Process Security & Data Protection
NIS2 and GDPR Consulting
+ Art. 20 Training (D.Lgs. 138/2024)
Hands-on support for NIS2 and D.Lgs. 138/2024 compliance: gap analysis, remediation, continuous auditing and Art. 20 e-learning pathways for Management, CISOs, IT professionals and staff.
NIS2 is EU Directive 2022/2555 on cybersecurity; Legislative Decree 138/2024 (D.Lgs. 138/2024) is its transposition into Italian law.
Talk to an expertHealthcare cybersecurity: the 3 risks NIS2 requires you to mitigate
Healthcare organisations are now a primary target for cyber attacks, with devastating consequences not only for privacy but for operational continuity and patient safety.
Ransomware attacks
When hospital IT systems are locked down, the damage is not just financial: operating theatres stop, emergency departments grind to a halt and patients' lives are put at risk.
GDPR penalties
Unlawful processing of health data carries the highest administrative fines (up to €20M or 4% of turnover) and irreparable reputational damage.
The new NIS2 Directive
Healthcare organisations are now classified as "essential entities". The legislation imposes strict security obligations and direct liability (including criminal liability) for directors.
GDPR and NIS2 consulting: an integrated approach
A holistic approach combining legal, technological and organisational expertise.
GDPR & Privacy
Not just paperwork, but data governance. We provide an external DPO service specialised in digital healthcare, with round-the-clock data breach management.
- DPIA (Data Protection Impact Assessment)
- Appointment of external data processors
- Privacy training for staff
NIS2 Compliance
Hands-on support for compliance with the EU cybersecurity directive. We prepare your organisation to guarantee the continuity of essential services.
- Business continuity plan
- Incident response plan
- Supply chain security
Essential or important entity under NIS2? Free exposure check
Leave nothing to chance. Request a free preliminary assessment to understand your organisation's level of exposure.
Request a NIS2 assessmentE-learning pathways for NIS2 compliance
Art. 20 of D.Lgs. 138/2024 makes cybersecurity training a direct obligation for the management body and for all staff. Four dedicated pathways cover every profile in your organisation.
4
Dedicated pathways
48
Training modules
15h
E-learning content
80%
Certificate pass mark
Art. 20 D.Lgs. 138/2024
NIS2 Course for Management
For: Boards, CEOs and senior executives
9 modules · approx. 2.5 hours
Governance, accountability and strategic decision-making for the leadership of organisations in scope of NIS2. Compliance is not something to delegate to IT: it is personal, documented and enforceable.
Art. 21 D.Lgs. 138/2024
NIS2 Course for the CISO
For: Chief Information Security Officers
10 modules · approx. 4 hours
The role of the CISO in the NIS2 ecosystem: technical governance, coordination of the Art. 21 measures and reporting to top management, with a focus on evidence, security KPIs and relations with the Italian cybersecurity agency (ACN).
Art. 21 D.Lgs. 138/2024
NIS2 Course for IT Professionals
For: IT technicians and security professionals
18 modules · approx. 6 hours
A hands-on programme for implementing, maintaining and documenting the technical measures required by Art. 21: risk analysis, SIEM and monitoring, identity and privileged access management, vulnerability management, backup and operational continuity.
Art. 20 D.Lgs. 138/2024
NIS2 Course for Non-Technical Staff
For: All employees and staff
11 modules · approx. 2 hours
Cybersecurity awareness with no technical prerequisites: phishing and social engineering, password hygiene, safe use of email and mobile devices, and how to recognise and report an incident in time.
Courses are delivered in Italian; an English translation is available on request.
Easy Health is an innovative start-up, ISO 9001 certified and a qualified supplier under Consip's Digital Healthcare framework (Italian public procurement). Find out who we are to meet the team and see our credentials.
Our approach
Gap Analysis
Mapping data flows and identifying vulnerabilities against the regulations.
Remediation
Drafting procedures, deploying controls and training your people.
Continuous Audit
Ongoing monitoring to guarantee sustained compliance over time.