Cybersecurity Training and Awareness Programme
Training plan, phishing awareness, register and Board requirements
1. Board Training Requirement (NIS2 Art. 21(1))
⚠ Critical – Board MUST attend training (NIS2 requirement)
In accordance with Art. 21(1) NIS2, the management body must attend cybersecurity training to acquire the knowledge and skills sufficient to identify risks and evaluate cybersecurity risk management practices.
| Participant | Required frequency | Format | Date of last training |
|---|---|---|---|
| ▸ CEO / President | ▸ min. once a yearmin. 1×/year – NIS2 | ▸ [e.g. 4h workshop / e-learning] | ▸ DD/MM/YYYY |
| ▸ [Other Board members] | ▸ min. once a yearmin. 1×/year | ▸ | ▸ |
2. Annual Training Plan
| Training | Target group | Frequency | Duration | Format | Deadline |
|---|---|---|---|---|---|
| Security induction training | New employees | ▸ On hiringmax. 14 days from hiring | ▸ [min. 2h]min. 1h | ▸ [e-learning / live training] | During onboarding |
| Recurring general training | All employees | ▸ once a yearmin. 1×/year – NIS2 | ▸ [min. 2h]min. 1h | ▸ [e.g. e-learning / webinar / workshop] | ▸ [e.g. Q1 every year] |
| Board training | Board / Senior Management | ▸ once a yearmin. 1×/year – NIS2 Art.21.1 | ▸ [min. 4h]min. 2h | ▸ [e.g. expert workshop] | ▸ |
| Technical training (IT) | Administrators, IT department | ▸ once a yearmin. 1×/year | ▸ [min. 8h]min. 4h | ▸ [conference / course / certification] | ▸ |
| Phishing simulation | All employees | ▸ 2–4 times a yearmin. 2×/year | N/A (campaign) | Simulated phishing | ▸ [e.g. quarterly] |
| Post-incident training | Those affected by incident | After every major incident | ▸ [depending on incident] | ▸ [debrief session + training] | Within 30 days of incident |
3. Training Content
Induction and recurring training (minimum):
- Information Security Policy – basic principles (DOC-001),
- Recognising phishing, smishing and vishing,
- Secure passwords and use of MFA,
- Information classification and data handling (DOC-010),
- Incident reporting – how and when (DOC-005/006),
- Secure remote work and BYOD,
- Social engineering – recognising manipulation,
- Clean desk / screen policy.
Board training (minimum):
- Cybersecurity threat landscape in the sector,
- NIS2 requirements and Board accountability,
- Cybersecurity risk management – concepts,
- Sector incident case studies,
- Decision-making exercise (tabletop).
4. Phishing Simulations
Requirement – minimum 2 phishing simulations per year
Campaigns sent via: ▸ [e.g. KnowBe4 / Proofpoint Security Awareness / GoPhish]
| Metric | Organisation's target | Action if exceeded |
|---|---|---|
| Click rate (% clicking link) | ▸ [e.g. below 5%]target <10% | Additional training for clickers, general communication |
| Report rate (% reporting phishing) | ▸ [e.g. above 70%]target >50% | Root cause analysis |
| Credential submission (% entering data) | ▸ [0%]target 0% | Immediate 1:1 training, password reset |
5. Training Register
CISO / HR maintains a central training participation register. Register contains: name, position, training type, date, result (pass/fail/N/A), signature or e-learning confirmation.
Retention: ▸ [min. 5 years]min. 5 years – NIS2.
Tool: ▸ [e.g. LMS (Moodle/KnowBe4) / HR register / Excel spreadsheet]
⚠ Confirmation of NIS2 Art. 21(2)(g) compliance – Board training
The organisation confirms that Board training was conducted in year: ▸ [year], date: ▸ DD/MM/YYYY, participants: ▸ [list of Board participants].
Change History
| Version | Date | Author | Description | Approved by |
|---|---|---|---|---|
| ▸ 1.0 | ▸ | ▸ | ▸ Initial release | ▸ Board |
DOC-017 Training and Awareness Programme | v1.0 | NIS2/ISMS