Security awareness training
Continuous security awareness training with three-minute challenges, phishing simulations, and audit-ready reporting. Helps meet the employee awareness requirements of Article 21.
NIS2 introduces new requirements for security awareness, executive accountability, and incident reporting. Guardey helps your organization prepare for Articles 20 and 21 with continuous training for employees and leadership.
Continuous security awareness training with three-minute challenges, phishing simulations, and audit-ready reporting. Helps meet the employee awareness requirements of Article 21.
Short modules on what Article 20 requires of the management body, with a certificate you can use as evidence of director training.
Guardey is built and hosted entirely within the EU, so your training data stays under European jurisdiction. No transfers outside the EU, giving you clarity around data residency and GDPR.
Three-minute challenges keep employees coming back instead of dreading another mandatory course. Streaks, levels, and rewards turn security awareness into a lasting habit.
Track completion, scores, and progress across your organization with audit-ready reporting that helps demonstrate your NIS2 awareness efforts.
Answer 4 quick questions and find out in just 2 minutes.
Get your free 15-page guide covering everything you need to know about NIS2. Learn who needs to comply, understand the key requirements, follow a practical compliance checklist, and discover how to prepare your organization for NIS2.
NIS2 covers essential and important entities across 18 sectors, including energy, transport, healthcare, banking, digital infrastructure and manufacturing. Size thresholds apply: generally 50+ staff or €10 million or more in turnover, though some sectors are covered regardless of size. The test tells you which category you fall into.
Both must meet the same security obligations. The difference is supervision: essential entities face proactive supervision and audits, important entities are supervised reactively after an incident. Fines differ too, up to €10 million or 2% of turnover for essential, up to €7 million or 1.4% for important.
Yes. Article 21 lists basic cyber hygiene practices and cybersecurity training among the minimum measures organisations must take. You need to be able to evidence it, which is where reporting matters.
Article 20 requires management bodies to approve the cybersecurity risk-management measures, oversee their implementation, and follow training themselves. Member states can hold leadership personally accountable for failures.
An early warning within 24 hours of becoming aware of a significant incident, an incident notification within 72 hours, and a final report within one month.