Mandatory Security Competence for Boards and Executives
The NIS2 directive mandates that management understands cyber risk. Prevent personal liability with tailored strategic training.
Strategic training modules
The training is composed around your organisation and the needs of your board.
-
Board Liability & NIS2
What the directive actually requires of management: approving the measures, overseeing them and undergoing training. We work through what that responsibility means in practice, and what must be evidenced when the regulator asks.
-
Executive Crisis Management
Decisions under pressure, when the information is incomplete and the clock is running. We rehearse the reporting sequence, with early warning within 24 hours and notification within 72, and who says what to customers, owners and media.
-
Cyber M&A and Security Culture
Cyber risk shapes both pricing and integration in a transaction. We look at what should surface before signing, and at how security culture is built in an organisation that has just become two.
Open courses and certifications
ISO 27001: The Key to Security and Trust in Your Organisation
ISO 27001 certification is about more than a certificate on the wall: it demonstrates systematic information security governance and compliance with requirements such as NIS2. Berigo supports you through every phase, from gap analysis to certification and maintenance.
ClassroomPECB Certified NIS2 Directive Lead Implementer
A five-day course that equips you to plan, implement, operate, monitor and maintain a cybersecurity programme aligned with the NIS 2 Directive. Exam and certification included.
Classroom Next: 19.10.2026 NOK 25 100Get Certified in the NIS 2 Directive: Foundation Course
A two-day foundation course on the NIS 2 Directive that gives you the baseline competence to understand the requirements, identify measures and play an active part in implementation. On completion you are eligible to sit the exam and become a PECB Certificate Holder in NIS 2 Directive Foundation.
Classroom NOK 13 100ISO/IEC 27701 Lead Implementer (PECB)
A five-day PECB course on establishing and running a privacy information management system (PIMS) to ISO/IEC 27701, with the certification exam on the final day.
Classroom NOK 25 100ISO/IEC 42001 Lead Auditor, auditing an AI management system
A five-day PECB course that teaches you to plan, conduct and close audits of AI management systems against ISO/IEC 42001.
Classroom NOK 26 900ISO/IEC 42001 Lead Implementer (PECB)
A five-day PECB course on planning, implementing and running an AI management system to ISO/IEC 42001, with the certification exam on the final day.
Classroom NOK 25 100PECB Certified Lead SOC 2 Analyst
Five-day PECB course on planning, implementing and maintaining SOC 2 compliance, with the certification exam on the final day.
ClassroomPECB Certified Lead Cybersecurity Manager
A five-day PECB course in setting up and running a cybersecurity programme: governance, risk, controls and incident management. The exam is held on the final day.
Classroom NOK 25 100PECB Certified NIST Cybersecurity Professional
A five-day PECB course on using the NIST frameworks to manage risk, select security controls and handle incidents.
Classroom NOK 25 100PECB Certified Data Protection Officer (DPO)
A five-day PECB course that prepares you for the data protection officer role and for monitoring GDPR compliance in your organisation.
Classroom NOK 25 100PECB Certified Digital Transformation Officer
A five-day PECB course on planning, implementing, and monitoring a digital transformation strategy, with the certification exam on the final day.
ClassroomISO/IEC 27001 Lead Implementer
Lead Implementer: establishing and running the management system itself.
Online (self-study) Information security NOK 14 900 + VATISO/IEC 27001 Lead Auditor
Lead Auditor: planning and conducting audits against the standard.
Online (self-study) Information security NOK 14 900 + VATISO/IEC 27001 Foundation
Foundation level: the concepts and the vocabulary, for anyone who needs to take part in the work without leading it.
Online (self-study) Information security NOK 8 900 + VATISO/IEC 27005 Risk Manager
Risk Manager: assessing and treating risk in a structured way.
Online (self-study) Information security NOK 14 900 + VATISO/IEC 27701 Lead Implementer
Lead Implementer: establishing and running the management system itself.
Online (self-study) Privacy NOK 14 900 + VATISO/IEC 27701 Lead Auditor
Lead Auditor: planning and conducting audits against the standard.
Online (self-study) Privacy NOK 14 900 + VATISO/IEC 27701 Foundation
Foundation level: the concepts and the vocabulary, for anyone who needs to take part in the work without leading it.
Online (self-study) Privacy NOK 8 900 + VATGDPR: Certified Data Protection Officer
For the person who is to hold the data protection officer role in practice.
Online (self-study) Privacy NOK 14 900 + VATISO/IEC 42001 Lead Implementer
Lead Implementer: establishing and running the management system itself.
Online (self-study) Artificial intelligence NOK 14 900 + VATISO/IEC 42001 Lead Auditor
Lead Auditor: planning and conducting audits against the standard.
Online (self-study) Artificial intelligence NOK 14 900 + VATISO/IEC 42001 Foundation
Foundation level: the concepts and the vocabulary, for anyone who needs to take part in the work without leading it.
Online (self-study) Artificial intelligence NOK 8 900 + VATISO 22301 Lead Implementer
Lead Implementer: establishing and running the management system itself.
Online (self-study) Continuity and resilience NOK 14 900 + VATISO 22301 Lead Auditor
Lead Auditor: planning and conducting audits against the standard.
Online (self-study) Continuity and resilience NOK 14 900 + VATISO 22301 Foundation
Foundation level: the concepts and the vocabulary, for anyone who needs to take part in the work without leading it.
Online (self-study) Continuity and resilience NOK 8 900 + VATISO 31000 Risk Manager
Risk Manager: assessing and treating risk in a structured way.
Online (self-study) Risk management NOK 14 900 + VATISO 37001 Lead Implementer
Lead Implementer: establishing and running the management system itself.
Online (self-study) Anti-bribery NOK 14 900 + VATISO 37001 Lead Auditor
Lead Auditor: planning and conducting audits against the standard.
Online (self-study) Anti-bribery NOK 14 900 + VATISO 37001 Foundation
Foundation level: the concepts and the vocabulary, for anyone who needs to take part in the work without leading it.
Online (self-study) Anti-bribery NOK 8 900 + VATISO 9001 Lead Implementer
Lead Implementer: establishing and running the management system itself.
Online (self-study) Quality NOK 14 900 + VATISO 9001 Lead Auditor
Lead Auditor: planning and conducting audits against the standard.
Online (self-study) Quality NOK 14 900 + VATISO 9001 Foundation
Foundation level: the concepts and the vocabulary, for anyone who needs to take part in the work without leading it.
Online (self-study) Quality NOK 8 900 + VATISO 45001 Lead Auditor
Lead Auditor: planning and conducting audits against the standard.
Online (self-study) Health, safety and environment NOK 14 900 + VATISO 14001 Lead Auditor
Lead Auditor: planning and conducting audits against the standard.
Online (self-study) Health, safety and environment NOK 14 900 + VATNo courses match these filters. Try removing one of them.
Upcoming sessions
Online courses
Every course below can be taken online, at your own pace, and ends with the certification exam. Berigo delivers all of them.
Information security
- ISO/IEC 27001 Lead Implementer Lead Implementer: establishing and running the management system itself.
- ISO/IEC 27001 Lead Auditor Lead Auditor: planning and conducting audits against the standard.
- ISO/IEC 27001 Foundation Foundation level: the concepts and the vocabulary, for anyone who needs to take part in the work without leading it.
- ISO/IEC 27005 Risk Manager Risk Manager: assessing and treating risk in a structured way.
Privacy
- ISO/IEC 27701 Lead Implementer Lead Implementer: establishing and running the management system itself.
- ISO/IEC 27701 Lead Auditor Lead Auditor: planning and conducting audits against the standard.
- ISO/IEC 27701 Foundation Foundation level: the concepts and the vocabulary, for anyone who needs to take part in the work without leading it.
- GDPR: Certified Data Protection Officer For the person who is to hold the data protection officer role in practice.
Artificial intelligence
- ISO/IEC 42001 Lead Implementer Lead Implementer: establishing and running the management system itself.
- ISO/IEC 42001 Lead Auditor Lead Auditor: planning and conducting audits against the standard.
- ISO/IEC 42001 Foundation Foundation level: the concepts and the vocabulary, for anyone who needs to take part in the work without leading it.
Continuity and resilience
- ISO 22301 Lead Implementer Lead Implementer: establishing and running the management system itself.
- ISO 22301 Lead Auditor Lead Auditor: planning and conducting audits against the standard.
- ISO 22301 Foundation Foundation level: the concepts and the vocabulary, for anyone who needs to take part in the work without leading it.
Risk management
Anti-bribery
- ISO 37001 Lead Implementer Lead Implementer: establishing and running the management system itself.
- ISO 37001 Lead Auditor Lead Auditor: planning and conducting audits against the standard.
- ISO 37001 Foundation Foundation level: the concepts and the vocabulary, for anyone who needs to take part in the work without leading it.
Quality
- ISO 9001 Lead Implementer Lead Implementer: establishing and running the management system itself.
- ISO 9001 Lead Auditor Lead Auditor: planning and conducting audits against the standard.
- ISO 9001 Foundation Foundation level: the concepts and the vocabulary, for anyone who needs to take part in the work without leading it.
Health, safety and environment
We can also put together a programme for a group, or combine online courses with sessions in person. Get in touch.
Why training has become an essential part of corporate governance
Competence requirements have changed
The EU has introduced a more comprehensive framework with greater accountability than before, including NIS2, DORA, the AI Act and the Digital Services Act. At the same time, customers, supervisory authorities and supply chains are placing ever higher demands on documented competence and the ability to manage risk systematically.
Organisations that fail to build competence internally risk falling behind, or taking on risk that could have been avoided with the right knowledge and routines.
Boards and executives need to understand more than before
Digital risk is now a natural part of corporate governance. That does not mean leaders must become technologists, but they need insight that enables them to:
- assess risks and consequences correctly
- prioritise the right measures
- ask the organisation the right questions
- see the connections between strategy, operations and security
- understand what EU requirements actually entail
Sound governance requires confidence in one's own competence.
Artificial intelligence creates both opportunities and responsibilities
AI can improve efficiency, strengthen quality and sharpen decision-making, but only if the organisation understands the frameworks, risks and requirements that come with it.
Competence in AI governance and risk management is now a critical part of business development.
Supplier security has become a governance responsibility
Requirements for contracts, audits, controls, maturity levels and documentation now reach across the entire supply chain. Without the right knowledge, an organisation does not know what to ask its suppliers for, or what it is actually accountable for.
What we offer
Berigo delivers a broad range of courses and training programmes, everything from condensed executive briefings to full certification tracks. Training can take the form of:
- Executive and board workshops
- Tailored in-house courses
- PECB certification courses (1 to 5 days)
- Topic-based professional seminars
- Dedicated training days and internal competence programmes
- Two-hour intensive sessions for rapid upskilling
- Multi-day deep dives for key teams
- Practical scenario exercises in preparedness and incident response
We can also build complete training programmes running over several weeks or months, designed to strengthen the organisation's maturity, governance culture and ability to manage risk.
Topic areas we cover
- ISO/IEC 27001: governance, implementation and auditing
- NIS2 compliance and governance model
- The AI Act and AI governance
- Strategic cybersecurity for executives and boards
- Supplier security and third-party management
- Risk management and internal control
- Privacy and GDPR
- Incident response and preparedness
- Security culture and awareness programmes
- Internal audit and control functions
- Decision support for digital risk
- Operational security for technical teams
- The role of the CISO and executive management in modern security
We adjust scope, level and content to the audience, from new employees to the chair of the board.
Tailored to your organisation's actual needs
No two organisations are alike. That is why we always map:
- maturity level
- industry context
- regulatory framework
- business model
- technology platform
- risk profile
- existing competence
- ongoing initiatives
We use this to design a training programme that delivers real value, not a generic programme that misses your actual challenges.
A teaching style that is calm, confident and professionally solid
The instructor delivering the courses has:
- a PhD in cybersecurity leadership
- more than 20 years of hands-on experience, both technical and strategic
- international instructor certification from PECB
- experience as CISO in a global organisation
- experience in board advisory and risk leadership
- experience with legal and regulatory processes
- experience from incident response and preparedness
The result is training that is professionally grounded, practical and realistic, delivered with a calm, reassuring and explanatory teaching style that makes the material accessible and understandable for everyone.
What you receive after completing a course
- Course materials that can be reused for further internal training
- Certification credentials (for PECB courses)
- Concrete action lists and priorities
- Recommendations for further competence development
- An overview of the regulatory requirements your organisation must meet
- A maturity assessment within the course area
- The option of follow-up, sparring and further advisory support
What your organisation actually gains
- Increased competence across the organisation
- Stronger governance and risk understanding
- Better compliance with EU requirements (NIS2, the AI Act, GDPR and others)
- Improved supplier control
- Reduced operational risk
- A better basis for management decisions
- A stronger position in tenders and customer assessments
- Faster maturity development
- More robust processes and culture
Competence is not a cost. It is an investment in safer decisions, better governance and increased value.
Get in touch
We offer a no-obligation scoping conversation to identify which courses best suit your organisation. Whether you need two hours with the leadership team, a full day for an entire department or a complete week-long course, we tailor the training to match your organisation's needs, pace and level of ambition.
Is your Board ready for NIS2?
Download the 2026 Executive Checklist for Cyber Liability.
Your address is used to send you the guide, and handled as described in our privacy statement. privacy statement.