Learn what the information security directive ECB CROE states about security awareness training.
Yes, the European Central Bank’s Cyber Resilience Oversight Expectations (CROE) requires financial market infrastructures to ensure comprehensive staff training on cybersecurity and resilience practices.
Under ECB CROE, organizations must implement a structured training program that covers topics such as cyber incident response, threat identification, and secure operational practices. Training should be role-specific and continuously updated to align with evolving cyber threats.
The European Central Bank provides official resources and guidance for organizations aiming to meet CROE requirements, including security awareness training. Financial institutions can also consult cybersecurity specialists for tailored programs.
Learn how Guardey's gamified security awareness training can help your organization with compliance.
Learn more