- Meaning
- Basic security routines in everyday work
- Examples
- Updates, patches, MFA, strong passwords
- Relation to NIS2
- Named expressly in Article 21
- Effect
- Removes much of the risk for little effort
- Updated
- June 2026
- Editorial team
- Compliance Compass
What is cyber hygiene?
Cyber hygiene means the simple, regular technical and organisational habits that keep your level of security high over time – much as washing hands does in medicine. The term deliberately stresses the routine: security is decided not by one expensive tool but by the reliability with which basic measures are carried out again and again. Cyber hygiene is in that sense the practical, everyday underpinning of an ISMS and is aimed more at systems and processes than at the security consciousness of people, which is what Security awareness covers.
The routines that matter most
- Install updates and patches quickly and by priority
- MFA plus strong, unique passwords
- Regular, tested backups, with the restore itself practised too
- Keep the overview of assets and permissions current, and remove accounts that are no longer needed
- Training and Security awareness as the measure alongside them
Why it is so effective
Many successful attacks exploit simple, long-known gaps – an update that was never installed, a missing second factor, a forgotten default password. Good cyber hygiene closes exactly those ways in and removes a large part of the risk for modest effort, long before expensive specialist tools become necessary.
Cyber hygiene and NIS2
Article 21(2)(g) of NIS2 names basic cyber hygiene practices expressly as a required measure. They are the foundation that more demanding Controls are built on. For example: At a regional hospital operator that counts as an essential entity under NIS2, a disciplined monthly patch cycle combined with MFA on every remote connection stops a known VPN vulnerability from being exploited. Routines of that kind are not only effective, they also have to be evidenced: for serious omissions by essential entities, Article 34 sets a minimum ceiling of EUR 10 million or 2 % of total worldwide annual turnover, and Member States may set higher amounts.
Frequently asked questions
What is meant by cyber hygiene?
Cyber hygiene means the basic technical and organisational security measures you repeat regularly: patching promptly, installing updates, multi-factor authentication, strong and unique passwords and tested backups. They are the foundation that more demanding safeguards and controls are built on. The term deliberately stresses the routine: what decides your security is not one expensive tool but the reliability with which these basic measures are carried out again and again.
Is cyber hygiene part of NIS2?
Yes. Article 21(2)(g) of the directive names basic cyber hygiene practices expressly as a required risk management measure, alongside cybersecurity training. Entities in scope have to implement and document them in a way that can be demonstrated. Article 34 sets minimum ceilings for fines of EUR 10 million or 2 % of total worldwide annual turnover for essential entities and EUR 7 million or 1.4 % for important entities, and Member States may set higher amounts.
Why is cyber hygiene so effective?
Cyber hygiene is so effective because many successful attacks exploit known, long-documented weaknesses and simple omissions – an update that was never installed, a missing second factor, a forgotten default password. Routines carried out consistently and regularly close exactly those ways in and remove a large part of the risk for modest effort, long before expensive specialist tools become necessary.
Further reading: BSI IT-Grundschutz, the German baseline security standard – modules and basic measures