Skip to content
atlas

Security awareness

Also known as: cyber awareness, security awareness training

What staff know about security and how they act on it in daily work.

Draft - this entry has not been reviewed yet.

Formal

The level of understanding employees have of the threats facing the organisation, combined with the habits they show in response - built and kept up through planned training, campaigns and follow-up.

In plain English

Like teaching everyone in a building where the fire exits are and why the fire doors must stay shut - knowing is only half of it; doing it every day is the point.

In practice

A school gives security ten minutes at every staff meeting - this month, how to spot a fake MitID login page - and teachers now forward doubtful mails to IT instead of just deleting them.

Why it matters

Many attacks aim at people rather than machines, and NIS2 lists training among its minimum requirements, so awareness is both a defence and a legal duty.

How to put it into practice

The usual steps, in order. Adapt them to your organisation.

  1. Get management to name an owner for the awareness programme and set aside budget and staff time, remembering that NIS2 also requires the management body itself to be trained.
  2. Use the risk assessment and recent incidents to pick three to five target behaviours for the year, such as reporting suspicious mails, locking screens and handling personal data safely.
  3. For each target group, map the gap between today's behaviour and the desired behaviour, including the practical barriers that make the secure choice hard.
  4. Write an annual plan that combines onboarding for new starters, short recurring activities (staff meetings, newsletters, e-learning) and role-based training for admins, developers and managers.
  5. Make the secure behaviour easy with a report-phishing button, a clear contact point and technical controls such as MFA that do not depend on people noticing anything.
  6. Test campaigns and materials on a few users before rollout, then spread the activities across the year instead of one annual push.
  7. Set measurable goals up front and measure behaviour rather than completions, such as reporting rate, time to report and repeat incidents.
  8. Report results to management at least once a year and adjust topics, target groups and methods for the next cycle.

Common pitfalls

  • Treating the annual e-learning module as the whole programme and counting completion rates as success.
  • Blaming or shaming people who make mistakes, so they stop reporting.
  • Running one programme for everyone and forgetting managers, administrators and new starters.
  • Expecting awareness to replace technical controls instead of backing them up.

Good guides

Technical deep dive

NIST's older guidance, SP 800-16 (1998) and SP 800-50 (2003), both superseded by SP 800-50 Rev. 1 in September 2024, framed learning as a continuum: awareness focuses attention on security and aims at recognition, training builds specific skills for a role, and education integrates skills into a professional body of knowledge. The distinction still matters. Awareness is a population-wide state - can staff recognise a threat and do they know what to do next - whereas training is role-bound, such as secure coding for developers or privileged-access hygiene for administrators. Treating the annual all-staff module as if it were training is a common category error.

The normative requirements are concrete. ISO/IEC 27001:2022 clause 7.3 requires that people working under the organisation's control are aware of the information security policy, their contribution to the effectiveness of the ISMS including the benefits of improved performance, and the implications of not conforming. Annex A control 6.3, elaborated in ISO/IEC 27002:2022, expects an awareness, education and training programme aligned with policies and topic-specific procedures, updated regularly and covering both new starters and existing staff. NIS2 Art. 21(2)(g) lists basic cyber hygiene practices and cybersecurity training among the minimum risk-management measures, Art. 20(2) requires training for members of management bodies, and DORA Art. 13(6) makes awareness compulsory in financial entities.

Measurement is the difficult part. The traditional knowledge-attitude-behaviour model assumes that knowledge produces the right attitude, which produces the right behaviour, but the knowing-doing gap is well documented: people who can pass a quiz still click under time pressure. Validated instruments such as the Human Aspects of Information Security Questionnaire (HAIS-Q) measure knowledge, attitude and self-reported behaviour separately, while observed behaviour - reporting rates in real and simulated incidents, time-to-report, policy exceptions, data-handling errors - is the stronger evidence. Large field studies (IEEE S&P 2022 and 2025) found that annual training and embedded post-click lessons had little measurable effect on phishing susceptibility, which is a reason to measure outcomes rather than completions.

Awareness is individual and cognitive; security culture is the collective set of norms that decides whether that knowledge is applied when it is inconvenient. Awareness is necessary but not sufficient: it works best when paired with nudges at the point of decision and with technical controls, such as phishing-resistant MFA, that do not depend on a person noticing anything at all.

What to learn first

Everything this builds on, foundations first.

  1. Threat
  2. →Security awareness

Relationships

Requires
Threat
Don't confuse with
Security culture

Sources & further reading

Standards & official texts

Course material

  • Cyber Security Fast Track - Ordliste

Where this data comes from

This entry was drafted by an AI from the sources above and has not yet been checked by a person. Treat it as a starting point, and check anything important against the sources.

See the review queueSuggest a correction on GitHubThis term as JSON

Check yourself

Loading…

Atlas is in beta.