06Specialist level

Security incident management and response

The path builds, step by step, the incident management process that the NIS2 Directive and Legislative Decree 138/2024 require of organisations: how you prepare, how an incident is detected and classified with the ACN taxonomy, what is notified to CSIRT Italia and when, how you respond technically and what you learn once the incident is closed.

NIS2 and Legislative Decree 138/2024ACN determinationsNotifications to CSIRT Italia

Enrol meI already have an account

6modules
26estimated hours
96test questions
6exercises
30questions in the final test

How it is delivered

Delivery
Entirely online and asynchronous, from any device: you study when you want, at your own pace.
Passing the tests
At least 70% correct answers; every answer comes with an explanation of why.
Attempts per test
Unlimited: the best attempt counts.
Time per test
20-40 minutes per test.
Progress
Tracked module by module: each module unlocks when you pass the test of the previous one.
On completion
A personal PDF certificate, with a unique verification code.
Length of access
You have 90 days from enrolment to complete the learning path. Once you complete it your access stays available with no expiry; if the deadline passes without the path being completed, the enrolment is suspended and the results you have already achieved stay on record.
Enrolment
With a personal key, after you have created your account.

The learning path in detail

Welcome. This path turns the obligations of the NIS2 Directive and of Legislative Decree 138/2024 into a process you can actually run: who does what when an incident happens, within which deadlines you notify, with which tools you respond and what must remain in writing at the end. The common thread is the ACN Guidelines on incident management (v1.1, April 2026), built on the NIST SP 800-61r3 model, and ACN determination No 379907/2025 with the taxonomy of significant incidents.

Path objectives

By the end of the path you will be able to:

  • distinguish between event, incident, significant incident and near miss, and place the GDPR personal data breach in relation to NIS2 (Module 1);
  • set up preparation: policies, an incident management plan approved by the management bodies, roles and RACI matrix, CSIRT contact (Module 2);
  • recognise and classify an incident with the ACN IS-1/IS-4 taxonomy and establish from what moment the notification deadlines run (Module 3);
  • manage the notification sequence to CSIRT Italia (24 hours, 72 hours, one month) and the dual track with the Garante when personal data are involved (Module 4);
  • carry out investigation, containment, eradication and recovery while preserving the evidence (Module 5);
  • close the loop: lessons learned, review of the plan, responsibility of the management bodies and the sanctions regime (Module 6).

Who it is for and prerequisites

For IT and security contacts, CSIRT contacts and NIS points of contact, compliance managers, DPOs and anyone who has to write or apply an incident management plan. Having followed the paths on the fundamentals and on compliance first is recommended, but not required: this path takes the concepts of risk, threat and control as given.

How it runs

The path is delivered entirely online, asynchronously: you can study when you want, at your own pace, from any device. The estimated total duration is 26 hours, to be spread within the completion deadline set out below.

Each module is organised into four lessons and two tests:

  1. Lesson. A reasoned treatment of the topic, with precise legal references, diagrams and concrete cases.
  2. In depth. The up-to-date legal and technical picture, with the deadlines that matter and references you can check at source.
  3. Real-world cases. What really happens in the market: documented episodes always read with the same grid, down to the control that would have broken the chain.
  4. In practice. What you do on Monday morning: procedures, checklists, ready-made templates and indicators to measure the result.
  5. Test. Closed-answer questions on the whole module. Passing requires at least 70%; attempts are unlimited and the best mark counts. At the end of every attempt you receive a detailed explanation of each answer, including the correct ones.
  6. Exercise. A case to work through by deciding: every choice opens a different path and the outcome depends on what you chose, with an explanation of what would have happened otherwise. Marking is automatic and you can retake it as many times as you like.

Progression. The 6 modules are taken in sequence: each module unlocks only after you have passed the previous module test. The exercises do not block progress, but they are an integral part of the path and of the overall assessment.

Final test and certificate

Once you have passed the tests of all the modules the final test is unlocked: 30 questions drawn at random from the topics of the whole path, with the same 70% pass mark and unlimited attempts. On passing you obtain the path certificate, downloadable as a PDF, with a unique code that allows its authenticity to be verified.

Warning

The content is up to date as of August 2026 and cites ACN determinations and guidelines in force at that date. The NIS2 implementation framework is evolving: before planning any compliance step, always check the official texts on the ACN website and in the Gazzetta Ufficiale.

Completion deadline

You have 90 days from enrolment to complete the learning path. 15 days before the deadline you receive an email reminder.

If you complete the path within the deadline, your access stays available with no time limit and you receive the certificate. If the deadline passes without the path being completed, the enrolment is suspended: the results you have already achieved stay on record, and to carry on you need a new enrolment key.

Support

In the Announcements forum you will find the trainer's messages. For questions on the content or on the exercises, use the channels indicated by your training contact.

Programme

The modules are taken in sequence: each one opens when you pass the test of the previous one.

  1. Module 1

    The security incident: definitions and legal framework

    Event, incident, significant incident and near miss; the GDPR personal data breach and how it fits together with NIS2. The map of sources: Directive (EU) 2022/2555, Legislative Decree 138/2024, Regulation (EU) 2024/2690, ACN determinations and the Guidelines on incident management.

    LessonLessonLessonLessonTest · 16 questionsExercise

  2. Module 2

    Preparation: governance, roles and management plan

    The preparation phase of the ACN Guidelines: policies and a management plan approved by the management bodies, inventories, protection measures. The roles: point of contact, CSIRT contact, CISO, SOC, response team, legal department, and the RACI matrix that holds them together.

    LessonLessonLessonLessonTest · 16 questionsExercise

  3. Module 3

    Detection, triage and classification

    The monitoring required by measure DE.CM-01, the concept of evidence from which the deadlines run, triage and the taxonomy of significant incidents IS-1, IS-2, IS-3 and IS-4, with the differences between essential and important entities and the quantitative thresholds.

    LessonLessonLessonLessonTest · 16 questionsExercise

  4. Module 4

    Notification obligations

    The sequence early warning within 24 hours, notification within 72 hours, final report within one month; the ACN portal and the role of CSIRT Italia; voluntary notification; the dual track with the GDPR when the incident touches personal data; communications to recipients of the services and to the public.

    LessonLessonLessonLessonTest · 16 questionsExercise

  5. Module 5

    The response: investigation, containment, eradication and recovery

    The sub-phases of response according to the ACN guidelines: acquiring the evidence without destroying it, reconstructing the perimeter and the vector, containing, cleaning up and recovering with documented procedures. With a guided case on a ransomware attack.

    LessonLessonLessonLessonTest · 16 questionsExercise

  6. Module 6

    After the incident: improvement, liability and penalties

    Lessons learned and the review of the plan, exercises, metrics. The liability of management bodies under Art. 23 of Legislative Decree 138/2024, the penalty regime and the reason why designating the CSIRT contact is not a delegation of liability.

    LessonLessonLessonLessonTest · 16 questionsExercise

  7. Final test and certificate

    Thirty questions drawn at random from the topics of all the modules. On passing, the path certificate is issued.

    Test · 30 questionsCertificate

How to get access to the learning path

To follow "Security incident management and response" you need an account on the platform: registration is free and takes a minute. Once the account is created you can request the enrolment key for the learning path.

Enrol meI already have an account

Back to all learning paths