During due diligence, audit or preparation for NIS2, the same question often comes back: Do employees know what they need to do to reduce digital risks, and can the organisation demonstrate this? One cybersecurity awareness training is not a loose e-learning or annual obligation, but a management measure. Training shall contribute to safe behaviour, better incident recognition and demonstrable control of human risks.

Cybersecurity awareness training starts at risk, not at behaviour campaigns

Many organisations start with awareness because employees click on phishing, reuse passwords or share sensitive information too easily. Those are visible symptoms. The underlying risk is greater: employees make daily decisions with an impact on confidentiality, integrity and availability of information. Without clear instruction, repetition and review, this risk remains difficult to manage.

A good one. cybersecurity awareness training Therefore, it does not start from fear or general warnings, but from the processes where risk arises. Think of financial approvals, customer data, access to systems, supplier communication, home working, data sharing and incident reporting. It is precisely there that safe behaviour must be concrete, verifiable and enforceable.

Kynexis Information Security approaches awareness as part of broader risk management. More information on the approach is on the page Security Awareness Training. For organisations wishing to know first where the greatest risk of behaviour is, a wider range of Cyber Security Audit help to replace assumptions with a factual picture.

Why cybersecurity awareness training is administratively relevant

Cybersecurity is often technically made, while many incidents start with human action. An employee opens an attachment, approves a payment request, shares data via an unsafe channel or reports a deviation too late. The impact can directly work in operational disruption, data leaks, contractual claims, repair costs and reputational damage.

For board members, the question is therefore not whether employees have ever completed training. The question is whether the programme reflects the organisation's risk appetite, critical processes and legal obligations. Under NIS2 and the Dutch Cybersecurity Act, cyber hygiene is explicitly linked to governance, duty of care and demonstrability. Training is therefore part of being in control.

This requires a different way of looking. Awareness is not an IT communication campaign, but a structural management measure that affects governance, HR, legal, compliance, IT and process owners. If ownership is lacking, training remains non-binding. If follow-up is missing, there will be no measurable improvement.

Cybersecurity awareness training under NIS2 and the Dutch Cybersecurity Act

NIS2 places greater emphasis on appropriate technical, operational and organisational measures. This is what the human factor is specifically covered by. Organisations need to be able to show that employees understand cyber risks, know policies and know how to act in case of deviations. In addition, board members should have sufficient knowledge and skills to identify risks and assess measures.

One cybersecurity awareness training should therefore be in line with the governance of the organisation. The management should be able to see whether the training is being followed, whether the content is up to date, which groups are at extra risk and whether incidents or test results lead to improvement. Without that link awareness remains an activity without decision-making value.

For the board and executive management additional deepening is often required. The page NIS2 Boardroom Training deals specifically with board-level responsibility, oversight and decision-making under the Dutch Cybersecurity Act. For employees, the emphasis is on practical action: identify, report, verify and work safely.

What cybersecurity awareness training should deliver concretely

The value of training is not in participation rates alone. A high percentage of completed modules says little when employees still do not know how to report an incident or how to check a suspicious payment request. Training shall lead to behaviour appropriate to the risk performance of the organisation.

An effective cybersecurity awareness training Therefore, at least four manageable outcomes are obtained:

  • staff recognise relevant threats such as phishing, social engineering and data breach risks;
  • staff members know what actions to take in the event of doubt or incidents;
  • managers can follow up on behaviour, deviations and learning points;
  • the governance receives measurable information on participation, effectiveness and improvement points.

This shiftes awareness from transmission to control. Training becomes part of a continuous process in which policies, behaviour, incidents and measurements reinforce each other. Organisations that want to deepen this can also look at Improve security awareness or a targeted security awareness workshop.

Measurability determines whether cybersecurity awareness training works

Without measurability, awareness remains difficult to steer. Participation is a starting point, but not an end point. Board members and IT board members need information about risks, trends and effectiveness. Think of clicking behaviour in phishing tests, reporting rate. Time to report, results of knowledge assessments, repeated deviations and differences between departments or roles.

These figures are only useful if they are put into context. A higher reporting rate can be positive if employees recognise incidents more quickly. A low score in a specific department does not have to be blamed, but may indicate insufficient instruction, unclear policy or high operational pressure. The goal is not to settle, but to improve.

In adult organisations, these insights are linked to governance. The results of the cybersecurity awareness training come back in management reports, improvement plans, incident reviews and periodic risk analyses. This creates a demonstration: the organisation shows that it recognises risks, takes measures and organises follow-up.

Cybersecurity awareness training in a deal context

A takeover or investment often underestimates awareness. Yet human behaviour can have a direct impact on valuation, closing and integration. If employees are not trained in data classification, incident reporting or secure handling of customer information, uncertainty arises about privacy risks, operational continuity and compliance.

During an IT due diligence is therefore relevant whether awareness is demonstrably set up. Are trainings repeatable? Are results measured? Is there role-based training for finance, HR, sales, IT and management? Are suppliers and temporary employees taken? And is it clear how incidents are reported and escalated from the organisation?

If these questions remain unanswered, they may lead to additional conditions, higher integration costs or priorities in the 100-day plan. More about digital risks in transactions is on the page IT, Cyber and Privacy Due Diligence. Awareness is not a detail, but a signal for the maturity of governance and internal control.

From training to permanent change in behaviour

One-time training is not enough. Threats change, systems change, and organisations change. New employees come in, teams work differently and suppliers get access to processes or data. Therefore, a cybersecurity awareness training follow a recurring cycle: analyse, train, measure, improve and reassess.

Role-based training strengthens that process. A finance employee needs different scenarios from a system administrator, account manager or board member. Finance must recognise payment fraud and CEO fraud. HR must handle personal data carefully. IT must understand how logging, access management and incident response connect. Board members must be able to ask the right questions about risk, impact and demonstrability.

When awareness is linked to policies, processes and reporting, an executable approach is created. Employees know what is expected of them. Managers can adjust. The Board will have a view on risks and progress. That is the step from awareness to demonstrably safe behaviour.

Summary: cybersecurity awareness training is a management measure

One cybersecurity awareness training is effective only if it goes beyond informing. The training should help employees identify risks, make appropriate choices and report incidents in time. Board members must be made aware of whether the measure is working and where improvements are needed.

In an environment with NIS2, increasing chain risks and higher expectations of customers and supervisors, awareness is part of being demonstrably in control. Not as a loose project, but as a structural part of cyber governance. Organisations that link training to risk analysis, measurable and follow-up not only reduce the risk of incidents, but also strengthen their position in audits, customer questions, investments and acquisitions.

Do you want to know how mature your organisation is in the field of awareness and digital risks? Start with the Quickscan Cybersecurity or see how CISO as a Service can help to ensure training, policy and governance in a structural way.