🚨  NIS2 is now in effect. Security awareness is now legally required in the EU.

Check compliance
Log in
Back to Resource Center

The ultimate security awareness training guide for 2026

About NIS2

Security awareness training is structured training that teaches employees to recognize, avoid and report the cyber threats they run into at work. For years it was something sensible organizations did. In 2026 it became something a lot of them are legally required to do.

NIS2, the European cybersecurity directive now written into national law across most of the Union, names cybersecurity training among the risk-management measures organizations have to put in place, and it holds management bodies personally accountable for them. The EU AI Act reaches further still: since February 2025 it has required AI literacy from every organization whose staff use AI at work, with no size threshold at all.

This guide covers what security awareness training is and what it is not, why 2026 and 2027 changed the stakes for large and small organizations alike, the four common training formats and where each one breaks down, and how five Dutch organizations run their programs today.

Looking for the platform rather than the theory? See Guardey’s security awareness training.

What is security awareness training?

Security awareness training is structured training that teaches employees to recognize, avoid and report cyber threats they encounter at work or at home. A good program covers phishing, social engineering, malware, password hygiene, safe data handling and physical security, and it is judged on changed behavior rather than on completed modules.

The shorter term, security awareness, describes the result: the level of alertness people in an organization have about digital risk. Training is how you build it. Measurement is how you prove you have it, which since 2026 matters as much as the training itself.

A program can be tied to a specific framework such as ISO 27001, NIS2 or a sector standard, or it can be general. It can run as a single annual session or as short exercises spread across the year. As the rest of this guide shows, that one choice does more to determine whether the training works than the content inside it.

Curious what this looks like in practice?

Guardey turns everything below into weekly 3-minute challenges, realistic phishing simulations and a report that shows an auditor exactly who is trained.

Discover Guardey Security Awareness Training

Why is security awareness training so important?

In its 2026 Data Breach Investigations Report, Verizon found the human element involved in 62% of all breaches, up from 60% a year earlier, with social engineering alone accounting for 16%. Clicking a convincing link, reusing a password across accounts, approving one MFA prompt too many: employees are not a weak link by nature, but they are the link attackers aim at, because it is the one that answers back. That is why teaching people to recognize and report threats is worth as much as any tool you buy.

The importance of security awareness training has been a hot topic for years now. Not every security professional views it as necessary, as they believe human error can’t be ruled out. They believe in technological measurements to ensure safety even when human errors occur.

At Guardey, we believe in a combination of both. While it’s true that training can’t guarantee safety, we understand that technology can’t either. There is no spam filter in the world that guarantees it will catch all phishing mails. For the one percent of phishing that makes it through your technology defenses, you want your employees to be aware of the dangers of phishing.

There are a lot of cyber threats that can’t be prevented by technology. Think of real-life social engineering, where a person enters the office and convinces the reception that he is a contractor that needs access to the servers. Situations like these can only be prevented when everybody within your organization has a high sense of security awareness.

Why security awareness training is mandatory in 2026 and 2027

Three pieces of European legislation have turned employee training from a recommendation into an obligation, and the deadlines that mattered have already passed. Here is what applies right now, and to whom.

NIS2 lists training as a security measure, not a suggestion

NIS2 replaced the original network and information security directive and had to be written into national law by 17 October 2024. Most member states missed that deadline, and by mid-2026 the European Commission had opened infringement procedures against 23 of them, but the national laws have been landing steadily since. The Commission estimates that roughly 160,000 organizations across 18 sectors fall in scope, from energy and drinking water to healthcare, government, transport and digital infrastructure.

Two articles do the work. Article 21(2)(g) lists basic cyber hygiene practices and cybersecurity training among the risk-management measures in-scope entities must have in place, which is what moves employee training from good practice to a control you have to be able to show. Article 20(2) is stricter at the top: members of management bodies are required to follow training themselves, so they can identify risks and judge whether the measures actually work. Security awareness stopped being something the board approves for other people. For that obligation specifically, see NIS2 training for executives.

Small organizations are pulled in through the supply chain

NIS2 has a size threshold. It applies to medium and large entities, broadly those with at least 50 staff or 10 million euro in turnover, so most small companies fall outside its scope on paper. That is not where the story ends.

Article 21(2)(d) requires in-scope organizations to manage security risk across their supply chain, including the practices of their direct suppliers and service providers. There is one practical way to do that, and it is to write requirements into contracts.

So a fifteen-person software company that sells to a hospital, an energy provider or a public body will be asked to show that its staff are trained, even though the directive never names it. The obligation does not arrive as a letter from a regulator. It arrives as a supplier questionnaire, a security annex in a renewal, or a procurement checklist with a box that has to be ticked before the contract is signed.

For a lot of smaller firms that changes the question entirely. Security awareness training is no longer weighed against the risk of an incident, which is easy to postpone. It is weighed against the risk of losing the largest customer on the books, which is not.

The AI Act made AI literacy mandatory for every organization

Article 4 of the EU AI Act has required AI literacy since 2 February 2025, and the bulk of the Act became applicable on 2 August 2026. This one has no size threshold and no sector list. Any organization whose staff use AI professionally, including those that only use tools like ChatGPT or Microsoft Copilot, has to make sure those employees understand the risks, the limitations and the appropriate use of what they are working with. Penalties under the Act run to 15 million euro or 3% of global annual turnover.

The practical effect is striking: a two-person agency pasting client data into a chatbot carries a training obligation that no NIS2 size threshold would ever have caught. It is currently the broadest employee training requirement on the European books. We cover it in our guide to AI literacy training.

What arrives in 2027

The Cyber Resilience Act completes the picture. Its vulnerability reporting obligations started on 11 September 2026, and its main obligations apply from 11 December 2027 to anyone who manufactures or sells products with digital elements. It carries its own duty of care through the supply chain and a support period of at least five years.

Read together, the direction is consistent enough to plan around. Regulators have stopped asking whether organizations bought security tooling and started asking whether the people using it know what to do, and whether that can be demonstrated on request. A training program that cannot produce evidence solves only half of the problem you now have.

An introduction to common cyber threats

Phishing, vishing, smishing, and quishing

Phishing is the use of email messages to attack a target. Phishing emails pretend to originate from someone the target would usually trust, like a client or colleague, or from a trustworthy entity such as a bank or online retailer. Sometimes the object of a phishing email is to trick the recipient into downloading malware. More generally, though, the aim is to obtain sensitive information, such as the target’s login credentials for an online banking service, or personally identifying information like their social security number.

A graph showing the growth of phishing attacks throughout the years.

Vishing is a similar attack using voice and video calls, while smishing uses SMS and text messaging. Spear phishing means an attack aimed at a specific individual, like a C-suite executive or someone with IT access. In these cases, the hacker often uses social engineering to make the target feel like the message is authentic. Quishing refers to the use of QR codes that trick targets into visiting malicious websites or transferring money directly to criminals.

Malware

Malware is malicious software that is spread by cybercriminals. It can infect individual computers and other devices, or entire networks. There are many different kinds of malware. Here are some examples:

Viruses

Viruses are self-replicating programs designed to cause damage to a system, deleting data or introducing further vulnerabilities that can be exploited.

Trojan horses

Trojan horses are programs that are disguised as legitimate software but cause damage to a system. Trojan horses often hide undetected on computer systems for an extended period, stealing information and sending it to cyber criminals. A common type of trojan horse is a keylogger. This records all the keystrokes entered into an infected computer, potentially revealing passwords and other sensitive information. This can then be used for further crimes, such as data theft and identity theft.

Ransomware

Another common type of malware is ransomware. Ransomware is malware designed to obtain a ransom from the victim. Typically, ransomware will encrypt all the files on a computer system or network, then solicit a ransom from the victim in exchange for the means to decrypt them.

The ransoms demanded are often very high, sometimes much more than the victim can ever pay. Even if the ransom is paid, there’s no guarantee that the attacker will provide decryption keys. In many cases, the encrypted files are lost for good. In recent years ransomware has shut down hospital departments, halted production lines and closed schools across Europe, often entering through a single employee who opened the wrong attachment.

Ransomware is on the rise internationally, with the size of ransom payments increasing.

Ransom payments by quarter

Malicious websites

Malicious websites, also known as attack sites, are websites that host malicious code with the intent of tricking users into downloading it onto their devices. In some cases, attack sites are set up for this specific purpose. In others, a legitimate site is hijacked by cybercriminals who then insert malicious code into it. Some sites, called drive-by attack sites, don’t even require the victim to click a download link or interact in any way — just visiting the site is enough to infect a system that’s improperly secured.

Malicious websites may also imitate trusted websites in order to trick users into entering their login credentials, allowing criminals to gain access to victims’ accounts.

USB attacks

Removable media such as USB drives can easily be used as a vector for malicious code. In some cases, a criminal might gain physical access to an organization’s devices; more usually, attackers will leave infected USB sticks where unwitting staff members can find them.

It is trivial for an attacker to acquire a USB drive adorned with the logo of the target organization, or another trusted entity such as a client or regular supplier, and leave it near the premises where it will be picked up. They’re relying on curious or helpful staff members to plug the USB drive into one of the computers on an organization’s network to check its contents. Once connected, the infected drive can deposit its payload of malware.

Note that any device capable of storing data can be used for this kind of attack, including MP3 players, digital cameras and smartphones. One recent example is Sogu, a USB-assisted cyber-espionage campaign that targets multiple industries.

All of these attacks can be devastating for an organization. You can minimize the odds of being hit by an attack like this with proper security awareness training for employees and business owners. When an organization’s personnel are aware of the risks and how to avoid them, they go from being a point of failure to a human firewall.

And the list goes on

The above mentioned cyber threats are some of the most prevalent, but cybercriminals have a lot of methods to steal valuable data. As time progresses, their methods improve and are harder to notice for the untrained eye. Especially with AI on the rise, the different types of cyber threats seem limitless.

The different types of security awareness training

There are multiple ways to train your employees. Below, we’ll go through some of the most-used.

Yearly courses

Many organizations still rely on annual training courses to prepare their staff to deal with cyber threats. Yearly security awareness training for employees has two main problems. Firstly, the digital threat landscape is constantly changing. New threats arise all the time, not just once a year, so annual training rapidly becomes outdated.

A visualization of the forgetting curve

Secondly, people simply don’t retain information for a full year. Even the most attentive learner won’t remember everything they’ve learned for more than a few months. This knowledge decay means that staff’s knowledge will inevitably become less comprehensive over time, making them less effective at avoiding risks.

In-class training

In-class training does have some advantages over other teaching methods. It creates a distraction-free environment where learners can focus on the specific topics that they need to understand and internalize. In-class training does have significant downsides, however. Learners need to be pulled away from other activities, meaning that they either fall behind on work tasks or give up their free time.

In-class training

In-class training also enforces a one-size-fits-all model onto students, with some learners feeling bored or unchallenged and others left confused by new topics.

Traditional e-learning

Traditional e-learning attempts to replicate in-class learning in a remote environment. Classes are delivered over a platform like Canvas or Moodle, using slides and other media. There are usually lectures, either pre-recorded or delivered live by an instructor. While traditional e-learning is more flexible and scalable than in-class learning, it has some of the same drawbacks. Learning tends to be passive, with limited interactivity and sub-par engagement or retention.

Gamified training

Gamified security awareness training offered by providers like Guardey is a modern solution. It’s similar to the approach taken by language learning apps like Duolingo. Instead of being presented with a great deal of information once a year, or as discrete classes with limited interaction, learners receive a steady flow of short, easily digestible trainings.

Example of a Guardey phishing awareness challenge

With Guardey, users get a weekly challenge that takes them about 3 minutes to complete. During a challenge, they learn about cyber threats such as phishing, malware, weak passwords, and AI. By performing well during challenges, they can score points for the organization’s leaderboard. Friendly competition among colleagues has proven to keep users engaged.

By gamifying the learning experience, users get intrinsically motivated to keep showing up. Whether that’s to get to the top spot of the leaderboard, continue their hot streaks of consecutive weeks played, or simply to improve their own high score.

How to get your organization on board with security awareness training

You’ve decided that gamified learning is the ideal solution for your organization’s security training needs. You’ve found some great products that fit all of your requirements. Now comes the tough part: persuading your organization to adopt a new training solution.

People may be reluctant to take the plunge into gamified security training for several reasons. You’ll need to answer a lot of questions. What is security awareness? How does it benefit the organization? People who’ve already endured a yearly cybersecurity class might feel that they don’t have anything to gain from ongoing training. Managers and executives may believe that their staff are too sharp to be taken in by a phishing email or a mysterious flash drive in the parking lot. Here are some ideas that can help persuade people and get them on board.

Organize a security awareness week: a fun and engaging security awareness event can help get people excited about cybersecurity and eager to know more.

Conduct a spear phishing simulation: A realistic spear phishing simulation that targets key individuals can help to demonstrate that anyone in your organization might be vulnerable.

Recruit a guest speaker: An expert speaker can help bring people around to your point of view more effectively than abstract information. This could be a victim of cybercrime, a security expert, or even an ethical “white hat” hacker.

How Dutch organizations are training security awareness

Here are some examples of Dutch organizations who have successfully implemented security awareness training for their employees.

EyeOn

The team at Eyeon

EyeOn is a forecasting and planning specialist, helping international companies to manage supply chain challenges. EyeOn is responsible for a great deal of their client companies’ data, which needs to be handled securely. They adopted a gamified cybersecurity training solution to make sure that their staff were up to the challenge and to align their security with ISO27001 certification requirements.

They introduced the new training program among employees with what they called a security awareness week. “We started every day with an interview of 15 minutes and called that the safety catch-up. Every day had a specific theme. The first one was called ‘from desk to destination’. This was all about security measures during traveling, such as using a safety screen, storing your laptop safely, and so on. Another theme was all about confidential data, which is what we called ‘how to not get in trouble with the SEC.”

Priore

Priore's office building

Priore offers accountancy and tax advisory services. With the responsibility for clients’ sensitive financial information, cybersecurity is vital to them. Priore wanted to maintain a high level of security awareness among its staff at all times. That’s why they switched from a yearly cybersecurity course to a solution that delivered ongoing learning: Guardey.

“80% of the organization immediately started actively engaging after the first introductory email. After a month or two, everybody apart from 1 or 2 people was using Guardey every week. This was all due to intrinsic motivation and understanding the importance of security awareness. There are no incentives like a monthly prize or anything, so we can still try that if participation happens to slow down.”

Konot

KONOT

KONOT is an educational foundation, providing education through 22 Dutch primary schools. The organization needed a security awareness training solution that would align them with GDPR. Having already been the target of multiple failed cyberattacks, KONOT needed a training product that would keep its staff informed and aware at all times. They adopted Guardey to offer ongoing training and evaluation to ensure consistent security awareness.

KONOT has recently rolled out Guardey, and the first feedback is now coming in from the users. “The first feedback that we have received is enthusiastic. Guardey made them real competitive, which is a good sign,” says Martijn. “It’s very accessible, which I appreciate. A small few were less excited about the concept of training awareness before we started, but we will evaluate with them soon.” Frieda continues: “I’m not a gamer at all, but I also noticed I kept taking on new challenges. It’s really easy to get through the questions.”

Delta Wines

Delta Wines is a wine wholesaler. When their insurance provider emphasized the importance of security awareness training and the forthcoming NIS2 directive, Delta Wines’ CEO took action. To get everyone on board, a phishing simulation was conducted that provided a valuable wake-up call to many people. After many staff were taken in by the convincing email, they were very receptive to additional training.

“We’re getting a lot of positive feedback. A lot of employees immediately start playing the new weekly challenge once they receive the email that it’s ready. Some of them are seriously disappointed when they get a question wrong. It has started multiple internal discussions about security, which is great.”

Gezamenlijke Brandweer Amsterdam

Gezamenlijke Brandweer Amsterdam (United Fire Department Amsterdam) is a major fire department, tasked with incident response in an industrial area of Amsterdam. If a fire department falls victim to a cyberattack, the results could be catastrophic. The department also needed to comply with NIS2 requirements. Team lead Raymond Pikee wanted a recurring training solution that would be fun and engaging.

In the leaderboard, the firefighters can see how well they are doing compared to colleagues, which boosts the internal competition. “We’re a competitive bunch, so that’s a nice touch. These gamification elements make it fun to play Guardey, which also helps us to remember the information.”

How to start implementing security awareness training

Now that you know what security awareness training is and why it stopped being optional, the question is what to look for in a program. Three things separate the ones that work from the ones that merely get completed.

It has to be continuous, because knowledge decays in months rather than years and the threat landscape does not wait for your annual session. It has to be short enough that people actually finish it, since a program with an 80% completion rate protects 80% of your organization. And it has to measure and record participation, because since 2026 you will be asked to prove what you did, not just describe it.

If you have no idea where your organization stands today, start by measuring rather than buying. A security awareness baseline measurement shows you which teams are actually at risk, and it turns training from a cost into something you can show a result for.

At Guardey, we offer gamified security awareness training that is focused on keeping users engaged throughout long time periods. By using a leaderboard, achievements, hot streaks, and other gamification elements, users get a sense of friendly competition which boosts participation.

Start a 14-day free trial

Try out Guardey's gamified security awareness training platform for free.

Start free trial
Dinela Lokvancic
Dinela Lokvancic Marketing Specialist Dinela keeps Guardey's online presence up to date. She creates content that makes complex cyber security topics accessible, and helps organizations understand why security awareness training matters for their teams.
READY TO GET STARTED?

Join 500+ businesses already protecting their teams with Guardey

Start your free 14-day trial
14 days free · No credit card · Full access · Setup in 5 minutes
Or schedule a personalised demo