Cybersecurity awareness training
Also known as: Security awareness training, NIS2 training
Cybersecurity awareness training teaches employees to recognise and avoid cyber threats, such as phishing emails, weak passwords, and social engineering, and to report incidents quickly. Many attacks start with a person clicking a link or sharing a password, so this training is one of the most effective security measures a company can take. In the EU, the NIS2 directive makes it a requirement for many organisations.
What it covers
Core topics are spotting phishing and suspicious links, strong passwords and multi-factor authentication, safe handling of data and devices, recognising social engineering such as fake calls from IT, and how to report a suspected incident.
Good programmes match the risks of each role. Finance teams need to recognise payment fraud, and IT admins need deeper training than the average user.
What NIS2 requires
The NIS2 directive lists basic cyber hygiene practices and cybersecurity training among the minimum risk-management measures for essential and important entities (Article 21). It also requires members of management bodies to follow cybersecurity training, and encourages organisations to offer similar training to employees regularly (Article 20).
NIS2 covers many sectors, including energy, transport, banking, health, digital infrastructure, and parts of manufacturing, and each EU country applies it through national law. Check which rules apply to your organisation.
Read the compliance training definition
How often, and how to prove it
Most organisations train at onboarding, refresh at least once a year, and add short updates as new threats appear. Many also run simulated phishing tests.
An LMS assigns the right course to each role, sends reminders, and keeps a dated record of who completed what, including management training, ready for an audit or a regulator.
See Coursy for compliance training
Frequently asked questions
What is cybersecurity awareness training?
Training that teaches employees to recognise and avoid cyber threats such as phishing and social engineering, handle data safely, and report incidents quickly.
Does NIS2 require cybersecurity training?
Yes. Article 21 includes cybersecurity training and basic cyber hygiene among the minimum measures, and Article 20 requires management body members to follow training.
Who needs cybersecurity training under NIS2?
Members of management bodies must follow training, and staff training is part of the required risk-management measures. In practice most organisations train everyone, with deeper training for high-risk roles.
How often should cybersecurity training happen?
At onboarding, at least once a year, and with short updates as threats change. Many organisations add regular simulated phishing tests.
How do you prove cybersecurity training for an audit?
With an LMS that records who completed which training and when, including management training, and produces a report on demand.