training should begin.
When do you need commercial training instead of NÚKIB courses?
We recommend NÚKIB courses as a supplement, not as the foundation of your training programme. Commercial training from certified providers is always required when:
- Are you a regulated entity under NIS2 and require verifiable employee training?
- You need to adapt the content to your company's specific processes and tools.
- Would you like to combine e-learning, phishing simulations and live workshops?
- Do you need certificates as proof for a potential inspection by NÚKIB?
SecureOn offers customised cybersecurity training: from basic awareness programmes for all employees to specialised courses for the IT team and management. Read more about why one-off training is not enough in the article. Safety training for employees: Why once a year is not enough.
If you are just starting with NIS2 and need to understand the entire framework, we recommend first finding out what NÚKIB requires from companies, read our overview article. What is NÚKIB and what does it do.
Customised cybersecurity training
SecureOn will prepare a training programme meeting the requirements of Decree 409/2025 Coll., including e-learning, phishing simulations and in-person workshops with certificates.
Contact SecureOn →