Strengthening and building cyber awareness for NIS2
Cybersecurity awareness is more than an annual e-learning exercise. With NIS2, organisations need to treat human behaviour as part of risk management, using targeted awareness, measurable behaviour change and continuous improvement to build stronger cyber resilience.
Why awareness matters
Cybersecurity is no longer only a technical concern. NIS2 places greater responsibility on leadership and organisations to manage cyber risk proactively, with awareness and human security forming an important part of the overall approach. Effective security culture helps people recognise risks, respond appropriately and act as a first line of defence.
From compliance to behaviour change
Many organisations measure completion rates, quiz results or phishing clicks, but these metrics do not necessarily show whether risk has been reduced. A stronger approach starts by identifying the human risks and behaviours that need to change, then selecting the right mix of training, simulations, nudges and other interventions for specific audiences.
A practical approach
The recommended approach has three stages, strategy and analysis, design and implementation, and scale and improvement. The example roadmap shows how an organisation can spend time identifying behavioural gaps before launching targeted initiatives, combining broad awareness with specialised interventions and using measurable outcomes to continuously improve the programme.
Strengthening and building cyber awareness for NIS2
Cybersecurity awareness is more than an annual e-learning exercise. With NIS2, organisations need to treat human behaviour as part of risk management, using targeted awareness, measurable behaviour change and continuous improvement to build stronger cyber resilience.
Why awareness matters
Cybersecurity is no longer only a technical concern. NIS2 places greater responsibility on leadership and organisations to manage cyber risk proactively, with awareness and human security forming an important part of the overall approach. Effective security culture helps people recognise risks, respond appropriately and act as a first line of defence.
From compliance to behaviour change
Many organisations measure completion rates, quiz results or phishing clicks, but these metrics do not necessarily show whether risk has been reduced. A stronger approach starts by identifying the human risks and behaviours that need to change, then selecting the right mix of training, simulations, nudges and other interventions for specific audiences.
A practical approach
The recommended approach has three stages, strategy and analysis, design and implementation, and scale and improvement. The example roadmap shows how an organisation can spend time identifying behavioural gaps before launching targeted initiatives, combining broad awareness with specialised interventions and using measurable outcomes to continuously improve the programme.
View transcript
Welcome and thanks for joining. Today I will walk through how to strengthen cybersecurity culture with NIS2 as the frame. And this session is meant to be very practical, so hopefully you should leave with things that you can put to work tomorrow or maybe even later today. In a nutshell, we will cover how to use cyber awareness as a driver in mitigating cyber risks. And questions are welcome throughout. Please write them in the chat as they come and I will try to pick them up at the end of the webinar. So I hope you are ready with a warm cup of coffee this Monday morning. And if you are on transport, please keep your eyes on the road and just listen to my voice. I will send out the slides afterwards. But let's get going. First, a short plan of the next 30 minutes. We will start with a short introduction, who I am and why this topic is relevant right now. Then we will look at why awareness matters for cybersecurity and resilience. Third, I will go through what NIS2 actually requires on training and awareness. And I will close out with some pitfalls that I see the most often and an example of what our program looks like when it actually works. And that latter part is the most juicy bit with the most takeaways. So please save your energy for that. Briefly, so you know where this is coming from. My name is Ulrich and I am a partner here at Implement. I have a legal background and I am the co-head of our regulatory and compliance transformations team. I have spent the past 10 years working with regulatory and security requirements, mostly NIST 2, GDPR, DORA and the ISO standards, especially the 27 series. Most of my time goes into organizations working out what these requirements mean in practice, going from a set of rules to actual human behavior change. And that's something I find both very fun and very challenging as well. And awareness in particular, I think, is the part my clients most often underestimate. It looks like an easy requirement, but I actually think that it's one of the things that it's most easy to get wrong. And that's why I wanted to spend a session on going into it a bit more. So before we go into NIST 2 and awareness specifically, I want to set a bit of context. So as you've all heard a million times, cyber risk is escalating at the moment. And what I find sort of in particular are four points. So first and foremost, ransomware keeps evolving and climbing. And the operators have gotten better at picking their targets. Secondly, more hybrid threats and geopolitical activity, particularly against critical sectors. Thirdly, supply chain attacks reaching further, where one compromised vendor exposes hundreds of customers potentially. And then fourthly, attackers are, as you all have heard by now, using AI. And that is in everything from automated technical attacks all the way to tailored phishing content. And meanwhile, plenty of organizations still run with what we could call a traditional reactive security model. You detect an incident, you respond, you recover, and you repeat. And security sits with a small team at the sideline and is involved way too late. And at today's volume, that model is running out of bandwidth. And the security team can only be in so many places at once. And that is why NIST 2 is pushing towards what we might call a more governance-based security model. And at the core of a governance-based security model is that you base your efforts on risks. You try to be proactive. You involve your management. And you adapt the management system when something changes. And I think that is very important for the session today because awareness is a fundamental part of going from a reactive mindset to a proactive, governance-based one. So before we go into what NIS2 specifically says about awareness, let me set the regulatory stage a bit. So NIST 2 marks what we have come to sort of call a clear shift. Cybersecurity stops being an IT concern and becomes a leadership responsibility with personal accountability and potentially liability attached directly to it. First and foremost, management's bodies have to approve risk measures, oversee them, and take trainings themselves. And as such, which I think is very important for the context of what we are talking about today, NIST 2 is risk-based rather than what you could call checklist-based. So nobody hands you a set of operational controls to TIC. You have to look at your own threat picture, the business impacts, and decide what is proportionate, and then be able to explain the reasoning for what you've done and what you're doing. And the measures in these two reach greatly beyond technology. So awareness and human security obviously are named directly alongside things like supply chain security, access management, asset management, encryption, and more. And what awareness means in practice is a culture where people recognize risk, know what to do when something looks wrong, and act as the first line of defense, you might say, rather than as a breach in your organization's firewall. So the short version, NIS2 moves cybersecurity from a technical function to an organizational responsibility, and awareness is how you make that real for the people who don't work in security every day. So awareness is a NIST 2 requirement. So far, so good. But if we set the directive aside for a moment, the human side of security, I would say, has more than earned its place at the table. Traditionally, security work rests on three pillars. Technology, process, and people. And in my experience, most organizations invest heavily in the first two. They buy tooling, they buy firewalls, they buy antivirus, and they document their processes to the teeth. And the people pillar tends to get sort of more of a yearly e-learning module and a poster in the canteen saying, remember to look out for phishing. And that's a real problem. Because very few controls will actually work without somebody changing their behavior. And as an example of that, you could say that access review controls depend on managers actually performing those reviews and knowing what to look for when they do. Otherwise, it's just a process. Similarly, incident reporting depends on people knowing how to react and reacting fast. And I think that there are, in particular, three things worth sort of holding up into this context. First and foremost, cybersecurity is rarely designed with humans in mind. And controls that fight the way people work gets bypassed. And that bypass is usually super invisible until something goes very wrong. Secondly, and that is also at the core of these two, like I mentioned, people are a dynamic risk factor. Behavior isn't changed and the stuff that can affect behavior isn't changed. And people will go a long way when responding or reasoning in a certain way makes sense to them. And they will always almost ignore rules that feel arbitrary and don't make sense to them. And then thirdly, investing in people is actually what makes the technical investments pay off. If there's a narrative that people believe in, you know, a slower login process or a stricter approval flow for new vendors, stop feeling like friction points and actually make sense to the individuals. So if there's one thing that you take away from today, it's this. Security awareness belongs in risk management. And it sits alongside your firewall rules and your access controls as a measure that reduces risk. And it deserves the same focus. And that is what I will go into on the next slides. With that introduction out of the way, let's look at what NIST 2 actually says about awareness. So the short answer is that less than you probably expect. And two provisions or two articles carry the main bulk of the weight. So first and foremost, Article 20 on management accountability. Leadership has to approve cybersecurity and risk management measures, oversee that they're implemented, and actually take trainings themselves on cyber risks. Secondly, Article 21 on cyber hygiene. Organizations must implement appropriate and proportionate technical and organizational measures. And the article names basic cyber hygiene practices and cybersecurity training explicitly among the requirements. And what the directive does not tell you anything about is the type of awareness and how often to do it and which audiences need to go through it beyond the management team. And that is where a few supporting texts come into play. So we have three main bodies of guidance that I would like to highlight. First and foremost, in Denmark, we have Styrelsen for Samfundssikkerhed that has provided guidance on adopting awareness in practice. And then we have something called the Implementing Regulation 2024-2690. I don't expect you to remember that. And then Enisa has published some guidance on that regulation. And I think one very important thing to note is that the Implementing Regulation and the Enisa guidelines apply formally only to certain digital and technology providers. So they don't apply to everybody who's covered by Enisa 2. But in a nutshell, I think that you should just go ahead and read them anyway. And that is because they are very clear articulation of what the European Commission thinks good awareness looks like. And supervisors in other sectors will most definitely have read them as well. So that's also why we will use them in this webinar as a benchmark while they're not directly part of the, while they're not directly part of Neist2. So, and I think my clicker is facing a bit of problems. Here we go. Yes. And on this slide, I've just made an overview to make it easier for you to navigate. So essentially, on the links that are provided on the slide, you can find all those three different texts. And we will, like I said before, share the slides after the webinar. Okay. So let's get down and dirty, so to speak. And now I want to go through some of the types of awareness that the sources name as potential types. And I have sort of bundled it into six different categories. First and foremost, on the upper left, we have cybersecurity information materials and handouts. Then we have virtual training. Then we have physical sessions and events. We have gamified interventions and nudgings. We have attack or incident simulations. And we have courses and certifications for IT professionals. And as you can see, this is a very, very broad range of types of awareness. I think that the one that we most often see is virtual training, being namely the traditional e-learning. And some of the things that I see the least is probably attack or incident simulations. But I think it's a very good sort of overview of how broad the scope actually is of what you can do. And then the question becomes, since NIST 2 doesn't prescribe any particular format, and since I have all these options, how do I choose what is right for my organization? And sadly, I cannot tell you that, what the right choice is, but I can tell you, like I said before, that the choice has to be risk-based. So instead of thinking about a specific format, think about the risk you're trying to reduce and the audience you're trying to reach. As an example, finance handling payment requests need something different from your development team doing secure code. And your board needs something else entirely, something different again. And the same story goes for frequency. The directive says nothing about that. That's risk-based too. So the frequency has to match the risk you're trying to address. But to be a bit more specific, I would say that each element of your awareness or culture program should run at least annually. And I'll get back to that in a moment. So again, look at the formats, be inspired by them, but remember to start with the risk and the audience, because that is really the point here. And in my experience, regulators and authorities will often give you a very large degree of grace if you can demonstrate that you focused on the risk instead of the type of awareness. And that brings me to sort of the next point, the other side of awareness, and that is measurement. How do we measure whether what we're doing is actually effective or not? And to that, I have mapped out a few types of metrics that you could use as examples. And in practice, what we see is that most awareness programs, they measure the training rather than the effect of the training. So very classic measurement points are stuff like completion rates, quiz responses, phishing click rates, engagement scores. So meaning how was the training campaign perceived by the audience and so forth. And they're all reasonable numbers. And they're also pretty easy to collect. Usually the provider that you use for your e-learning or for your phishing campaign or whatever can provide those numbers. But there is a problem with them. And that is that they don't tell you that the risk went down, just that the training took place and potentially that people like the training. But again, it doesn't tell you anything about the core risk that you are assumingly trying to address with doing whatever you're doing. So my advice is that while these metrics are good and you should start with them, you also need to add some metrics that track observed behavior changes. So are people actually reporting suspicious emails? Has the volume changed? Is the time to identifying breaches coming down? Are risk assessments coming back with better quality? Are people raising things with the security team that they used to just ignore or sit on? Those numbers are way harder to gather, but the ones that actually really make an impact for your security program. And last thing to note on this slide is the bottom right. Remember to put your metrics and your security and awareness program into your annual wheel and follow up on them at least once a year. And that will sort of ensure that you close the loop, that you measure, you see what worked, and then you adjust the program accordingly. And that is also something that I will get back to in a moment on how to do that a bit more specifically. Before we move on, I promised you that I would also mention some pitfalls when it comes to awareness and security culture. And for that purpose, we've made a little graph here where you can see on the very left-hand side, you have initiatives that have low impact. And on the right-hand side, you have initiatives that have more high impact. And if we start with something that has fairly low impact, that is on the left-hand side, like I said, pure compliance. Least possible effort. In essence, pure compliance means that people sign a document saying that, you know, I read the policy, I understand it, and I'll follow it every day. It's fast. It's very cheap. It doesn't really cost a dime. And if you're very lucky, it might get you an ISO stamp, but there is absolutely no behavior change, and you have no way of knowing whether what you're doing actually has any kind of impact. Then moving to the middle of the slide, the generic awareness. That is the classic e-learning, right? Where you roll out mandatory e-learning for your entire organization and then have them sit through that and test them at the end. And it requires a bit more effort, and it's a fairly good place to start if the field is new to you. But the problem is that usually everybody just clicks through the same e-learning. That means that the same training material goes to your CFO and your CEO and maybe even your board as your warehouse staff and your developers and your HR people and your front desk people. So it cannot be effective for all of them at once. And that means that you might have spent valuable hours of staff time and an expensive license without knowing whether you've actually touched on any real risk or not. And in my experience, most organizations sit between somewhere the two mentioned here, pure compliance and generic awareness. And what I think you should be nudging toward is what we have here on the very right-hand side of the slide. That means that you do the analytical work first, find out what your risks are, what behaviors drive them, what needs to change. And then you design your awareness and culture initiatives against that. So it costs more, but it's also way more efficient. And for organizations that are new to working with awareness and security culture, that might be a big stretch to start all the way up at the strategic intervention. And I just want to say that there is nothing wrong with starting with pure compliance or generic awareness, as long as you are aware that it will only cover your bases for so long and that it will not drive any changes long term. So looking at how to actually get that lasting impact, that strategic intervention, how does that work in practice? And doing it well has three steps. Strategy and analysis, design and implementation, and scale and improving. And a lot of organizations that we work with tend to jump straight into designing awareness and security culture initiatives. And that's because that's the fun part. That's why you get to choose the vendor and you get to design what you're doing and you get to do the pretty poster. But if we haven't analyzed our human risks, we might not design for any impact since we're not mitigating our highest risks. And therefore, we recommend that you take a step back, so to speak, and invest some time and energy in solving the right problem. And that is the strategy and analysis step. In essence, that means knowing your human risks. For instance, do people not know that there is an increased threat from cyber? Do they not know how to navigate this? Or do they know that the threat exists and how to navigate it but still don't have the right behavior? Those are three very different ways, three very different risks that could be addressed with very different kinds of awareness. And going through that step will inform your design phase a lot more. And you will have a much greater chance of actually mitigating your risks. And the last phase, scale and improve, means building on top continuously. And realizing that almost no matter what you do, it will never be perfect in the first go. And building a good security culture is not a one-off. It takes repetition and it requires putting some thought into learning from your initiatives and the inevitable mistakes that come with that. Again, we have to do with real people here. Then, before we head to the Q&A part, I want to spend a few moments on going through a client example of a roadmap for 2026. And it's fairly detailed, so I will not go into sort of depth with every deliverable. But there are a few things that I want to highlight for you. First, as you can see, we spent the entire first quarter of 2026 on ensuring that we are solving the right problem. So that was analysis mode, right? We began with a risk assessment that we got approved by management. And based on that, we defined the behavioral gap. So what is it that we need to do that we are not doing right now? And then we came up with measures to address that and to see whether it actually, the initiatives that we were going to roll out actually had the impact that we were planning for. And only after that was done, meaning after a full quarter, we started doing the actual awareness. And that had two tracks. So it had core initiatives, which were awareness that were rolled out across the business. And then secondly, what we called specialized initiatives, which included specific employee groups where there was an elevated risk. So you can see what we did here was that we addressed both a general lack and a specific lack in the organization. And the core initiatives regarded secure use of AI, while the core or the specialized initiatives regarded social engineering, in particular spear phishing. And at the end of the year, we will evaluate the success of the program in accordance with the set out metrics and then prepare for initiatives for 2027. And I think that in a way, this slide demonstrates the life cycle of working with awareness and security culture, figuring out what is our problem, figuring out how do we solve that problem in the right way, and then how do we continue to improve? And that is, in a nutshell, how to build good awareness and security culture. So to summarize, before we round off, NIST 2 raises expectations for cybersecurity governance and resilience. And awareness is now a core risk management control, sitting alongside access management, asset management, cryptography, vendor management, and all the more traditional cyber risk measures. And what we see is that organizations that succeed treat awareness as a behaving, shaping measure, and not just like a tickboxing exercise where you do the cheapest e-learning you can find, and then that's it. Should we start to be part of an organization that is still preparing to do its first security risk assessments? Should I then wait with awareness until all those assessments are done, or is there something that I could begin with doing now? And I think that's a very good question, actually, and a very difficult one to answer. And it sort of takes me back to how much do we analyze before we actually start doing something? And I think that while I'm not saying that I'm a massive fan of just rolling out e-learning across the business, if you're not doing anything right now, I would just find a small focus group of my company, figure out what is their level. And if you haven't done anything at all, there is a pretty big likelihood that the knowledge gap right now is the biggest one. So maybe they don't even know about cybersecurity. And if that is the case, then there's absolutely no problem with starting with some light e-learning or other sort of broad format training while you prepare for more in-depth things. And with that, I want to leave you to the rest of your day and the rest of your week. And as always, feel free to reach out to me either by phone or by email if you have any questions or comments or something you want to discuss regarding awareness. Have a very good day, everyone. Have a great day.