Resources

/

Templates & Checklists

Ready-to-use templates for your security program

Checklists, reporting templates, playbooks, and annual plans — all tailored to German law and typical healthcare scenarios. Download after a brief sign-up, no follow-up campaigns.

PDF

NIS2 · Self-Assessment

NIS2 Readiness Check: 32 Audit Points according to Section 30 of the BSIG

Structured self-assessment based on the ten risk management measures according to § 30 BSIG, broken down into 32 concrete checkpoints with maturity assessment. The result: a reliable baseline assessment in 60 minutes — with a prioritized list of gaps.

8 pages

For management, ISB, IT management

DOCX

NIS2 · Reporting Obligations

NIS2 reporting templates: 24h, 72h, 30 days

Three pre-prepared Word templates for the § 32 BSIG reporting obligation: initial report (24 hours), assessment report (72 hours), final report (30 days). Healthcare scenarios as sample wording, with all required fields structured and ready to fill out directly in an emergency.

12 pages

For management, ISB, CISO

DOCX

BETRVG · SAMPLE TEXT

Phishing Simulation Works Agreement

Complete model works agreement for phishing simulations — purpose limitation, anonymisation, retention periods, access rights, works council evaluation. Compliant with Section 87 (1) No. 6 BetrVG, Art. 28 and Art. 6 (1) lit. f GDPR. Directly negotiable.

10 pages

For management, HR, staff council

XLSX

Awareness · Annual Planning

Awareness Program: 12-Month Annual Plan

Editable Excel template for a 12-month awareness program with monthly topics, module suggestions, target group matrix, and KPI tracking sheet. Suitable as proof of training for NIS2 (§ 30 BSIG) and the IT security guideline according to § 390 SGB V.

3 tables

For HR, ISB, Security Team

MORE RESOURCES

Templates alone are not enough. NIS2 checks, guides, and webinars build the context.

For those who first want to clarify whether NIS2 applies to them at all: Our eligibility check provides an initial assessment in just two minutes. For more in-depth written analyses, we offer guides on NIS2 implementation in medical centers (MVZs) and hospitals, ransomware emergency planning, phishing law, and Section 30 of the BSIG, as well as live webinars with Q&A for interactive, dialogue-based formats.

FREE RISK ASSESSMENT

30 minutes. An honest picture of your security posture.

Every conversation begins with a free risk assessment — 30 minutes, no obligation. You will then receive a written report with your cybersecurity maturity level, risk areas, and immediate measures.

FREE RISK ASSESSMENT

30 minutes. An honest picture of your security posture.

Every conversation begins with a free risk assessment — 30 minutes, no obligation. You will then receive a written report with your cybersecurity maturity level, risk areas, and immediate measures.