Skip to content
Knowledge base Updated: February 5, 2026

KSC NIS2 and the human firewall: How must a CISO build an ongoing security culture program?

You have implemented EDR, SIEM and firewalls. But your weakest link remains humans. KSC/NIS2 requires cyber hygiene training. How is a CISO supposed to build an effective, ongoing program that will realistically change habits, not just be a one-time

As CISO, you led the implementation of the CORE Suite. The organization invested in advanced EDR, SIEM and firewall technologies. The network architecture has been segmented, and key EMS procedures have been written. The technical front end appears to be secured. But you know full well that even the most expensive technology is useless if an employee opens the door to an attacker by clicking on a single malicious link. The human firewall remains the most frequently attacked and weakest link.

KSC/NIS2 legislators are well aware of this. That’s why the new legislation explicitly requires organizations to implement cyber hygiene policies and training. This is no longer a “nice-to-have” from the HR department, but a hard legal requirement. What this means for you, as a CISO, is that you need to build a program that makes a real difference in human behavior, and that is a key pillar of the RESILIENCE Package - the ongoing maintenance of resilience.

Shortcuts

Why does KSC/NIS2 place so much emphasis on “cyber hygiene” and employee training?

KSC/NIS2 represents a change in philosophy - from reacting to problems to proactive risk management. An analysis of almost every major incident in recent years leads to the same conclusion: human error was at the root of most successful ransomware attacks or data leaks. Most often it was clicking on a phishing link or providing credentials on a fake site.

The legislature understands that it is impossible to build a 100% effective technological barrier. That’s why KSC/NIS2 requires the implementation of “appropriate and proportionate” measures that also include ** a “human layer of security.”** The obligation to conduct cyber hygiene training is nothing more than a legal requirement for an organization to manage the risk of human error in a systemic way.

For you as a CISO, this is a powerful argument with management. Investment in employee awareness is no longer a cost, but an implementation of a specific provision of the law. In the event of an incident, the regulator will ask not only about the logs from the SIEM, but also about how the company trained its people not to let the incident happen.

📚 Read the complete guide: NIS2: Kompletny przewodnik po dyrektywie NIS2 - obowiązki, kary, terminy

What is an “ongoing safety culture building program” and why is it better than one-time training?

Many companies try to “tick off” the training requirement by holding a mandatory two-hour training session for all employees once a year. As a CISO, you know that this is completely ineffective. Such knowledge is forgotten after a week, and the training itself is treated by employees as a necessary evil. This is “security theater,” not real risk management.

The Continuous Safety Culture Building Program, a key component of the RESILIENCE Package, is a completely different philosophy. It is not a one-time “event,” but an ongoing process based on a cycle: test, measure, train and repeat. Instead of boring lectures, this program uses short, engaging formats and, most importantly, is directly linked to real-world threats.

Such a program keeps employee awareness high throughout the year. It turns safety from an annual obligation into a permanent part of the organizational culture. It’s the only model that realistically changes people’s habits and allows you to demonstrate to the regulator that the awareness-building process is taken seriously and is continuously improved.

What role do simulated social engineering tests play in building awareness?

Simulated social engineering tests are the heart of a modern awareness-building program. Instead of telling employees what phishing is, you send them a controlled, secure simulation of a phishing attack and see how they react.

The role of these tests is twofold. First, they are the best diagnostic tool. They allow you to measure the real level of risk. You’re not relying on “do you know what phishing is?” surveys, but measuring a hard indicator: what percentage of employees in your company are clicking on malicious links. This gives you a baseline metric that you can report to management.

Second, it is the most effective form of learning. Nothing teaches faster than personal experience. The moment when an employee clicks on a link and sees the “Oops, that was a simulated phishing attack” board is priceless. It’s the moment when an abstract threat becomes real. It’s a safe failure that teaches far more than any lecture.

Is social engineering testing “testing” or “training” employees?

This is one of the most common questions and dilemmas when implementing a program. The answer is a smart combination of both. The test itself is a form of training - it teaches through experience. But its main strength is that it acts as a precise diagnostic tool that allows you to optimize the training process.

In the traditional model, you train everyone equally, wasting the time of those who are aware and boring them, while failing to reach those who are most susceptible with the right message. In the continuous, test-based model, the opposite is true. Social engineering tests allow you to identify which employees (or which departments) are most vulnerable.

This allows you to stop training everyone equally. You can target your training resources (e.g., short e-learning modules) only to those people who “failed” the test and need the knowledge the most. This turns training from a mass, generic process into a precise, tailored remediation program.

What types of simulated attacks (phishing, vishing) should be carried out regularly?

An awareness-building program cannot be limited to simple phishing emails. Attackers are creative, and your simulations must reflect real-world scenarios. A good program, such as the one described in the RESILIENCE Package, should cover the entire spectrum of social engineering attacks.

The basis, of course, is phishing (e-mail) campaigns. These need to range from simple mass mailings (e.g., “you’ve won a prize”) to more targeted ones (e.g., a fake invoice for the finance department or an urgent request from IT to change your password).

These should be supplemented with vishing (telephone attacks). It’s crucial to test employees who have direct contact with the outside world, such as receptionists, management assistants or finance departments. A scenario could involve a “support staff member” trying to phish for a password or soliciting an urgent wire transfer. Smishing (SMS) that tests the resilience of employees using work phones (such as a link to a fake courier package) should also be included.

How to combine phishing test results with e-learning training?

This is the mechanism that transforms testing into an effective training program. The idea is to create an immediate feedback loop. The moment an employee clicks on a simulated phishing link, they shouldn’t just see a “you’ve been caught” message.

A modern awareness-building platform should immediately, upon clicking, redirect the employee to a short (3-5 minutes) e-learning module that is thematically related to the mistake he just made. If he clicked a link with a fake invoice, he immediately watches the module “How to verify malicious attachments?”. If he entered his password on a fake login page, he watches the module “How to recognize a fake website?”.

This combination is brilliant in its simplicity. Training takes place at the exact moment when the employee is most aware of his or her mistake and most open to accepting the knowledge. This turns failure into an immediate lesson and is incomparably more effective than general training conducted six months later.

Who should be included in the training program - is it just office workers?

It is a mistake to limit the awareness program to office workers only. KSC/NIS2 requires a holistic approach, and risks exist throughout the organization. The program must be tailored to different groups.

Office workers are, of course, a prime target for phishing and vishing. But production (OT) workers are equally important. They can unknowingly connect an infected flash drive or private laptop to the industrial network, causing factory paralysis. Their training needs to be different - focused on physical security and the specifics of the OT environment.

The most important group, however, is management and the board of directors. KSC/NIS2 explicitly requires specialized training for them. In addition to training in strategic risk management, they must be included in social engineering tests. They are the No. 1 target for whale phishing attacks (targeting C-level executives) and Business Email Compromise (e.g., trying to get the CFO to make a fraudulent wire transfer).

How to measure the effectiveness of the awareness program and report it to the board?

As a CISO, you have to prove to management the return on investment of this program, and to the regulator its effectiveness. In this model, “measuring” is not about counting “hours trained” or “training attendance.” You are measuring real behavioral change.

A key metric you need to track and report on is the organizational “click-rate, or the percentage of employees who clicked on a link in a simulation campaign. Your goal is to show management a graph where this rate steadily declines - for example, from 30% in the first campaign to 5% after a year of running the program.

Another important metric is the “reporting-rate” - that is, how many employees, instead of clicking, used the “Report Phishing” button. An increase in this rate shows that employees are becoming an active part of the defense system. Having such hard data is the best proof for you that you are actively and effectively managing the “human firewall”.

What role does an external partner play in implementing and running such a program?

You can try to build such a program internally, but it is extremely time-consuming. It requires buying or building a phishing platform, creating a library of e-learning modules, designing attack scenarios and managing entire campaigns. Your IT/Security team probably has more important tasks.

A third-party partner, such as nFlo, provides this program as a managed service as part of the RESILIENCE Package. You gain several key benefits. First, a ready-made platform and content. You get access to a professional platform and a continuously updated library of simulations and e-learning courses.

Second, expertise and resources. The partner’s dedicated team designs and manages campaigns on your behalf, analyzes results, and provides you with ready-made reports for management. Third, objectivity and benchmarking. The partner provides an independent assessment and can compare your results (e.g., click-rate) with the average for your industry. This allows you, as CISO, to focus on strategy while the partner operationally does the tedious but critical work of building a safety culture.

Building a Culture of Safety (RESILIENCE Package): Table for CISOs

The following table summarizes the components of an effective awareness-building program required by KSC/NIS2.

Learn key terms related to this article in our cybersecurity glossary:

  • Security Operations Center (SOC) — Security Operations Center (SOC) is a central location where a team of security…
  • Ransomware — Ransomware is a type of malicious software (malware) that blocks access to a…
  • SOC as a Service — SOC as a Service (Security Operations Center as a Service), also known as…
  • Cybersecurity — Cybersecurity is a collection of techniques, processes, and practices used to…
  • Cybersecurity Incident Management — Cybersecurity incident management is the process of identifying, analyzing,…

Learn More

Explore related articles in our knowledge base:


Explore Our Services

Need cybersecurity support? Check out:


See also:

Share:

Talk to an expert

Have questions about this topic? Get in touch with our specialist.

Sales Representative
Grzegorz Gnych

Grzegorz Gnych

Sales Representative

Response within 24 hours
Free consultation
Individual approach

Providing your phone number will speed up contact.

Want to Reduce IT Risk and Costs?

Book a free consultation - we respond within 24h

Response in 24h Free quote No obligations

Or download free guide:

Download NIS2 Checklist