Security & AI training · NIS2 and the EU AI Act
The training your team will actually finish.
National laws implementing the NIS2 Directive made security training a legal duty for the organisations in their scope, and the EU AI Act added AI literacy on top of it. Cyberact covers both in two minutes a day, in a format people don't resent, with every lesson mapped to the clause it evidences.
- 249
- lessons live
- 8
- frameworks mapped
- 2 min
- per lesson
Founding customers
Your logo here.
We are new, and our first customers help decide what we build next. With your permission, your logo goes up in this spot.
- Your logo
- Your logo
- Your logo
- Your logo
- Your logo
- Your logo
Cyberact in 36 seconds
Why training became the law, and what it looks like done well.
The problem
You're already paying for training nobody remembers.
Annual compliance modules get clicked through in eight minutes and forgotten by February. The certificate still prints. The risk doesn't move.
We measure what stuck
Everyone reports completion. We weight retention at 40% of the readiness score — because a course someone clicked through in eight minutes protects nobody.
The AI Act is already covered
Article 4 has applied since 2025, and in July 2026 it became a duty to take measures that support AI literacy, with no set level required. Most vendors bolted on a ChatGPT module. We built two whole paths — and the record that evidences them.
Built in the EU, under EU law
Cyberact is designed and built in Finland, with EU law as the starting point rather than something retrofitted afterwards. Digital sovereignty has become a procurement question across Europe — and when your training record is the legal evidence, whose jurisdiction holds it is not a detail. Ours stays in the EU, hosted in Germany.
Does this apply to you
Three questions, and you know which class you are in.
NIS2 does not ask whether you would like to be in scope. Under the Directive it falls out of your sector and your size, and you already know both. Your country's NIS2 law applies the same test and may add to it. Nothing here is stored and no email is asked for.
Staff
Turnover
Choose a sector.
Self-test
A supervisor does not start with your firewall. They start with these three.
Article 20 puts the duty on the management body. When the authority arrives, the opening questions are not technical — they come out of the board papers. Answer honestly; nobody can see this.
01Show me where the management body approved the risk-management measures, and when.
NIS2 Article 20(1), as your country's NIS2 law transposes it. Not that the measures exist — that the management body approved them, dated and minuted.
02Show me how the management body has overseen them since.
Meetings, decisions, and what changed as a result. Oversight that changed nothing is hard to tell apart from oversight that did not happen.
03Show me that the members of the management body have followed training.
Article 20(2) of the Directive requires members of the management body to follow training. National laws word it differently (Finland's, for example, asks management to be sufficiently familiar with cybersecurity risk management), but the training record is the easiest way to show it.
Compliance
One programme. Every box you already have to tick.
In the EU this stopped being a nice-to-have. NIS2 applies through the national law of every member state, the AI Act and the Cyber Resilience Act apply directly across the EU, and awareness training is also named in your ISO certificate, your SOC 2 report, your PCI scope and your insurance renewal. Cyberact maps each lesson to the specific clause it evidences.
| Framework | Clause | What it requires of you |
|---|---|---|
| NIS2 DirectiveArt. 20 / 21 | Art. 20 / 21 | Basic cyber hygiene and cybersecurity training are among an in-scope entity's risk-management measures (Art. 21(2)(g)). The management body approves and oversees them, and its members are required to follow training (Art. 20). Your country's NIS2 law sets out the detail. |
| SOC 2CC1.4 / CC2.2 | CC1.4 / CC2.2 | Show staff are competent for their control responsibilities, with evidence. |
| ISO 27001Annex A 6.3 | Annex A 6.3 | Awareness, education and training: an Annex A control you apply through your Statement of Applicability. |
| GDPRArt. 32 / 39 | Art. 32 / 39 | Staff awareness can be part of the organisational security measures Article 32 asks for, and awareness-raising and training of staff are a task of the DPO, where you have one (Art. 39). |
| EU AI ActArt. 4 | Art. 4 | Take measures to support AI literacy for anyone using AI on your behalf. Article 4 carries no fine of its own; national supervision applies from August 2026, on terms each country sets. The training record is the whole artefact — Article 4 leaves nothing else behind. |
| CRAArt. 14 | Art. 14 | If you make software and market it under your own name, an actively exploited flaw gets an early warning within 24 hours — since September 2026. The Act asks for no training; the deadline depends on whoever hears first knowing what starts the clock. |
| PCI DSS12.6 | 12.6 | An awareness programme, at least annually, with proof of participation. |
| Cyber insuranceRenewal | Renewal | Asked on every underwriter questionnaire. Affects your premium. |
Evidence pack
One-click CSV: every person, every control, coverage and score, dated. That's what the auditor asks for.
Retention-adjusted risk
A single number blending completion, quiz quality and what people still remember weeks later.
Board report
A print-ready report for the board and the auditor, with an AI-written summary.
AI leverage
Compliance is the floor. What your team does next is the upside.
Article 4 makes supporting AI literacy something you have to do. Worth More is the path your team opens anyway, because it is the one that pays them back — 41 lessons on where their hours actually go, how to get output they'd send without rewriting, and how a saved hour becomes capacity instead of a shorter afternoon.
- 41
- lessons in the path
- 8
- modules, from basics to business case
- Art. 4
- the obligation it evidences
Start with the week, not the tool
Most AI training teaches features. This starts by auditing where your people's hours actually go, then hands over only the work a model is genuinely good at — repetitive, low-stakes, and fast to check.
Output you'd send without rewriting
Context, one worked example, and constraints instead of adjectives. Habits that survive the next model, rather than prompt tricks that expire with it.
One person's trick becomes the process
A prompt that works is a written-down process. The path covers sharing it, standardising a house style, and keeping a human in exactly the places that need one.
Hours only count when you spend them
The last module is the business case: turning a saved hour into capacity, quality, or work you couldn't afford before — and putting a number on it the person holding the budget will accept.
How it works
Four steps, every day.
- 01
Pick a path
Six paths, from phishing and payment fraud to data protection, how AI actually works, how to get real work out of it, and what the law asks of management.
- 02
Listen for 2 minutes
A focused micro-lesson with a simple animation. It reads itself aloud, so people can just listen.
- 03
Prove it in a quiz
A few questions with real explanations. Miss one and it comes back tomorrow, not never.
- 04
Keep the streak
A daily quiz spaces the review out. That's what turns a session into a memory.
The curriculum
Six paths people open on purpose.
Written for the person doing the job, not the auditor reading the report — which is why people finish it. The security paths make you harder to fool. The AI paths teach what employers are hiring for right now: how these models actually work, and how to get real work out of them. Skills that follow you to the next job, not a certificate that expires.
Attack Surface
Every way in that runs through a person — and how to close it.
- Phishing & scams
- Passwords & accounts
- Using AI tools safely
- Devices & networks
- When the risk arrives from outside
- When something goes wrong
- Where the work actually lives
- When the rules apply to you
- Where the old advice runs out
- When your product is the risk
Follow the Money
The scams aimed at your inbox, your phone and your finance team.
- How the con starts
- Invoice and payment fraud
- Voice, video and text
- Scams that walk into the office
- The controls that actually hold
- The first hour after
- Money that doesn't come back
Need to Know
Who can see what, why it matters, and what happens when data escapes.
- What actually counts as data
- Need to know, not nice to know
- Sharing without leaking
- Keeping it, then losing it properly
- People have rights over this
- When data escapes
- The ordinary moments
Inside the Machine
How AI actually works, where it breaks, and how not to get burned.
- How language models work
- Prompting well
- Giving a model your knowledge
- Agents and tools
- Judgement
- Shipping AI responsibly
- Feeding the model well
Worth More
The AI skills that keep you relevant — and turn up in your next pay review.
- Where the hours actually are
- Getting output you can send
- The everyday jobs
- From your habit to the team's
- Automating a process
- Turning hours into business
- Doing it safely
- The AI Act in practice
On the Hook
What the law asks of the people who approve the measures — and carry the liability.
- What the law asks of you personally
- The ten measures
- When the clock starts
- Supply chain and contracts
- AI risk tiers and the red lines
- AI in the workplace
- Evidence and supervision
- The law on what you sell
Engagement, honestly
Competition that doesn't become pressure.
Opt-in leaderboards: only the people in your own organisation who chose to join appear on them. No lives, no countdowns, no loot boxes, and a streak freeze so one missed day doesn't undo a month.
For managers
Know exactly where your risk is.
The Platform + manager console + audit plan adds the console: audit readiness per framework, a competency matrix by department, the roster, and an evidence export.
- Audit readiness across every mapped control
- Competency by department — see which team is the gap
- Retention-adjusted risk, trended over time
- Evidence pack and board summary, exportable
Huomiva Health · this week
▲ readinessAudit ready
54%
Risk score
27
Active
82%
Guides
What the law expects your people to know
Short guides to NIS2, the EU AI Act and the other duties behind security training.
Security awareness training for employees: what EU law requires
What NIS2, GDPR, the EU AI Act and ISO 27001 expect of staff security training, what the training should cover and how to keep a record an auditor accepts.
NIS2 training requirements: what the Directive asks of staff and management
What the NIS2 Directive (EU) 2022/2555 requires on cybersecurity training for staff and the management body, who is in scope in any EU country, and how to evidence it.
AI literacy under Article 4 of the EU AI Act
The Digital Omnibus rewrote Article 4 of the EU AI Act in July 2026. What supporting AI literacy now requires, who it covers in any EU country and how it is supervised.