Cyber hygiene and security training
Article 21(2)(g) requires essential and important entities to ensure that their personnel possess basic cybersecurity knowledge and follow cyber hygiene practices. The goal is to reduce the risk of security incidents caused by human error or lack of awareness across all levels of the organization.
What it means
In practice, this requirement mandates a shift from occasional training to an ongoing program of behavioral change. It distinguishes between "training" (the formal transfer of knowledge) and "cyber hygiene" (the habitual application of security best practices in daily operations).
The scope extends beyond IT staff to include all employees, contractors, and senior management. Because the Directive emphasizes risk management, the depth and frequency of training should be proportional to the specific risks the organization faces and the access levels of the personnel involved.
Ultimately, this control is intended to harden the "human firewall." An entity must demonstrate that its people are not only aware of threats but are actively practicing the routines necessary to mitigate them.
How to meet it
- Establish a formal cybersecurity awareness program with defined learning objectives for different roles (e.g., general staff vs. privileged administrators).
- Implement mandatory onboarding training for all new hires and regular refresher courses for existing staff.
- Define and communicate "cyber hygiene" standards, such as strong password management, the use of multi-factor authentication (MFA), and clean-desk policies.
- Conduct periodic phishing simulations to test employee vigilance and provide immediate corrective training for those who fail.
- Deliver targeted briefings for senior management regarding their specific risks and legal responsibilities under NIS2.
- Use a variety of delivery methods, such as short video modules, newsletters, or workshops, to ensure engagement.
Evidence an auditor asks for
- A documented training curriculum or syllabus detailing the topics covered and the frequency of updates.
- Completion records or certificates proving that all required personnel have finished their assigned training.
- Reports from phishing simulations showing baseline metrics, failure rates, and subsequent remediation efforts.
- Signed acknowledgments (digital or physical) where employees confirm they have read and understood the cyber hygiene policies.
- A schedule of planned security awareness activities for the current calendar year.
Common pitfalls
- "Check-the-box" compliance: Using generic, once-a-year slide decks that do not test knowledge or change behavior.
- Excluding leadership: Failing to train executives and board members, who are often high-value targets for attackers.
- Lack of tailoring: Providing the same basic training to IT administrators as to administrative staff, ignoring the higher risk associated with privileged access.
- Absence of metrics: Being unable to prove that training is effective because no tests or simulations were conducted.