Pader­born Uni­ver­sity makes SMEs fit for cy­ber se­cur­ity

 |  DigitalizationResearchEconomy & BusinessTransferSoftware Innovation Campus Paderborn (SICP)Faculty of Business Administration and EconomicsFaculty of Computer Science, Electrical Engineering and Mathematics

Online tool and learning platform support NIS2 directive

The new EU Network and Information Security Directive (NIS2) has also been in force in Germany since the beginning of the year. This obliges numerous companies to improve their cyber security. With the KMU.kompetent.sicher and FitNIS2 projects, the SICP - Software Innovation Campus Paderborn supports SMEs in assessing their vulnerability and optimising their cyber security strategy. The new learning platform has now gone live.

NIS2 is the revised EU directive from 2022 and affects around 30,000 companies from 18 sectors, from healthcare to transport to telecommunications. Due to the integration into supply chains and the digital networking often associated with this, the directive also affects many small and medium-sized enterprises (SMEs). "SMEs in particular often struggle with limited resources in the field of IT security and are dependent on vendor-independent support," says Prof Dr Simon Thanh-Nam Trang from Paderborn University. This is precisely where two projects come in, in which the SICP - Software Innovation Campus Paderborn, a research and innovation network of Paderborn University with business partners, is involved.

KMU.kompetent.sicher offers customised e-learning with NIS2 reference

In the KMU.kompetent.sicher project, the SICP is working with the University of Hohenheim, the InnoZent OWL innovation network and the IT service provider coactum to develop a training platform to provide SMEs with practical support in implementing the NIS2 directive. The project is being sponsored by the Federal Ministry for Economic Affairs and Energy with around one million euros and will run for two years.

After the first year of the project, the project partners have reached an important milestone: the learning platform has now been activated. It consists of practice-oriented "learning nuggets", i.e. small modular (video) learning units, quiz questions and interactive tasks to apply what has been learnt. Storytelling elements such as true crime examples are used, for example, to show how phishing, a form of internet fraud, works, what the consequences are and what measures can protect against it. The learning paths "NIS2 basic protection" and "Assessing threats correctly" cover topics tailored to NIS2. Further learning paths are planned, such as IT security culture, risk management, backup management, secure handling of emails, emergency management, password security and ransomware.

Overall, the project aims to train management and employees. The concept includes a control loop to identify training needs for the company and anchor them in the culture in the long term.

Who is affected by the NIS2 Implementation Act and what needs to be done? The FitNIS2 Navigator finds out

In the "FitNIS2" project, the SICP has developed the FitNIS2 Navigator in cooperation with Deutschland sicher im Netz e.V. and the Cybersecurity Transfer Centre. In the first step, the online tool analyses whether a company is covered by the directive. In the second step, the current level of compliance with the NIS2 requirements is analysed and in the third step, users receive clear recommendations on how they can meet the NIS2 requirements. The project is being sponsored by the Federal Ministry for Economic Affairs and Energy (BMWE) for a total of two years until August 2026. The free FitNIS2 Navigator has been available since June 2025 at: https://fitnis2.de.

Just three months after the tool was released, the FitNIS2 Navigator's impact assessment was completed 1,500 times. In addition, 700 participants have completed the self-assessment to fulfil the NIS2 requirements. This means that the planned utilisation targets were achieved in the first half of the year. The Navigator is currently being expanded to include specific requirements for small companies based on the cyber risk check from the German Federal Office for Information Security (BSI). Sector-specific criteria will also be added in the next phase of the project. In future, SMEs will receive targeted information on their NIS2 exposure and possible overlaps with other relevant regulations, depending on their sector.

"Both projects thus provide a free introduction to the topic of NIS2. An extensive range of events in the projects complements the information on offer," says Dr Simon Oberthür, Head of Digital Sovereignty Innovation at the SICP - Software Innovation Campus Paderborn.

Symbolic image (Paderborn University, Jennifer Bounoua)

Contact

business-card image

Dr. Simon Oberthür

Software Innovation Campus Paderborn (SICP)

R&D Manager - Digital Security

Write email +49 5251 60-6822