Glossary · Term

Cyber hygiene explained

Cyber hygiene covers the basic security measures of everyday work – patching, strong passwords, MFA, updates and training.

At a glance
Meaning
Basic security routines in everyday work
Examples
Updates, patches, MFA, strong passwords
Relation to NIS2
Named expressly in Article 21
Effect
Removes much of the risk for little effort
Updated
June 2026
Editorial team
Compliance Compass

What is cyber hygiene?

Cyber hygiene means the simple, regular technical and organisational habits that keep your level of security high over time – much as washing hands does in medicine. The term deliberately stresses the routine: security is decided not by one expensive tool but by the reliability with which basic measures are carried out again and again. Cyber hygiene is in that sense the practical, everyday underpinning of an ISMS and is aimed more at systems and processes than at the security consciousness of people, which is what Security awareness covers.

The routines that matter most

Why it is so effective

Many successful attacks exploit simple, long-known gaps – an update that was never installed, a missing second factor, a forgotten default password. Good cyber hygiene closes exactly those ways in and removes a large part of the risk for modest effort, long before expensive specialist tools become necessary.

Cyber hygiene and NIS2

Article 21(2)(g) of NIS2 names basic cyber hygiene practices expressly as a required measure. They are the foundation that more demanding Controls are built on. For example: At a regional hospital operator that counts as an essential entity under NIS2, a disciplined monthly patch cycle combined with MFA on every remote connection stops a known VPN vulnerability from being exploited. Routines of that kind are not only effective, they also have to be evidenced: for serious omissions by essential entities, Article 34 sets a minimum ceiling of EUR 10 million or 2 % of total worldwide annual turnover, and Member States may set higher amounts.

Frequently asked questions

What is meant by cyber hygiene?

Cyber hygiene means the basic technical and organisational security measures you repeat regularly: patching promptly, installing updates, multi-factor authentication, strong and unique passwords and tested backups. They are the foundation that more demanding safeguards and controls are built on. The term deliberately stresses the routine: what decides your security is not one expensive tool but the reliability with which these basic measures are carried out again and again.

Is cyber hygiene part of NIS2?

Yes. Article 21(2)(g) of the directive names basic cyber hygiene practices expressly as a required risk management measure, alongside cybersecurity training. Entities in scope have to implement and document them in a way that can be demonstrated. Article 34 sets minimum ceilings for fines of EUR 10 million or 2 % of total worldwide annual turnover for essential entities and EUR 7 million or 1.4 % for important entities, and Member States may set higher amounts.

Why is cyber hygiene so effective?

Cyber hygiene is so effective because many successful attacks exploit known, long-documented weaknesses and simple omissions – an update that was never installed, a missing second factor, a forgotten default password. Routines carried out consistently and regularly close exactly those ways in and remove a large part of the risk for modest effort, long before expensive specialist tools become necessary.

Further reading: BSI IT-Grundschutz, the German baseline security standard – modules and basic measures

Cyber hygiene

The basics that make the difference

Compliance Compass keeps the basic safeguards in view – the foundation of your NIS2 compliance.