Skip to content
atlas

Security awareness

Also known as: cyber awareness, security awareness training

What staff know about security and how they act on it in daily work.

Draft - this entry has not been reviewed yet.

Formal

The level of understanding employees have of the threats facing the organisation, combined with the habits they show in response - built and kept up through planned training, campaigns and follow-up.

In plain English

Like teaching everyone in a building where the fire exits are and why the fire doors must stay shut - knowing is only half of it; doing it every day is the point.

In practice

A school gives security ten minutes at every staff meeting - this month, how to spot a fake MitID login page - and teachers now forward doubtful mails to IT instead of just deleting them.

Why it matters

Many attacks aim at people rather than machines, and NIS2 lists training among its minimum requirements, so awareness is both a defence and a legal duty.

Technical deep dive

NIST's older guidance, SP 800-16 (1998) and SP 800-50 (2003), both superseded by SP 800-50 Rev. 1 in September 2024, framed learning as a continuum: awareness focuses attention on security and aims at recognition, training builds specific skills for a role, and education integrates skills into a professional body of knowledge. The distinction still matters. Awareness is a population-wide state - can staff recognise a threat and do they know what to do next - whereas training is role-bound, such as secure coding for developers or privileged-access hygiene for administrators. Treating the annual all-staff module as if it were training is a common category error.

The normative requirements are concrete. ISO/IEC 27001:2022 clause 7.3 requires that people working under the organisation's control are aware of the information security policy, their contribution to the effectiveness of the ISMS including the benefits of improved performance, and the implications of not conforming. Annex A control 6.3, elaborated in ISO/IEC 27002:2022, expects an awareness, education and training programme aligned with policies and topic-specific procedures, updated regularly and covering both new starters and existing staff. NIS2 Art. 21(2)(g) lists basic cyber hygiene practices and cybersecurity training among the minimum risk-management measures, Art. 20(2) requires training for members of management bodies, and DORA Art. 13(6) makes awareness compulsory in financial entities.

Measurement is the difficult part. The traditional knowledge-attitude-behaviour model assumes that knowledge produces the right attitude, which produces the right behaviour, but the knowing-doing gap is well documented: people who can pass a quiz still click under time pressure. Validated instruments such as the Human Aspects of Information Security Questionnaire (HAIS-Q) measure knowledge, attitude and self-reported behaviour separately, while observed behaviour - reporting rates in real and simulated incidents, time-to-report, policy exceptions, data-handling errors - is the stronger evidence. Large field studies (IEEE S&P 2022 and 2025) found that annual training and embedded post-click lessons had little measurable effect on phishing susceptibility, which is a reason to measure outcomes rather than completions.

Awareness is individual and cognitive; security culture is the collective set of norms that decides whether that knowledge is applied when it is inconvenient. Awareness is necessary but not sufficient: it works best when paired with nudges at the point of decision and with technical controls, such as phishing-resistant MFA, that do not depend on a person noticing anything at all.

What to learn first

Everything this builds on, foundations first.

  1. Threat
  2. →Security awareness

Relationships

Requires
Threat
Don't confuse with
Security culture

Sources & further reading

Standards & official texts

Course material

  • Cyber Security Fast Track - Ordliste

Where this data comes from

This entry was drafted by an AI from the sources above and has not yet been checked by a person. Treat it as a starting point, and check anything important against the sources.

See the review queueSuggest a correction on GitHubThis term as JSON

Check yourself

Loading…

Atlas is in beta.