Skip to content
atlas

Awareness officer

Also known as: awareness lead, security training lead

The person responsible for teaching staff to spot and avoid attacks, and for measuring whether their habits actually change.

Draft - this entry has not been reviewed yet.

Formal

A role that plans, runs and evaluates the organisation's awareness and training work - choosing target groups, messages and methods, running phishing simulations, and reporting results against agreed measures.

In plain English

Like the dental nurse who teaches children to brush - the aim is fewer holes later, and the next check-up shows whether the lesson stuck.

In practice

At a Danish wholesale company, the awareness officer sees that the warehouse team rarely reports fake emails, so she runs a ten-minute session at their morning meeting instead of sending another online course.

Why it matters

Attacks aimed at people keep changing, so someone must own the job of keeping staff ready - NIS2 even requires training for management.

Technical deep dive

NIST SP 800-50 Rev. 1 (September 2024), which supersedes SP 800-50 (2003) and SP 800-16 (1998), is the most detailed public description of the role, calling it the CPLP manager (Cybersecurity and Privacy Learning Program manager). Section 1.6.3 gives it tactical responsibility: interpreting legislation and policy with subject-matter experts, producing timely material for defined audiences, choosing dissemination channels, collecting learner feedback, reviewing content periodically, setting up tracking and reporting, identifying staff with significant security or privacy responsibilities, and reporting goals and metrics to a senior leadership committee. Strategy, budget and accountability stay with the head of the organisation and senior leadership, which is the right split: the officer runs the programme but does not own the risk.

The regulatory hooks the officer works against are specific. ISO/IEC 27001:2022 clause 7.2 requires the organisation to determine competence, act to close gaps and retain documented information as evidence, and clause 7.3 requires that people doing work under the organisation's control are aware of the information security policy, their contribution to the ISMS and the implications of not conforming; Annex A control 6.3 (detailed in ISO/IEC 27002:2022) covers awareness, education and training. NIS2 Art. 20(2) obliges members of management bodies to follow training and encourages regular training for employees, and Art. 21(2)(g) lists basic cyber hygiene and cybersecurity training among the minimum measures; in Denmark this is transposed through NIS 2-loven, in force since 1 July 2025. Financial entities also fall under DORA Art. 13(6), which makes ICT security awareness and digital operational resilience training compulsory for all staff and senior management.

Day to day the work is closer to behavioural design and marketing than to IT: needs analysis per audience segment (finance, HR, developers, privileged administrators, executives), a content calendar, phishing and vishing simulations, report-button adoption and feedback loops with the SOC so that reporters hear what happened to their report. Useful KPIs are reporting rate, median time-to-report, repeat-clicker rate and incidents with a human root cause; completion rates alone only prove attendance.

The role is often confused with neighbours. A data protection officer under GDPR Art. 39(1)(b) must also monitor awareness-raising and training, but only for personal-data processing and with independence requirements the awareness officer does not have. The CISO owns security risk overall, and HR owns onboarding and sanctions. In smaller organisations these hats are frequently combined, which is legitimate as long as the awareness work has its own plan, budget and measures.

What to learn first

Everything this builds on, foundations first.

  1. Threat
  2. →Security awareness
  3. →Awareness programme
  4. →Awareness officer

Relationships

A kind of
Grey roles

Sources & further reading

Standards & official texts

Course material

  • Cyber Security Fast Track - Kursuskompendium, Kursistens udbytte og Modul 2

Where this data comes from

This entry was drafted by an AI from the sources above and has not yet been checked by a person. Treat it as a starting point, and check anything important against the sources.

See the review queueSuggest a correction on GitHubThis term as JSON

Mentioned in

Check yourself

Loading…

Atlas is in beta.