Specialist training paths in Information Security and Cybersecurity, from conceptual foundations to regulatory compliance.

The path builds the vocabulary and the conceptual models on which all the rest of the training rests: what we protect, from whom, with which controls and with what risk logic. It is the recommended prerequisite for the other paths.

Who it is for: all staff, with particular value for those with IT, process or compliance responsibilities.

Estimated duration: 26 hours. 6 modules, 93 test questions, 6 exercises.

Content updated to August 2026 with the European regulatory framework in force (NIS2 and Legislative Decree 138/2024, ACN determinations, CRA, DORA, AI Act) and with the threat context data from the Clusit Report 2026 and the ENISA Threat Landscape.

The everyday practices that measurably reduce the attack surface of a person and of an organisation. Practical in style: every module closes with concrete actions to apply straight away.

Who it is for: all staff, regardless of technical role.

Estimated duration: 26 hours. 6 modules, 93 test questions, 6 exercises.

Content updated to August 2026 with the European regulatory framework in force (NIS2 and Legislative Decree 138/2024, ACN determinations, CRA, DORA, AI Act) and with the threat context data from the Clusit Report 2026 and the ENISA Threat Landscape.

The human factor is not the weak link: it is the first detection sensor, if trained. The path works on the psychological mechanisms of manipulation and on recognising the attacks that come through people, including those carried out with synthetic voice and video.

Who it is for: all staff; the modules on payment order fraud and insider threat are particularly useful for administration, treasury and human resources.

Estimated duration: 26 hours. 6 modules, 100 test questions, 6 exercises.

Content updated to August 2026 with the European regulatory framework in force (NIS2 and Legislative Decree 138/2024, ACN determinations, CRA, DORA, AI Act) and with the threat context data from the Rapporto Clusit 2026 and the ENISA Threat Landscape.

The regulatory and methodological framework within which a defensible security programme is built. The path does not stop at describing the frameworks: it shows how they map onto each other and how they turn into verifiable evidence.

Who it is for: IT and security managers, compliance contacts, management bodies of entities in NIS2 scope.

Estimated duration: 35 hours. 8 modules, 129 test questions, 8 exercises.

Disclaimer. The contents are for training purposes and do not constitute legal advice. For the obligations that fall on your organisation always refer to the legislation in force and to internal legal support.

Content updated to August 2026 with the European regulatory framework in force (NIS2 and Legislative Decree 138/2024, ACN determinations, CRA, DORA, AI Act) and with the threat context data from the Rapporto Clusit 2026 and the ENISA Threat Landscape.

A path that starts from the meaning of the prompt and arrives at the routine management of a server in service. Every command is presented for what you need to know in order to use it well: what it answers, in what situation it is used, how it is written, which examples make it clear and what happens when you get it wrong.

Who it is for: anyone who administers or will have to administer Linux systems, IT contacts, developers who work on remote servers, and anyone coming from Windows who needs an orderly way in.

Prerequisites: none of a technical nature. You need a Linux system to practise on: a virtual machine, a container or a test server are all fine.

Estimated duration: 39 hours. 9 modules, 124 test questions, 9 practical exercises, a final test and a personal certificate.

Content updated to August 2026. The examples are verified on Debian and Ubuntu; where the Red Hat family behaves differently the text says so. Every module points to the relevant official documentation.

The path builds, step by step, the incident management process that the NIS2 Directive and Legislative Decree 138/2024 require of organisations: how you prepare, how an incident is detected and classified with the ACN taxonomy, what is notified to CSIRT Italia and when, how you respond technically and what you learn once the incident is closed.

Who it is for: IT and security contacts, CSIRT contacts and NIS points of contact, compliance managers, DPOs and anyone who has to write or apply an incident management plan.

Estimated duration: 26 hours. 6 modules, 96 test questions, 6 exercises, final test and personal certificate.

Content updated to August 2026 with the NIS2 Directive and Legislative Decree 138/2024, ACN determinations no. 379907/2025, 127437/2026 and 127434/2026, the ACN incident management guidelines (v1.1, April 2026) based on NIST SP 800-61r3, and the interplay with the GDPR obligations in the event of a personal data breach.

Unlocking progression: each module opens when you pass the test of the previous one (70% threshold, unlimited attempts). At the end, a final test of 30 questions on the whole path and, on passing, the certificate in PDF with a verification code.

The learning path takes you from the basics of artificial intelligence through to the obligations of Regulation (EU) 2024/1689: how generative models really work, how to work with them effectively and verifiably, what European law asks of those who provide them and of those who use them, and what security and data protection risks they bring into the organisation.

Who it is for: anyone who uses or is about to introduce AI tools at work; IT and security managers, compliance managers, DPOs, HR and training contacts, and anyone who has to write or apply a company policy on the use of AI. No technical skills are required.

Estimated duration: 31 hours. 7 modules, 114 test questions, 7 exercises, final test and personal certificate.

Content updated to August 2026 with Regulation (EU) 2024/1689 (the AI Act), the timetable rewritten by the Digital Omnibus (Regulation (EU) 2026/1744), Italian Law 132/2025 and the interplay with the GDPR. The working method draws on the public training materials of the Anthropic, OpenAI and Google Academies; the learning path is not affiliated with any provider and the selection criteria are written to be applied to any tool.

Unlock-based progression: each module opens when you pass the previous module's test (70% threshold, unlimited attempts). At the end, a final test of 30 questions on the whole learning path and, on passing, the PDF certificate with a verification code.

The learning path builds the business continuity programme an organisation needs in order to carry on delivering its services when something breaks: how the cost of downtime is measured with the business impact analysis, how recovery strategies are chosen, how the business continuity plan and the recovery plan are written, how they are tested and how you demonstrate to whoever audits you that they exist and that they work.

Who it is for: IT and security managers, process and production managers, compliance managers and risk managers, NIS contact points and DPOs, and anyone who has to write, approve or test a continuity plan.

Estimated duration: 26 hours. 6 modules, 96 test questions, 6 exercises, a final test and a personal certificate.

Content updated to August 2026 with ISO 22301 and the related standards (ISO 22313, ISO 22317, ISO/IEC 27031), the NIS2 Directive and Legislative Decree 138/2024 with the ACN (Italy's National Cybersecurity Agency) determinations, Regulation (EU) 2022/2554 (DORA) and Article 32 of the GDPR on restoring availability.

Progression by unlocking: each module opens once you pass the test of the previous one (70% threshold, unlimited attempts). At the end there is a final test of 30 questions on the whole learning path and, once you pass it, the certificate in PDF with a verification code.