NIS2 Cyber Hygiene & Security Training (Article 21(2)(g)): The Human Layer
NIS2 Article 21(2)(g) requires basic cyber hygiene practices and security-awareness training. It's the cheapest, highest-leverage measure on the list, here's a practical baseline.
Article 21(2)(g) asks for “basic cyber hygiene practices and cybersecurity training.” It’s easy to dismiss as the soft measure, but the majority of incidents still start with a person clicking, reusing a password, or running something they shouldn’t. This is the highest return-on-effort line in Article 21.
Treat this as orientation rather than legal advice. NIS2 lands differently in each country once transposed (in Italy via D.Lgs. 138/2024, overseen by the ACN); your national authority holds the binding detail.
Cyber hygiene: the basics, done consistently
“Hygiene” is the unglamorous set of habits that prevent most trouble:
- Patching, keep systems and software up to date, prioritising vulnerabilities that are actually being exploited.
- Strong authentication, unique passwords, a password manager, and MFA on anything that matters (covered in depth under measure (j)).
- Least privilege, people and services get only the access they need.
- Known inventory, you can’t protect or patch what you don’t know you run.
- Backups, tested, per measure (c).
None of this is advanced. The NIS2 expectation is that it’s done consistently and across the organisation, not just by the one careful admin.
Training: regular, relevant, recorded
Security-awareness training under NIS2 should be:
- Recurring, not a one-time onboarding slide, annual at minimum, with shorter nudges in between.
- Relevant to real risks: phishing, business-email compromise, safe handling of data, reporting suspected incidents.
- Inclusive of leadership, NIS2 explicitly expects management bodies to follow training too, because they’re accountable.
- Recorded, who was trained, when. That record is your evidence.
A phishing simulation a couple of times a year turns “we told people about phishing” into “we measure whether it’s working,” which also feeds your effectiveness assessment (measure (f)).
Where hygiene meets the rest
Hygiene and vulnerability management overlap directly: “keep things patched, prioritising what’s exploited” is hygiene. Making that practical at scale, knowing which of the thousands of CVEs actually matter for your inventory, is the narrow job SentriKat does, so your team spends its limited time on the patches that move risk, not chasing noise.
Start here
Put a recurring annual awareness session and two phishing simulations in the calendar, write the one-page “our basics” hygiene checklist, and make sure leadership is on the training list. Cheap, fast, and it measurably reduces incidents.
Curious where training and hygiene rank among your NIS2 gaps? The free NIS2/DORA readiness check shows you in ~5 minutes.
Ready to automate your vulnerability management?
Deploy SentriKat on-premises in minutes. Track CISA KEV vulnerabilities, generate NIS2 compliance reports, and protect your infrastructure.
Request a Demo