Cybersecurity & Certifications:
from awareness to legislation and certification
Six in-company courses around one question: how do you keep your organisation digitally safe, and how do you show that you do? From awareness for all staff and the obligations of the Dutch Cybersecurity Act to officially recognised Microsoft exams for your administrators.

Choose the training that suits your team
From digital awareness for all staff to recognised Microsoft certifications for IT professionals. Every training is in-company and fully tailored.
Cybersecurity Awareness
Your team learns to recognise and prevent digital threats: phishing, social engineering, password security and safe remote working. Practical, recognisable and immediately applicable.
NIS2 Compliance
What does the NIS2 directive mean for your organisation? Your team learns what obligations apply, what risks exist and how to remain demonstrably compliant.
SC-900
Microsoft Security, Compliance and Identity Fundamentals. The entry-level certification for anyone working with Microsoft 365 or Azure who wants to understand the basics.
AZ-900
Microsoft Azure Fundamentals: cloud concepts, Azure services, security and pricing models. A solid foundation for further Azure certifications.
MS-700
Managing Microsoft Teams: administrator skills for Teams admins, from configuration and policy to security, compliance and lifecycle management.
AB-900
Microsoft 365 Copilot & Agent Administration Fundamentals: the basics of Copilot administration, AI agents and governance within Microsoft 365. Prepares you for the official AB-900 exam.
Awareness, legislation or a certificate: where do you start?
These six courses solve different problems and are poor substitutes for one another. A certification track does not make your people more alert, and a day of awareness produces no exam result. Below is what each of the four groups is good at, and where the limit lies.
Awareness for all staff
Phishing, fake invoices, someone following a colleague through the door, and these days a phone call in a voice that sounds like the director. The value is not in listing threats but in practising with messages that resemble your own: your house style, your suppliers, your payment process. The conversation is then about what should have stood out, rather than about an example from a leaflet.
Where it stops: one day changes behaviour for about six weeks. Without repetition, without a reporting button that works and without a culture in which a wrong click can be reported without fuss, it fades. We would rather plan two shorter sessions with time in between than one long day.
Cybersecurity Awareness trainingComplying with the Dutch Cybersecurity Act
Since 15 August 2026, NIS2 is law in the Netherlands. If your organisation is covered, you register with the NCSC, take risk management measures and report significant incidents within 24 hours. The board approves those measures and, since this Act, carries a training obligation of its own, with a transition period until 15 August 2028.
Where it stops: training does not make you compliant. Your inventory, your policy and the evidence behind it stay your own work. What the day does do is put the board in a position to judge whether what exists is enough, and make visible where the gaps are.
NIS2 Compliance trainingMicrosoft fundamentals: SC-900 and AZ-900
Two entry-level certifications that are often requested together. SC-900 covers security, identity and compliance across Microsoft 365 and Azure: who may access what, how conditional access works, what happens with labels and retention. AZ-900 covers the cloud itself: what a region is, what you are buying and what you are paying for. For most teams AZ-900 is the logical first, because SC-900 leans on concepts explained there.
Where it stops: a fundamentals certificate gives a shared vocabulary, not professional competence. It is meant for people who need to follow the conversation, such as procurement, project management and functional administration, not as training for whoever actually configures the environment. What such an exam does and does not test, and why a fundamentals certification never expires while a role-based one has to be renewed every year, is set out in AZ-900: what the certification is and is not.
AZ-900 Azure Fundamentals SC-900 Security, Compliance & IdentityAdministration and governance: MS-700 and AB-900
For the people who actually configure the environment. MS-700 covers Microsoft Teams: policies, guest access, meeting settings and the life cycle of teams and channels, including what happens to a team nobody uses any more. AB-900 is the newest in the series and covers the administration of Microsoft 365 Copilot and the agents your colleagues build themselves: who may create one, which data it may reach and how you can see that afterwards.
Where it stops: both are about settings you control. Whether your colleagues also do what the policy intends is a different question, and it belongs with awareness, or with training on the application itself.
MS-700 Managing Microsoft Teams AB-900 Copilot & Agent AdministrationWhich training suits you?
From awareness for all staff to official Microsoft certifications for IT professionals. Here's how to choose the right training.
Awareness & compliance
For all staff who want to work consciously and safely with digital tools.
What the Dutch Cybersecurity Act asks of you
Of all the questions we were asked on this subject this year, most concern one law. NIS2 is a European directive and does not apply directly; in the Netherlands it has been translated into the Cyberbeveiligingswet, the Dutch Cybersecurity Act, which entered into force on 15 August 2026. More than eight thousand organisations across eighteen sectors are covered. Whether you are one of them is something you determine yourself, based on your sector and your size, and nobody will notify you.
- Registration. If the Act applies to you, you register in the entity register held by the NCSC. That obligation has applied since the day the Act took effect.
- Duty of care and reporting duty. You carry out a risk analysis, take appropriate and proportionate measures, and report a significant incident within 24 hours to the CSIRT and to the supervisor for your sector. A substantive notification follows within 72 hours, and a final report after one month at the latest.
- Training obligation for the board. Executive directors of essential and important entities must be able to assess the risks themselves. Directors already in post have until 15 August 2028, and keep that knowledge current afterwards. Employees are not under a personal training obligation, but cyber hygiene and cybersecurity training are among the measures you take under the duty of care.
Those last two rules explain why organisations usually ask us for two things at once: a session for the board and recurring awareness for everyone. What the Act contains, who it applies to and what you have to be able to show afterwards is set out on the page about the NIS2 Compliance training.
Do you need a certificate, or a habit?
“Which cybersecurity certificates do we need?” is a question we hear often, and the honest answer is usually: fewer than you think, and for different people than you thought. A certificate is evidence of knowledge at a moment in time. It says nothing about how your environment is configured and nothing about how your colleagues handle a suspicious email. Two reasons to choose one anyway do hold up.
- Someone asks for it. In tenders, in an audit, or from a client who wants to know whether your administrators know what they are doing. An official Microsoft exam is then the shortest route to an answer that counts.
- It forces completeness. An exam syllabus walks through topics you would skip in a tailored course because they do not apply to you right now. That is sometimes exactly where the gap is.
If neither applies, a course built on your own environment usually delivers more than an exam. We say so even when you ask for the exam: it saves you a day and gives your team more. And the other way round, if you do certify, we prepare for the real exam, including the question formats, so the result is no surprise. You sit the exam itself at a Microsoft test centre or online; we do not administer it.
One thing holds for everyone: there is no awareness certificate worth having. What counts there is repetition, and the number of reports that reach you. That second figure should rise when an awareness programme works, which tends to surprise boards.
The same threat, different work
A director, a management assistant and a systems administrator run into very different versions of the same problem. The director has to weigh a risk without knowing the technology, the assistant is the first to see the fake invoice and the urgent request, and the administrator has to be able to configure the policy. We match the examples to the role; for three groups we have set that out in an entry of its own.
Weighing risks without knowing the technology, approving measures and being able to show that you did so carefully.
Fake invoices, urgent requests on behalf of a director, other people's calendars and mailboxes, and sharing safely with parties outside the organisation.
Agreements everyone keeps: what you report, to whom, and what happens when someone clicks anyway.
Does your team work in another field? Every course is in-company and is built around your own work. These three are simply the entries the question came from most often.
At your location, online or blended
We are based in The Hague and train throughout the Netherlands. In practice we are most often with organisations in the Randstad, in The Hague, Rotterdam, Amsterdam, Utrecht, Leiden and Delft, but distance is no obstacle: a day in Eindhoven, Zwolle or Groningen takes the same preparation.
- At your location. The most common choice, and clearly the best one for awareness: we use your own house style, your supplier names and your own payment process in the examples.
- Online. In Teams, preferably in half-days. Practical for organisations spread across several sites, and for a board that struggles to free up a whole day.
- Blended. A day on site and a shorter follow-up session online a few weeks later. For awareness that is not a luxury but the difference between remembering and forgetting.
A course runs for a day as standard, with a maximum of twelve participants. A half-day workshop on a single subject is possible too, for instance a session for the board or a phishing workshop for one department. The certification courses follow the length of the exam syllabus: SC-900 and AB-900 one day, AZ-900 two days, MS-700 four. We train in English and in Dutch.
From need to result
Every training is tailored to your organisation, your work processes and the level of your team.
Explore
What's really going on? Through intake and observation we map your reality.
Design
Materials and methods tailored to your team, tools and daily context.
Practise
Doing, not just listening. Cases from your own practice, immediately applicable.
Embed
Commitments and follow-up so what's learned sticks beyond the training day.
What people usually want to know
All our courses in this category are in-company, which means there is no rate per participant. What a day costs depends on group size, duration, format and how much preparation is needed to work with your own situation. Tell us what you are looking for and you will have a tailored proposal within two working days.
Yes, if your organisation is covered by the Dutch Cybersecurity Act. That Act places a training obligation on the executive directors of essential and important entities: they must be able to assess the risks to their network and information systems. Supervisory board members and non-executive directors are not covered. Directors already in post have until 15 August 2028.
Employees are not under a personal training obligation. Cyber hygiene and cybersecurity training are, however, among the measures you have to take under the duty of care, which makes them recurring rather than one-off. What works in practice is an annual session with a short refresher in between, and a reporting process people actually dare to use.
No. We prepare for SC-900, AZ-900, MS-700 and AB-900, including the question formats you will meet in the exam, so the result is no surprise. You sit the exam itself at a Microsoft test centre or online through their own exam environment. We do help with planning and with the question of which exam fits which role.
The full-day Cybersecurity Awareness course includes an exercise with phishing messages that resemble your own. We do not offer a running simulation service in which test emails go out to your staff for months on end; that works better through your own managed service provider or through the tooling already in your Microsoft 365 environment. We are happy to help read the results.
Yes. We are based in The Hague and train throughout the Netherlands, at your own location. Rotterdam, Amsterdam, Utrecht and the rest of the Randstad are the familiar route, but Eindhoven, Zwolle or Groningen works just as well. We also train online, which for a board that struggles to free up a whole day is often the practical choice.
Awareness is half a day or a full day, NIS2 Compliance a full day. The certification courses follow the length of the exam syllabus: SC-900 and AB-900 one day, AZ-900 two days, MS-700 four days. A half-day workshop on a single subject is possible too, for instance a session for the board alone.
The courses in this category are delivered to teams within one organisation. Which courses start on fixed dates and can be booked individually is shown on the open enrolment calendar.
Want to know more about cybersecurity training?
Whether it's awareness for your entire team or preparation for a Microsoft certification: we'll help you choose. Get in touch.