- Meaning
- The security consciousness of your staff
- Typical topics
- Phishing, passwords, social engineering
- Relation to NIS2
- Training is mandatory (Article 21)
- Effect
- It narrows the largest way in, which is people
- Updated
- June 2026
- Editorial team
- Compliance Compass
What is security awareness?
Security awareness describes how well the people who work for you recognise dangers and react correctly. Because people are the most frequent target of attack – through phishing, social engineering or forged invoices – well-trained staff are among the most effective protective measures there are. Unlike the more technical Cyber hygiene, which aims at systems and routines, awareness addresses the human factor directly: knowledge, attention and the right behaviour at the decisive moment.
Why people are the focus
Technology alone is not enough: many attacks aim at people, not at systems. A convincing forged e-mail, a faked call from the IT department or a payment instruction that looks urgent is often all it takes to walk around good technical safeguards. Awareness closes exactly that gap by enabling staff to recognise the familiar patterns of manipulation and, in case of doubt, to ask rather than act.
How awareness becomes effective
It is not the single course that counts but the regular repetition – short, practical training sessions, simulated phishing tests and clear, low-threshold ways of reporting a suspicious e-mail. A culture without blame matters just as much: someone who reports a wrong click at once helps the organisation more than someone who hides it out of fear. Awareness thereby complements good Cyber hygiene and a living ISMS.
Security awareness and NIS2
Article 21(2)(g) of NIS2 names basic cyber hygiene practices and cybersecurity training among the minimum measures, and Article 20 extends the training duty expressly to the Management body, which carries personal responsibility for cybersecurity. Awareness is therefore not a nice-to-have but a required measure. In concrete terms: A logistics company runs quarterly ten-minute training sessions and unannounced phishing simulations, and records who took part. When an employee receives a deceptively genuine supplier e-mail carrying altered bank details, he recognises the warning signs, reports them along the defined route – and stops a transfer to fraudsters. Documented proof of training of exactly this kind is what a competent authority expects as part of the NIS2 duties.
Further reading: ENISA – the EU Agency for Cybersecurity
Frequently asked questions
What does security awareness mean?
Security awareness is the security consciousness of the people who work for you: their ability to recognise threats such as phishing, social engineering or forged payment instructions and to react correctly. Because people are the most frequent target of attack, well-trained staff count among the most effective protective measures there are. Awareness complements technical safeguards by addressing the human factor directly: knowledge, attention and the right behaviour at the decisive moment.
Is awareness training mandatory under NIS2?
Yes. Article 21(2)(g) of the NIS2 Directive names basic cyber hygiene practices and cybersecurity training among the minimum risk management measures, and Article 20 obliges the management body itself to follow training and to carry personal responsibility for cybersecurity. Documented proof of that training is what your national competent authority will ask for. Article 34 sets minimum ceilings for fines of EUR 10 million or 2 % of total worldwide annual turnover for essential entities, and Member States may set higher amounts.
How do you make awareness work?
Awareness works through short, regular, practical training sessions, simulated phishing tests and clear, low-threshold ways of reporting a suspicious e-mail, not through a single course. What decides the outcome is a culture without blame: someone who reports a wrong click at once helps the organisation more than someone who hides it out of fear. That is how security consciousness settles into everyday work for good.