Key information
- Application opening date: July 27, 2026
- Next application deadline: September 25, 2026
- Next course starts: October 1, 2026
- Format: Fully online, asynchronous and synchronous
- Course duration: 8 weeks
- Language: English
- Awarding Institution: Brno University of Technology
- Delivered by: Brno University of Technology
- Certified by: Brno University of Technology
- EQF Level: 6 / QF EHEA 1
- ECTS: 3 ECTS (78 hours of total student workload, including 21 hours of synchronous online lectures and 57 hours of asynchronous self-directed learning).
- Fees: €210
Microcredential Information
The aim of this educational module is to familiarise participants with the basic approaches to cybersecurity regulation, both in an international context and within the framework of Czech legislation. The module focuses on the related legal aspects of cybersecurity and the relevant regulatory framework, enabling participants to gain a basic understanding of the topic and identify the main legal challenges in this area.
Key Details
Approximate Total workload: 78 hours
The module is designed to fit around professional and personal commitments. All core content is available asynchronously for self-paced study, complemented by optional live sessions offered throughout the module.
The individual lectures follow on from each other logically.
Lecture 1 – Intro + Secure data handling 101
Lecture 2 – Introduction to Cybersecurity Governance
Lecture 3 – Cybersecurity regulation in the EU
Lecture 4 – Compliance in Cybersecurity
Lecture 5 – Identity management
Lecture 6 – Personal Data Protection
Lecture 7 – Regulating AI data governance
Assessment
The MC will be completed with an exam consisting of a test. The final exam will be conducted online in the presence of instructors, with both microphone and camera turned on. The test contains 35 questions randomly generated from the MC question bank. Five random questions will be selected from each of the seven lectures and their corresponding practical exercises. To pass the exam, it is necessary to score at least 50% on the test. As part of the conclusion of the MC, a consultation hour will also be provided, during which the correct answers and contextual aspects of the relevant legal regulations will be discussed with the participants.
Register your interestSubjects covered
Lecture 1 – Intro + Secure data handling 101: This lecture provides an introduction to cybersecurity law and secure data handling. It covers key concepts and reasons for regulation and compliance requirements. The lecture also explores legal obligations for securing digital assets in context of cybersecurity and expands key principles which will be discussed throughout this course.
Lecture 2 – Introduction to Cybersecurity Governance: This lecture introduces the importance of cybersecurity and its regulation, focusing on the EU’s legal frameworks like the NIS2 Directive and Cybersecurity Act. It explores cybersecurity risks, governance approaches, and international cooperation. Participants will gain insights into regulatory measures and institutional roles in addressing cyber threats.
Lecture 3 – Cybersecurity regulation in the EU: This lecture examines key legislative instruments shaping the EU’s cybersecurity framework following on the introduction to cybersecurity. It covers the need for harmonized rules and explores in more depth crutial major regulations, including the NIS2 Directive, Cybersecurity Act, Cyber Resilience Act, Cyber Solidarity Act, and DORA. The discussion highlights their implementation at the national level, the role of institutions like ENISA and the European Commission, and the importance of cooperation among Member States. This lecture thus focuses on the relations and intersections between regulatory instruments.
Lecture 4 – Compliance in Cybersecurity: This lecture explores how organizations can integrate EU cybersecurity regulations, such as NIS2, the Cybersecurity Act, and the Cyber Resilience Act, into daily practices. It highlights risk management, the role of Information Security Management Systems (ISMS), and certification mechanisms for compliance. The discussion includes ENISA’s guidance, national enforcement differences, and real-world case studies, helping students understand how to align legal requirements with operational security.
Lecture 5 – Identity management: This lecture explores identity management, focusing on the legal framework established by the eIDAS Regulation and its expansion under eIDAS 2. It examines electronic identity (eID) in both public and private sectors, highlighting challenges in secure authentication and the role of private identity providers. A key topic is the European Digital Identity Wallet, which aims to enhance cross-border interoperability and security. Participants will gain insights into the regulatory, technical, and practical aspects of digital identity management in the EU.
Lecture 6 – Personal Data Protection: T his lecture covers the legal framework for personal data processing and EU data transfer restrictions, focusing on the GDPR. It explores key principles, datasubject rights, cybersecurity overlaps, and international transfer mechanisms like adequacy decisions and contractual safeguards, with practical case studies on compliance challenges.
Lecture 7 – Regulating AI data governance: This lecture explores cybersecurity and privacy challenges in AI development and deployment, focusing on regulatory and standardization efforts. It examines ENISA’s reports on AI security, the role of AI in cybersecurity, and risks from malicious AI use. The discussion includes the AI Act and its interaction with cybersecurity frameworks, extending beyond traditional security to trustworthiness aspects like transparency and data protection, with a focus on challenges in AI training data.
Register your interestLearning objectives
Knowledge – The graduate can:
- introduce basic terminology in the field of cybersecurity, understand the fundamental aspects of legal regulation
- explain current methods of regulation
Skills – The graduate can:
- identify relevant legislation and be able to apply it to relevant entities,
- analyze and propose specific vectors for setting processes and rules for relevant entities.
- assess regulatory settings in a broader context and with related impacts on management,
- analyze the impacts of legal regulation in the field of cybersecurity, including its specific manifestations,
- evaluate the impacts of cybersecurity regulation, including the setting of compliance aspects and their specifics.
Competence – The graduate can:
- think creatively and work independently,
- plan and organize their own activities,
- collaborate effectively,
- assess and process safety requirements imposed by legislation.
Module leaders
Name: Pavel Loutocký
Title: Dr.
Organisation: Masaryk university