The BSE Cybersecurity Guide provides businesses with ten practical steps for strengthening cybersecurity and improving resilience against digital threats. It covers risk assessment, cybersecurity governance and planning, protection of systems and data, employee awareness, business continuity, incident response, standards and certification, cyber insurance, and supply-chain security. The guide supports organisations, particularly SMEs, in systematically managing cyber risks, protecting business operations and developing a stronger cybersecurity culture.
Operational and Compliance Training
Access a wealth of resources including articles, whitepapers, tools, and guides to support your learning.
- Risk Management
Cybersecurity Risk Management Standards and Methodologies
- Published date:
- Author: European Union Agency for Cybersecurity (ENISA)
This publication provides an overview of established standards addressing cybersecurity and information security risk management. It examines relevant risk management approaches and presents methodologies and tools that organisations can use to implement or conform with these standards. The resource can support organisations in selecting appropriate frameworks and developing structured approaches to identifying, assessing and managing cybersecurity risks.
- Risk Management
SME Cyber Resilience and CRA Maturity Assessment Model
- Published date:
- Author: European Union Agency for Cybersecurity (ENISA)
This ENISA maturity assessment model helps SMEs evaluate and strengthen their cyber resilience and product security practices in line with the Cyber Resilience Act (CRA). Primarily aimed at manufacturers of products with digital elements, the model provides a structured approach for assessing cybersecurity maturity and identifying areas for improvement. It can also support integrators, service providers and other organisations involved in the digital product lifecycle. An accompanying Excel-based assessment tool enables practical application of the model.
- Risk Management
ENISA Cybersecurity Maturity Assessment for SMEs
- Published date:
- Author: European Union Agency for Cybersecurity (ENISA)
The ENISA Cybersecurity Maturity Assessment for SMEs is an online self-assessment tool that helps small and medium-sized enterprises evaluate their cybersecurity maturity across people, technology, and organisational processes. Based on the assessment results, the tool provides a tailored action plan with practical recommendations to improve cyber resilience, strengthen security practices, and support the management of cybersecurity risks.
- Compliance Standards
Technical Competence Requirements for Cyber Resilience Act (CRA) Notified Bodies
- Published date:
- Author: European Union Agency for Cybersecurity (ENISA)
This ENISA publication outlines the high-level technical competence requirements for Conformity Assessment Bodies (CABs) seeking designation as Notified Bodies under the EU Cyber Resilience Act (CRA). The document focuses on the knowledge, experience, training, and auditing capabilities required for personnel involved in evaluating the cybersecurity conformity of products. It provides guidance for developing qualified assessment teams and supports the consistent implementation of CRA certification and conformity assessment processes across the European Union.
- Risk Management
ENISA NIS360: Maturity and Criticality Assessment of NIS2 Sectors
- Published date:
- Author: European Union Agency for Cybersecurity (ENISA)
The ENISA NIS360 is an assessment framework that evaluates the maturity and criticality of sectors covered by the NIS2 Directive. Drawing on data from national authorities, organisations operating in critical sectors, and EU-level sources, the tool provides both a comparative overview and detailed sector-specific analysis. It helps Member States, regulators, and stakeholders identify cybersecurity capability gaps, benchmark sector readiness, and prioritise investments and resources to strengthen cyber resilience across critical sectors.
- Compliance Standards
EU AI Act Service Desk and Single Information Platform
- Published date:
- Author: European Commission
The EU AI Act Service Desk and Single Information Platform provide practical tools and guidance to help organisations understand and comply with the European Union AI Act. The platform includes the AI Act Explorer, Compliance Checker, implementation guidance, FAQs, and support services designed to assist stakeholders in assessing obligations related to trustworthy and high-risk AI systems. It supports startups, SMEs, developers, and deployers in navigating AI governance, compliance, and risk management requirements across the EU.
- Compliance Standards
Guidelines for Providers and Deployers of High-Risk AI Systems under the EU AI Act
- Published date:
- Author: European Commission
These European Commission guidelines support providers and deployers in understanding and classifying high-risk AI systems under the EU AI Act. The document explains key obligations, risk categories, and practical implementation considerations, including examples across sectors such as biometrics, critical infrastructure, education, employment, and migration. The guidelines aim to facilitate compliance, improve trustworthy AI deployment, and support the secure and responsible use of AI systems across the European Union.
- Compliance Standards
ENISA National Cyber Security Strategies Interactive Map
- Published date:
- Author: European Union Agency for Cybersecurity (ENISA)
This interactive tool by ENISA provides a comprehensive overview of national cybersecurity strategies across EU Member States and selected European countries. Users can explore each country’s strategic priorities, implementation status, key organisations, and supporting initiatives such as ISACs, R&D activities, and public-private partnerships. The platform supports policy awareness, benchmarking, and the exchange of best practices across Europe.
- Compliance Standards
EU AI Act: Cybersecurity, Risk Management and Trustworthy AI Governance Framework
- Published date:
- Author: European Parliament & Council of the European Union
The EU Artificial Intelligence Act (Regulation (EU) 2024/1689) establishes a risk-based framework for the secure and trustworthy development, deployment, and use of AI systems across the European Union. From a cybersecurity perspective, the regulation introduces strict requirements for high-risk AI systems, including risk management, robustness, resilience against attacks, and protection against data manipulation and system vulnerabilities. It also sets obligations for general-purpose AI models to address systemic risks, enhance transparency, and ensure secure lifecycle management. By integrating cybersecurity into AI governance—alongside compliance, monitoring, and incident response—the AI Act strengthens the resilience of digital systems and mitigates emerging threats associated with AI technologies.