Training and workshops
Training is part of the fourth measure, and several other sub-measures require it too. We keep it concrete and tied to your work.
Training is a measure, not good practice
Several sub-measures of Annex II require training expressly, and all of them require a record that it happened.
Sub-measure 4.4 requires regular cyber hygiene training and awareness raising for all employees, and sub-measure 4.3 documented training for those with security duties. Both are binding from the basic level. Sub-measure 11.3 requires training in recognising and reporting suspicious events, also from the basic level.
The management body is not exempt. Sub-measure 1.9 requires awareness raising for those responsible for implementing the measures, through workshops, seminars and training, and is binding from the medium level upwards. Sub-measure 1.2 requires all employees and relevant third parties to be made aware of the security policy.
From the medium level onwards come incident response training for key personnel, sub-measure 4.9, and an annual simulated incident exercise, sub-measure 11.5. Social engineering testing, sub-measure 4.11, stays voluntary at every level, but carrying it out is additionally credited.
All of which means one thing: training that leaves no attendance list, no programme and no date does not exist in front of an auditor. Every programme of ours therefore carries those three things, whatever its length.
Programmes and duration by audience
Examples, scenarios and system names come from your own sector.
Sub-measure 4.11 is voluntary at every level, but carrying it out is additionally credited in self-assessment and audit. Which sub-measure binds you at which level is set out on the thirteen measures page.
How we work
Five steps from tailoring the programme to a record that goes into the evidence set.
Tailoring the programme to your sector
Before the workshop we ask which systems you use, what your processes look like and what has already happened. The scenarios and examples come from there, because generic examples do not stick.
Delivery, in person or remote
We do both, but for the management body and for exercises we recommend in person. The discussion that brings the most value rarely happens remotely.
Knowledge check and measurement
A short check at the end, not for a grade but for a record of effect and to see what did not land. With simulated deception, the response rate is measured before and after.
A record that goes into the evidence set
An attendance list with signatures or electronic confirmation, the programme, the date and the duration. Alongside it a short note on which sub-measure it covers, so nobody has to look for it later.
A repetition plan
At least once a year for everyone, with a short refresher on joining and on changing role. More often for higher-risk roles such as finance and IT. The plan goes into the obligations calendar so it does not depend on anyone remembering.
Frequently asked questions
The questions we are asked most often before we start.
Is training mandatory?
It is. Employee training and education are part of the fourth measure, human resources security and digital identities, and are binding from the basic level. Awareness raising for responsible persons is required by the first measure, so the management body is covered too, not just employees.How do we prove it took place?
With an attendance list, the programme and the date. Without those, the measure does not exist in front of an auditor, however many sessions you held. That is why we attach a note to each record stating which sub-measure it covers.How often does it need repeating?
At least once a year, with a short refresher on joining and on changing role. More often for higher-risk roles such as finance and IT. The annual simulation exercise is a separate obligation from the medium level upwards.How long is a workshop?
One hour for the management body, two to four hours for the IT team, one to two hours for employees, and two to three hours for a simulation exercise. Beyond that, more time rarely adds value and attention drops.Do you deliver remotely?
We do, but for the management body and for exercises we recommend in person. The discussion that brings the most value rarely happens remotely.Do you tailor the programme to our sector?
That is exactly what we do. The examples, scenarios and system names come from your own field. A short questionnaire therefore always goes out before the workshop.Do you run simulated email deception?
We do, by agreement with the management body and under a clear rule that the results are not used for disciplinary action. Sub-measure 4.11 is voluntary at every level, but carrying it out is additionally credited.Is artificial intelligence part of the programme?
It is, as one module, where the organisation actually uses such systems. Since 2 February 2025 the AI Act has required a sufficient level of AI literacy among the staff of providers and of entities deploying such systems. There is no direct fine for it, but it is taken into account in supervision.Do you issue certificates to participants?
We do, on request. For audit evidence an attendance list with a date is enough, but a certificate helps where a personal training record is also required.Can we run the training ourselves with your materials?
You can, and for repeat cycles that is often the cheapest option. We then produce the programme, the materials and a record template, and your own person delivers the sessions. As a rule we run the first cycle so you can see how it looks.Where to go next
The measures training touches most directly.
From the blog: cyber security
The three latest texts on attacks, incidents and the human factor.
Let us arrange a workshop for your team.
Half an hour, no obligation. Tell us who the participants are and what lies ahead, and we will propose a programme and a duration.
