Resources
/
Templates & Checklists
Ready-to-use templates for your security program
Checklists, reporting templates, playbooks, and annual plans — all tailored to German law and typical healthcare scenarios. Download after a brief sign-up, no follow-up campaigns.
NIS2 · Self-Assessment
NIS2 Readiness Check: 32 Audit Points according to Section 30 of the BSIG
Structured self-assessment based on the ten risk management measures according to § 30 BSIG, broken down into 32 concrete checkpoints with maturity assessment. The result: a reliable baseline assessment in 60 minutes — with a prioritized list of gaps.
8 pages
For management, ISB, IT management
DOCX
NIS2 · Reporting Obligations
NIS2 reporting templates: 24h, 72h, 30 days
Three pre-prepared Word templates for the § 32 BSIG reporting obligation: initial report (24 hours), assessment report (72 hours), final report (30 days). Healthcare scenarios as sample wording, with all required fields structured and ready to fill out directly in an emergency.
12 pages
For management, ISB, CISO
DOCX
BETRVG · SAMPLE TEXT
Phishing Simulation Works Agreement
Complete model works agreement for phishing simulations — purpose limitation, anonymisation, retention periods, access rights, works council evaluation. Compliant with Section 87 (1) No. 6 BetrVG, Art. 28 and Art. 6 (1) lit. f GDPR. Directly negotiable.
10 pages
For management, HR, staff council
XLSX
Awareness · Annual Planning
Awareness Program: 12-Month Annual Plan
Editable Excel template for a 12-month awareness program with monthly topics, module suggestions, target group matrix, and KPI tracking sheet. Suitable as proof of training for NIS2 (§ 30 BSIG) and the IT security guideline according to § 390 SGB V.
3 tables
For HR, ISB, Security Team
MORE RESOURCES
Templates alone are not enough. NIS2 checks, guides, and webinars build the context.
For those who first want to clarify whether NIS2 applies to them at all: Our eligibility check provides an initial assessment in just two minutes. For more in-depth written analyses, we offer guides on NIS2 implementation in medical centers (MVZs) and hospitals, ransomware emergency planning, phishing law, and Section 30 of the BSIG, as well as live webinars with Q&A for interactive, dialogue-based formats.