• NormaShieldAcademy

    Specialist cybersecurity training

    Security skills you can verify

    The training platform that takes people across the whole organisation from the fundamentals of Information Security through to regulatory compliance, with structured learning paths, tests at every step and personalised certificates with a verification code and one year validity. Every piece of content is available in Italian and in English.

    Create your account Resume your courses Browse the paths

    Aligned withNIS2NIST CSF 2.0CIS Controls v8.1ISO/IEC 27001AI Act

    8Learning paths
    54Modules
    217Lessons
    54Decision-based exercises
    845Test questions
    235Hours of training

    The programme

    Eight paths, one progression

    The four security paths are independent but designed to be followed in sequence: first the language of security, then everyday practice, then the human factor, finally governance. Together they form a complete curriculum, from the first notion of risk through to the compliance audit. Alongside them, four specialised paths: the Linux command line, from zero to administering a server in production; incident management under NIS2 and ACN (Italy's National Cybersecurity Agency) determinations, from preparation to notifying CSIRT Italia (the national CSIRT); artificial intelligence, from the fundamentals of generative models to the obligations of the AI Act; and business continuity, which answers the question all the others depend on: how long the organisation can stay down, and what it takes not to go beyond that.

    01 Introductory level

    Information Security Fundamentals

    The vocabulary and the conceptual models everything else rests on: what you protect, against which adversaries, with which controls and with what risk logic. It is the recommended prerequisite for the other paths.

    Risk analysisSecurity controlsCryptography and identity

    6 modules · 24 lessons · 26 hours · final certificate

    EnrolExplore this path

    02 Operational level

    Cybersecurity Hygiene

    The everyday practices that measurably reduce the attack surface, from credential management to data continuity. Every module closes with a checklist you can apply straight away.

    Credentials and MFAUpdatesBackup and recovery

    6 modules · 24 lessons · 26 hours · final certificate

    EnrolExplore this path

    03 Behavioural level

    Cybersecurity Awareness

    The human factor is not the weak link: trained properly, it is your first detection sensor. How manipulation works, how to recognise attempted attacks and how to build a culture of reporting.

    Social engineeringPhishing and fraudReporting

    6 modules · 24 lessons · 26 hours · final certificate

    EnrolExplore this path

    04 Advanced level

    Compliance and frameworks

    The regulatory and methodological framework of a defensible security programme: not only what the frameworks require, but how they map onto each other and how they turn into evidence an auditor can verify.

    NIS2ACN specificationsNIST CSF 2.0ISO/IEC 27001

    8 modules · 32 lessons · 35 hours · final certificate

    EnrolExplore this path

    05 Technical path

    Linux system administration from the command line

    From the meaning of the prompt to the day to day running of a server. For every command: what it answers, in which situation you use it, how you write it and what happens when you get it wrong. Every lesson contains terminal sessions meant to be reproduced, not read, and points to the official documentation.

    Filesystem and permissionsStreams and pipelinesProcesses and systemdNetworking and SSHScripting and hardening

    9 modules · 36 lessons · 39 hours · final certificate

    EnrolExplore this path

    06 Specialist level

    Security incident management and response

    The process that NIS2 and Legislative Decree 138/2024 really require: preparing with a plan and defined roles, classifying with the ACN (Italy's National Cybersecurity Agency) taxonomy, notifying CSIRT Italia (the national CSIRT) within 24 and 72 hours, responding while preserving the evidence and learning from the incident. With a precise link to the GDPR whenever the data is personal.

    NIS2 and Legislative Decree 138/2024ACN determinationsNotifications to CSIRT Italia

    6 modules · 24 lessons · 26 hours · final certificate

    EnrolExplore this path

    07 Cross-cutting level

    Artificial intelligence: fundamentals, tools and the AI Act

    From the basics of AI to the obligations of Regulation (EU) 2024/1689: how generative models really work and why they get things wrong, how to work with them methodically, what European law asks of those who provide them and those who use them, and what security and data protection risks they bring into the organisation. No technical skills required.

    Fundamentals and generative modelsWorking methodAI ActData and security

    7 modules · 29 lessons · 31 hours · final certificate

    EnrolExplore this path

    08 Organisational level

    Business continuity and disaster recovery

    Sooner or later every organisation comes to a halt: the difference between a disruption you manage and one you simply suffer is decided beforehand. How to measure the cost of downtime with a business impact analysis, how to set RTO and RPO, how to design backups that hold up against an encryption attack, how to write plans that can be used under pressure and how to test them. With the continuity obligations of NIS2, DORA and the GDPR.

    ISO 22301Business impact analysisStrategies and plansNIS2 and DORA

    6 modules · 24 lessons · 26 hours · final certificate

    EnrolExplore this path

    The method

    Study, test, apply

    The same structure across every path, so the pace of study stays predictable from the first module to the certificate.

    Step 1

    Four lessons per module

    The treatment of the topic, the regulatory background with sources you can verify, the documented real-world cases and the in practice chapter: what you do on Monday morning. Operational in tone, with no needless jargon.

    Step 2

    Test

    Pass mark 70%, unlimited attempts. Every answer, including a wrong one, comes with an explanation of why.

    Step 3

    Decision-based exercise

    A case to work through by choosing: every decision opens a different path and the outcome depends on what you chose, with an explanation of what would have happened otherwise. You can retake it as many times as you like.

    At the end

    Certificate

    Once the modules are complete, the final test of the path unlocks and, on passing it, a personalised PDF certificate with a verification code. It is valid for one year: after that the path reopens for recertification.

    The proof

    Training you can prove

    For a regulatory obligation, delivering the training is not enough: you have to be able to prove it years later. The platform produces by itself the evidence an audit asks for.

    Verifiable certificates

    Every certificate carries a unique code: whoever receives it can check that it is genuine on the public verification page, without registering and without having to ask anyone.

    Annual validity

    Twelve months after completion the path reopens by itself: tests to retake on updated content and a new certificate. The training stays alive instead of becoming a PDF in a drawer.

    Progress and study time

    A progress bar module by module and recorded study time: anyone following a path always knows where they stand, and anyone administering the training can document it.

    Evidence retained

    Completions, test results and certificates stay on record even after the annual renewal: each person's training history can be reconstructed for the whole retention period.

    Italian and English, the same path

    Every lesson, every question, every diagram and every certificate exists in both languages: not two parallel courses, but the same path switching language with one click. Anyone with staff who do not work in Italian trains them and documents it the same way, with the same records and the same certificates.

    The obligations

    The training the regulations require

    Four European regulations now require organisations to hold documented skills. Every path is built to answer a specific obligation, article in hand.

    Who it is for

    A path for every role

    All staff

    Hygiene, awareness and AI literacy require no technical skills: they cover the training obligations of NIS2 (Article 21) and of the AI Act (Article 4) for anyone who works with digital information and tools.

    IT and security leads

    Fundamentals, compliance, incident response, Linux administration and business continuity: risk models, the taxonomy of controls, recovery objectives and the operational practice needed to build a defensible security programme.

    Management bodies

    NIS2 places responsibility for the measures on the top of the organisation, together with a duty to be trained: the compliance and business continuity paths are designed with this in mind too, because policy, recovery objectives and accepted risks are decisions nobody can take on behalf of senior management.

    Consistency

    We practise the security we teach

    A platform that trains people in cybersecurity is also judged by how it handles your data and your access. Here the rules taught in the courses apply first of all to us.

    Multi-factor sign-in

    Privileged accounts can only sign in with a second factor. For learners, access stays simple: the weight of security falls on those who administer the platform, not on those who study.

    Passphrases, not convoluted passwords

    The policy asks for long, memorable phrases, exactly as the Hygiene path teaches: no mandatory symbols pushing people towards predictable passwords.

    Documented privacy

    A clear privacy notice at registration and a public register of purposes and retention periods, which anyone can consult without an account.

    Encryption and backups

    Encrypted traffic, daily backups with an integrity check and separate environments: the cyber hygiene of the courses, applied to the platform that hosts them.

    How to get access to the paths

    Every path has its own overview page, with the full syllabus and how the course runs. From there, access takes three steps:

    • Create your account. Registration is free and takes a minute: all you need is a valid email address and its confirmation.
    • Buy or request the path. Once signed in, from the Available paths page you buy the 12-month subscription on your own: you pay by bank transfer and the activation key, personal and single-use, arrives at your email address. Companies and public bodies can instead request several seats from the Enrol me form: a contact person receives the keys to hand out and pays in a single instalment, including by bank transfer against an invoice.
    • Activate your access. Paste the key and the path opens straight away. If your organisation has already given you the key, this is the only step you need.

    With the subscription you have access to the path for 12 months from when you redeem the key, with a reminder before it expires; complete it, and your access remains available with no time limit and your certificates and progress stay yours. Keys issued without a subscription open the path for 90 days, with a reminder 15 days before the deadline.

    Create your account I already have a key

    The content is intended for training purposes and does not constitute legal advice. For the obligations that fall on your organisation, refer to the legislation in force and to qualified legal support.