August 31, 2026

Strengthening and building cyber awareness for NIS2

Cybersecurity awareness is more than an annual e-learning exercise. With NIS2, organisations need to treat human behaviour as part of risk management, using targeted awareness, measurable behaviour change and continuous improvement to build stronger cyber resilience.

Why awareness matters

Cybersecurity is no longer only a technical concern. NIS2 places greater responsibility on leadership and organisations to manage cyber risk proactively, with awareness and human security forming an important part of the overall approach. Effective security culture helps people recognise risks, respond appropriately and act as a first line of defence.

From compliance to behaviour change

Many organisations measure completion rates, quiz results or phishing clicks, but these metrics do not necessarily show whether risk has been reduced. A stronger approach starts by identifying the human risks and behaviours that need to change, then selecting the right mix of training, simulations, nudges and other interventions for specific audiences.

A practical approach

The recommended approach has three stages, strategy and analysis, design and implementation, and scale and improvement. The example roadmap shows how an organisation can spend time identifying behavioural gaps before launching targeted initiatives, combining broad awareness with specialised interventions and using measurable outcomes to continuously improve the programme.