← Guide

Is security training mandatory for staff and directors?

Measure (g) of the NIS2 duty of care is about cyber hygiene and training. The practical answer: yearly awareness training for all staff with an attendance list, occasional phishing tests, clear written rules on passwords and working from home, and training for the board itself. That last one is not a recommendation but an explicit obligation in the law: directors must demonstrably understand cyber risks.

The most expensive security technology loses to one convincing fake email. Most incidents start with an employee clicking something, which is why training is a separate topic in the law.

What counts as awareness training?

A yearly moment where all staff learn what to look out for: recognising phishing, passwords and password managers, what to do about a suspicious message. The form is up to you; an online module, a lunch session or an external trainer all count.

Two details make it demonstrable. Everyone takes part, so including the people without a computer on their desk and the temporary staff. And there is an attendance list, because that list is the evidence a customer audit wants to see.

Do phishing tests really work?

Practising demonstrably works better than giving a presentation. Sending a test email once or twice a year and discussing the results keeps the subject alive, and the trend over the years (fewer clicks, more reports) is a strong story towards customers.

The tone matters: the goal is that people dare to report suspicious mail, not that whoever clicks is put in the stocks. Punish reporting and you train people to stay quiet.

Which rules have to be on paper?

A short acceptable-use policy: how we handle passwords, working from home, personal use of company devices and business use of personal devices. Written down, signed by staff and repeated yearly. The point is not that the rules are strict, but that they are known and do not exist only in the IT person's head.

Does the board have to be trained too?

Yes, and this is the least known part of the law: for organisations that fall under it directly, director training is an explicit obligation. Directors have to be able to assess the risks for which they are personally liable. Customers carry that question over into their questionnaires, so keep proof of attendance.

How often does training have to be repeated?

Yearly for everyone, and on top of that when someone joins. The second is forgotten most often: someone starting in March when the training was in November goes eight months without. A short introduction in the first week, with a signature under the acceptable use rules, solves that and is the piece of evidence at the same time.

What has the most effect in between is not more training but shorter and more frequent reminders. One paragraph per quarter about a current example, preferably one from your own industry, keeps the subject alive without anyone having to free up an agenda for it.

How do I show the training works?

With attendance and with an outcome. Attendance shows it happened; the outcome shows it did something. Usable numbers are the percentage of staff who clicked a test mail, the percentage who reported it, and the time to the first report. That last one is the most interesting, because it says something about your incident procedure.

Put this year's numbers next to last year's and you have exactly what testing effectiveness asks for: not a snapshot but a line.

How do I do this with a small team?

Without a learning platform and without a budget, and that is fine. For a team of up to fifteen people this works: one hour-long session a year in which you go through three real examples together, preferably mails your own company received. Reading the mail out and letting the others say what is wrong with it achieves more than a module of forty slides.

Record three things alongside it: the date, who was there, and which three points were covered. That fits on half a page and is exactly the evidence a customer audit asks for. If you would rather use something off the shelf, the free awareness materials from the Dutch Digital Trust Center and the National Cyber Security Centre are more than enough for this purpose, and the fact that you did not make them yourself counts against you nowhere.

Have a look at the other nine measures as well.

Getting started yourself

Take the free scan: 39 questions in plain language, about ten minutes, no account needed. You will know where you stand and what deserves attention first, and you can share the result with your customer as a passport.

Already have a questionnaire on your desk? With Pro (€39 per month, excl. VAT) you upload it and have the answers filled in from your own scan and evidence. You review it and send it back.

Updated on 5 August 2026