DOC-017 ← Document Portal

Cybersecurity Training and Awareness Programme

Training plan, phishing awareness, register and Board requirements
Document Number
DOC-017
Version
▸ 1.0
Status
DRAFT
Issue Date
▸ DD/MM/YYYY
Owner
▸ CISO / HR
Approved by
▸ Board / CEO
Legal Basis
Art. 21(2)(g) NIS2; Art. 21(1) NIS2 (Board training); ISO/IEC 27001:2022 A.6.3
Related Documents
DOC-016 | DOC-001

1. Board Training Requirement (NIS2 Art. 21(1))

⚠ Critical – Board MUST attend training (NIS2 requirement)

In accordance with Art. 21(1) NIS2, the management body must attend cybersecurity training to acquire the knowledge and skills sufficient to identify risks and evaluate cybersecurity risk management practices.

ParticipantRequired frequencyFormatDate of last training
▸ CEO / President ▸ min. once a yearmin. 1×/year – NIS2 ▸ [e.g. 4h workshop / e-learning] ▸ DD/MM/YYYY
▸ [Other Board members] ▸ min. once a yearmin. 1×/year

2. Annual Training Plan

TrainingTarget groupFrequencyDurationFormatDeadline
Security induction training New employees ▸ On hiringmax. 14 days from hiring ▸ [min. 2h]min. 1h ▸ [e-learning / live training] During onboarding
Recurring general training All employees ▸ once a yearmin. 1×/year – NIS2 ▸ [min. 2h]min. 1h ▸ [e.g. e-learning / webinar / workshop] ▸ [e.g. Q1 every year]
Board training Board / Senior Management ▸ once a yearmin. 1×/year – NIS2 Art.21.1 ▸ [min. 4h]min. 2h ▸ [e.g. expert workshop]
Technical training (IT) Administrators, IT department ▸ once a yearmin. 1×/year ▸ [min. 8h]min. 4h ▸ [conference / course / certification]
Phishing simulation All employees ▸ 2–4 times a yearmin. 2×/year N/A (campaign) Simulated phishing ▸ [e.g. quarterly]
Post-incident training Those affected by incident After every major incident ▸ [depending on incident] ▸ [debrief session + training] Within 30 days of incident

3. Training Content

Induction and recurring training (minimum):

  • Information Security Policy – basic principles (DOC-001),
  • Recognising phishing, smishing and vishing,
  • Secure passwords and use of MFA,
  • Information classification and data handling (DOC-010),
  • Incident reporting – how and when (DOC-005/006),
  • Secure remote work and BYOD,
  • Social engineering – recognising manipulation,
  • Clean desk / screen policy.

Board training (minimum):

  • Cybersecurity threat landscape in the sector,
  • NIS2 requirements and Board accountability,
  • Cybersecurity risk management – concepts,
  • Sector incident case studies,
  • Decision-making exercise (tabletop).

4. Phishing Simulations

Requirement – minimum 2 phishing simulations per year

Campaigns sent via: ▸ [e.g. KnowBe4 / Proofpoint Security Awareness / GoPhish]

MetricOrganisation's targetAction if exceeded
Click rate (% clicking link) ▸ [e.g. below 5%]target <10% Additional training for clickers, general communication
Report rate (% reporting phishing) ▸ [e.g. above 70%]target >50% Root cause analysis
Credential submission (% entering data) ▸ [0%]target 0% Immediate 1:1 training, password reset

5. Training Register

CISO / HR maintains a central training participation register. Register contains: name, position, training type, date, result (pass/fail/N/A), signature or e-learning confirmation.

Retention: ▸ [min. 5 years]min. 5 years – NIS2.

Tool: ▸ [e.g. LMS (Moodle/KnowBe4) / HR register / Excel spreadsheet]

⚠ Confirmation of NIS2 Art. 21(2)(g) compliance – Board training

The organisation confirms that Board training was conducted in year: ▸ [year], date: ▸ DD/MM/YYYY, participants: ▸ [list of Board participants].

Change History

VersionDateAuthorDescriptionApproved by
▸ 1.0▸ Initial release▸ Board
DOC-017 Training and Awareness Programme | v1.0 | NIS2/ISMS