Security awareness training for employees: what EU law requires

What NIS2, GDPR, the EU AI Act and ISO 27001 expect of staff security training, what the training should cover and how to keep a record an auditor accepts.

Updated

In short

Security awareness training teaches every employee how attacks usually start and what to do differently: spot a phishing message, confirm a payment request through another channel, protect their accounts and report anything suspicious at once. Many breaches and frauds involve a person's action, such as a click, a reply or a payment, so training is a cost-effective way to reduce risk.

No single EU law prescribes one security course for every company. But NIS2 (Directive (EU) 2022/2555, applied through each member state's national law), the GDPR, Article 4 of the EU AI Act and the ISO/IEC 27001 standard all require training or make it a practical necessity. None of them sets a length or a frequency. NIS2 laws, the GDPR and ISO 27001 expect risk-based measures, and ISO 27001 requires documented evidence of competence (clause 7.2). A record of the training is the practical way to show any of them.

Which rules require staff training

The duties come from different sources, and one programme can meet several of them when its content and its records are designed for it.

  • NIS2: Article 21(2)(g) lists basic cyber hygiene practices and cybersecurity training among the risk-management measures, and Article 20(2) requires member states to make members of management bodies follow training. National laws word this differently: Finland's Cybersecurity Act 124/2025 lists cybersecurity training in section 9 and, in section 10, requires management to have adequate familiarity with cybersecurity risk management. Applies to essential and important entities under each country's transposing law.
  • GDPR (Regulation (EU) 2016/679): Article 32 requires appropriate technical and organisational measures, and Article 32(4) requires the controller and processor to take steps to ensure that anyone acting under their authority with access to personal data processes it only on the controller's instructions, unless the law requires otherwise. Where a data protection officer is appointed, monitoring compliance, including awareness-raising and training of staff involved in processing, is one of their tasks (Article 39(1)(b)). Article 32 applies to every organisation that processes personal data.
  • EU AI Act, Article 4: providers and deployers of AI systems must take measures to support the development of AI literacy among their staff (wording in force since 27 July 2026). Applies regardless of size to any organisation that uses AI systems under its authority (a deployer).
  • ISO/IEC 27001:2022: Annex A control 6.3 covers information security awareness, education and training, and clauses 7.2 and 7.3 require competence and awareness. Applies to certified organisations and those working towards certification, and many customers ask the same of their suppliers.

What the training should cover

The content follows from your own risk assessment, but the same topics recur in most organisations, because attacks come in by the same routes. Good training covers at least these:

  • Phishing and social engineering, including AI-written messages without spelling mistakes, device-code phishing and ClickFix
  • Invoice and payment fraud, changed bank details and CEO fraud
  • Passwords, password managers and multi-factor authentication
  • Handling personal and confidential data (GDPR)
  • Using AI tools safely and well: what may be pasted into a tool and how to check the output
  • Recognising and reporting an incident inside the organisation
  • Remote work, devices, networks and software updates
  • For management, also the risk-management framework, reporting duties and their own responsibility

Once a year, or a little at a time

A one-hour online course once a year is the most common model and the weakest. What is learnt fades quickly without review, and attack techniques change faster than the course does. NIS2 requires measures that take the state of the art into account (Article 21(1)), and some national laws, such as Finland's (section 9(2)), require them to be kept up to date.

A short, recurring model works better: lessons of a few minutes through the year, and review that brings a point back just before it is forgotten. New starters are trained during onboarding, and new threats are covered when they appear. Phishing simulations complement training but do not replace it: they measure one risk.

How to evidence the training

An auditor and a supervisory authority ask the same questions: who has been trained, when, against which risks, and how you know it works. Buying a course is not evidence on its own.

  • A training plan: who, what and how often, and how it ties to the risk assessment
  • Dated, per-person completion records
  • Evidence of competence, not just attendance, such as quiz results
  • Management's own training, by name (NIS2 Article 20(2), or your national equivalent)
  • Which duties and controls each topic serves: NIS2, GDPR, the AI Act, ISO 27001
  • A change history: when the content changed and why

How to choose a training service

Compare services with these questions before asking for a quote:

  • Is the content written against EU law and your country's law, or generic?
  • Does it cover AI both as a risk and as a tool?
  • Is there a report you can hand to an auditor as it is, with management named?
  • Does it measure competence, or only that a video was watched?
  • Is it priced per seat, and what does adding a new starter cost?
  • Where is your staff's data stored?

How Cyberact helps

Cyberact is security and AI literacy training for organisations, built in Finland. A lesson takes about two minutes, a daily quiz spaces the review out, and each lesson is mapped to the NIS2, AI Act, GDPR and ISO 27001 clauses it supports. The manager console shows who is competent and who is behind, and produces the audit evidence. The price is flat per organisation with unlimited users, data is stored in the EU, and the service is in English and Finnish. Prices are on the pricing page, and a free account gets you started at once.

Sources

Legislation checked against primary sources on 4 October 2026.

  • Finland's Cybersecurity Act 124/2025, Finlex: https://www.finlex.fi/fi/lainsaadanto/2025/124
  • NIS2 Directive (EU) 2022/2555, EUR-Lex: https://eur-lex.europa.eu/eli/dir/2022/2555/oj
  • General Data Protection Regulation (EU) 2016/679, EUR-Lex: https://eur-lex.europa.eu/eli/reg/2016/679/oj
  • EU AI Act (EU) 2024/1689, EUR-Lex: https://eur-lex.europa.eu/eli/reg/2024/1689/oj
  • Digital Omnibus on AI (EU) 2026/1744, EUR-Lex
  • ISO/IEC 27001:2022, Annex A, control 6.3

Frequently asked questions

Is security awareness training mandatory for employees in the EU?
Not under one law for every company, but often in practice. NIS2 lists cybersecurity training among the risk-management measures of essential and important entities (Article 21(2)(g)), the GDPR requires organisational measures to protect personal data, and an organisation whose staff use AI must support their AI literacy (EU AI Act Article 4).
How often should security awareness training be done?
No law sets a frequency. NIS2 asks for measures that reflect the state of the art, and some national laws require them to be kept up to date. Continuous training in short lessons, with spaced review, keeps knowledge fresher than a course once a year.
What should security awareness training include?
Whatever your risk assessment points to. The usual topics are phishing and social engineering, invoice fraud, passwords and multi-factor authentication, handling personal data, using AI tools safely and reporting incidents.
How do you prove security training to an auditor?
With dated, per-person completion records, evidence of competence such as quiz results, a training plan tied to the risk assessment, and management's own training recorded by name.
Is a phishing simulation enough?
Not on its own. A simulation measures one risk; training also needs to cover fraud, data protection, AI use and incident reporting.

Read next

Training your team will actually finish

Cyberact teaches security and practical AI in two minutes a day, and keeps a record of what each person knows.