Back to playbooks
    Playbook

    Security awareness that changes behaviour

    A method for running an awareness programme against measured behaviour instead of completion rates, with the training records falling out as a by-product.

    Governance5 Sept 202622 min read

    Directive (EU) 2022/2555ISO/IEC 27001:2022ISO/IEC 27002:2022NIST CSWP 29Regulation (EU) 2022/2554Regulation (EU) 2024/1689
    On this page

    Scope: one awareness programme, end to end · Who: the officer accountable for it · Prerequisites: an incident log and a named sponsor · First result: a behaviour baseline in six weeks

    1. Why this exists (the failure mode it prevents)

    Awareness programmes are usually measured by the wrong number. Completion is cheap to count and easy to reach. A module goes out in October, reminders follow in November, and the year-end report shows 98 per cent. Nothing observable about the organisation has changed.

    That is a measurement choice, not a failure of effort. Completion measures the delivery of content. It says nothing about whether anyone reports a suspicious message faster, stores a shared credential differently, or stops an out-of-band payment request.

    Three patterns follow. The annual module becomes a fixed syllabus with no relation to the incidents the organisation actually has. The phishing simulation becomes a trap: the headline is the click rate, individuals are named, and people quietly stop reporting. The training record satisfies a clause on paper and nothing else.

    It surfaces in assessment predictably. ISO/IEC 27001:2022 clause 9.1 is titled "Monitoring, measurement, analysis and evaluation" 1. An assessor asks what the programme is meant to change, how that change is measured, and what the last three measurements showed. A completion report answers none of the three.

    The standard asks the same at control level. ISO/IEC 27002:2022 control 6.3 is Information security awareness, education and training. It says understanding should be assessed at the end of an activity, to test knowledge transfer and programme effectiveness 2. A completion tick tests neither.

    The regulatory version is sharper. Article 21(2)(g) of Directive (EU) 2022/2555 lists basic cyber hygiene practices and cybersecurity training among the measures essential and important entities must at least take 3. Article 21(2)(f) requires policies and procedures to assess the effectiveness of those measures 4. A slide deck is not such an assessment.

    This playbook replaces the completion number with a small set of measured behaviours, and treats every intervention as an experiment against one of them.

    2. Definitions (only the ones that cause disputes)

    Six terms account for most disagreement between a security function, its assessor and its human resources partner. Guidance text is paraphrased throughout; titles are quoted, and nothing longer than a short phrase.

    TermWorking definitionSource
    AwarenessWorking definition: what a person needs to know about the policy, their contribution and the consequence of not conforming. General, for everyone in scope.ISO/IEC 27001:2022 clause 7.3, titled "Awareness" 5
    CompetenceWorking definition: the ability to do a specific job to a defined standard, shown by education, training or experience and recorded per role. Awareness does not substitute for it.ISO/IEC 27001:2022 clause 7.2, titled "Competence" 6
    Target behaviourOne observable action, by a named audience at a named moment, that changes the outcome of a plausible incident. "Be vigilant" is not one. "Report a suspected message within ten minutes" is.Working term, measured under clause 9.1 1
    Measure of behaviourA number produced by a system that records the behaviour, not by asking people about it. Report counts and approval records qualify; survey confidence does not.Working term; control 6.3 asks for assessed understanding and programme effectiveness 2
    Cyber hygieneA common baseline of practices. Recital 49 names software and hardware updates, password changes, management of new installs, limits on administrator-level accounts, and backing up data.Directive (EU) 2022/2555, recital 49 7
    Management-body trackA separate duty on the board, not a senior edition of the staff module. Its members are required to follow training; entities are encouraged to offer similar training to employees.Directive (EU) 2022/2555 Art. 20(2) 8

    The first two are worth separating in writing, because assessors do. Clause 7 of ISO/IEC 27001:2022 covers resources, competence, awareness, communication and documented information 9. An awareness campaign delivered to an engineering team is not a competence record.

    3. The method — numbered steps, each with input, activity, output and owner

    Eight steps. The first four build the programme from evidence the organisation already holds. The fifth handles the body carrying its own duty. The last three measure, record and retire.

    3.1 Start from incidents and risks, not from topics

    Most syllabuses are inherited: they cover phishing, passwords and clear desk because the previous version did. Start instead from what has gone wrong here, and from what the risk register says could.

    Read the last twenty-four months of the incident log and pull out the human action in each entry. Someone clicked, shared, approved, skipped a step, or waited two days before reporting. Group those actions, keep the groups that recur, then cross-check the risk register for scenarios where a human action is the first or last line of defence.

    Five to eight target behaviours is the working range: fewer ignores real exposure, more and no single behaviour gets enough attention to move.

    ISO/IEC 27002:2022 control 6.3 supports this directly: the programme should be built on lessons learnt from information security incidents 2. A syllabus with no traceable link to the incident log is one nobody chose.

    • Input: incident log for the last twenty-four months; risk register; policy set and topic-specific policies.
    • Activity: extract the human action from every incident; group and rank by frequency and consequence; select five to eight behaviours; write each as an observable action.
    • Output: behaviour catalogue, one row per behaviour, with audience, moment, action and the failure it prevents.
    • Owner: security officer drafts; risk owners confirm the ranking.

    3.2 Map the audiences and their moments

    A behaviour without a moment is a poster. The moment is when the person is in the situation: opening a payment request, being granted an administrator role, changing team.

    Six audiences cover most organisations — new joiners, role changers, privileged-access holders, the management body, engineers, and third parties with access. Control 6.3 puts external people explicitly in scope: the programme should be planned taking account of the roles of personnel, including internal and external personnel such as external consultants and supplier personnel. The same control treats a substantial change of role as an initial-training trigger, alongside joining 2.

    Financial entities are to include ICT third-party service providers in the relevant training schemes where appropriate 10. For everyone else the same reach comes through supplier obligations.

    Write the map as a grid: audience down the side, behaviour across the top, the moment in each cell. Empty cells are as informative as full ones.

    • Input: behaviour catalogue; joiner, mover and leaver process; access model; supplier register.
    • Activity: list the audiences; name the moment each meets each behaviour; mark empty cells and decide whether the behaviour applies.
    • Output: audience map, a grid of audience against behaviour, with the moment named in each live cell.
    • Owner: security officer, with the human resources partner and the access owner.

    3.3 Baseline the behaviours before intervening

    This is the step programmes skip, and skipping it is why nothing can be shown afterwards. A measure taken only after the campaign proves nothing.

    Every measure comes from a system that records the behaviour: the reporting channel, the credential store, the approval records, the endpoint estate, the change record. Surveys measure confidence, which in our working view is not the same thing as behaviour.

    Take the baseline over a defined window and record the method, not only the number. A report rate measured against a different denominator next quarter is not a comparison.

    Two measures need care. A report rate reflects how easy and how safe reporting feels, in our working view, so read it beside median time-to-report. A low click rate on an obvious lure tells us little.

    • Input: audience map; access to the recording systems; a defined measurement window.
    • Activity: define one or two measures per behaviour; write down the source system, denominator and collection method; collect the first window; record who can reproduce it.
    • Output: measure definitions and the baseline record, one value per behaviour per audience cohort.
    • Owner: security officer defines; the system owners produce the numbers.

    3.4 Design one intervention per behaviour, and run it as an experiment

    An intervention exists to move one measure. If it cannot be tied to a measure, it does not go in the calendar. Four kinds cover most of the work.

    Just-in-time prompts sit at the moment itself: a banner on external mail, a confirmation step on a first-time payee, a reminder in the approval screen. They do not rely on recall.

    Role-based sessions carry what genuinely differs by role. Control 6.3 asks for a training plan for technical teams whose roles need specific skill sets, and for acquiring skills that are missing 2. That is competence work under clause 7.2, and it produces a competence record rather than an awareness record.

    Simulations run as practice. Publish the rules before the first run: what is simulated, how often, what is recorded, who sees individual results, and what never follows from them. The measures are report rate and time-to-report, not click rate.

    That is not a matter of taste. ISO/IEC 27002:2022 control 6.4, Disciplinary process, describes a graduated response that weighs whether an offence was intentional or accidental, first or repeated, and whether the person was properly trained. It also asks that people facing disciplinary action are shielded from exposure where possible, and it allows good behaviour to be rewarded 11. A simulation that names people inverts both.

    Leader modelling is a control in its own right. ISO/IEC 27002:2022 control 5.4 is Management responsibilities. It asks that personnel be briefed before access is granted, and given guidelines stating what their role expects 12. Where practicable, it also asks for a confidential channel for reporting violations 12.

    Two behaviours have control text worth designing against. Control 6.8 is Information security event reporting. It asks that the mechanism for reporting observed or suspected events be as easy, accessible and available as possible 13. It also asks that people be told the procedure and the point of contact, and that they not try to prove a suspected vulnerability 13.

    Control 8.7 is Protection against malware. It states that protection should be supported by appropriate user awareness, and that detection and repair software alone is not usually adequate 14. It asks for training on identifying malware-infected mail, files and programs 14.

    • Input: behaviour catalogue; audience map; baseline record.
    • Activity: design one intervention per behaviour per audience; state the measure it targets and the change expected; schedule it; publish the simulation rules first.
    • Output: intervention calendar, naming a target measure and expected direction per entry; simulation rules, published.
    • Owner: security officer designs; the audience's line management sponsors delivery.

    3.5 Run the management-body track as a separate obligation

    The board's training is a duty in its own name, not the staff module with a shorter deck.

    Directive (EU) 2022/2555 requires Member States to ensure that members of the management bodies of essential and important entities follow training 8. Member States must also encourage those entities to offer similar training to employees regularly 8. The purpose is that they gain sufficient knowledge and skills to identify risks, and to assess cybersecurity risk-management practices and their impact on the entity's services 8.

    The same article puts the body in the approval seat. Management bodies approve the Article 21 measures, oversee implementation, and can be held liable for the entity's infringements 15. Training that leaves a member unable to challenge a proposed measure set has missed the clause.

    Financial entities carry two overlapping duties. Regulation (EU) 2022/2554 makes ICT security awareness programmes, and digital operational resilience training, compulsory modules within the staff training scheme 10. Those modules reach all employees and senior management staff, with complexity matched to the remit of their functions 10. Separately, members of the management body must keep up to date with the knowledge and skills to understand and assess ICT risk, through regular training 16.

    A third literacy duty sits alongside them. Regulation (EU) 2024/1689 requires providers and deployers of AI systems to take measures supporting the AI literacy of their staff 17. The duty reaches other persons dealing with the operation and use of those systems on their behalf 17. It does not require any specific level of AI literacy to be guaranteed in any individual 17. Because no level is defined, the defensible position is a stated one: write down what sufficient means for each role, and keep the record of what was delivered.

    • Input: the applicable instruments; the measure set awaiting approval; the register of AI systems in use.
    • Activity: set a syllabus around assessment and challenge rather than threat description; fix the cadence; record attendance per member; state the AI-literacy level per role.
    • Output: management-body programme with syllabus, cadence and per-member attendance; AI-literacy statement per role.
    • Owner: the chair or company secretary schedules; the security officer supplies the content.

    3.6 Measure change, not completion

    The measurement step reuses the definitions written in 3.3. Nothing new is invented, or the comparison is lost.

    Report by cohort, not as an organisation-wide average. An average hides the two things worth acting on: the audience that has not moved, and the audience that moved and then slid back.

    Read each measure against the direction stated in the calendar. Three outcomes are all useful. It moved as expected, so the intervention stays. It did not move, so it is redesigned or dropped. It moved the wrong way, which usually means the intervention changed what people report rather than what they do.

    This is what the directive means by procedures to assess the effectiveness of the measures 4. NIST CSWP 29 sets the PR.AT outcome: personnel receive cybersecurity awareness and training so they are able to perform their cybersecurity-related tasks 18. Performing the task is the test, not attending the session.

    • Input: measure definitions; the baseline record; the intervention calendar with its stated expectations.
    • Activity: collect each measure for the period using the recorded method; compare to baseline by cohort; classify each intervention as kept, redesigned or dropped; record the decision.
    • Output: quarterly measure set by cohort, with the decision per intervention.
    • Owner: security officer produces; the sponsor reviews the decisions.

    3.7 Let the training record fall out of the work

    The record that satisfies clauses 7.2 and 7.3 is a by-product of steps 3.4 to 3.6. It becomes a separate exercise only when the programme produced nothing else.

    Keep three sets separately. The awareness record covers everyone in scope and shows what each person was made aware of and when. The competence record covers roles needing a defined skill and shows how it was established. The effectiveness record is the baseline plus the quarterly measure sets plus the decisions.

    Control 6.3 asks that understanding be assessed at the end of an activity 2. An awareness entry carrying a comprehension result is therefore stronger than an attendance line. The control lists what general awareness should cover: management's commitment, the applicable rules and obligations, and personal accountability 2. It names basic procedures such as event reporting, and the contact points for advice 2.

    Store the sets where the process already keeps its records, and name them in the document control register.

    • Input: delivery records; comprehension results; measure sets; the document control register.
    • Activity: separate the awareness, competence and effectiveness records; attach comprehension results to awareness entries; register the location and retention of each set.
    • Output: training record set, in three parts, registered and retained.
    • Owner: human resources holds the per-person records; the security officer holds the effectiveness record.

    3.8 Keep it alive, and retire what does not move a measure

    A programme that runs unchanged for three years is a syllabus. Three mechanisms keep it current.

    Incident-driven refresh. An incident whose human action matches a catalogue behaviour triggers a review of that intervention within the month. One matching nothing in the catalogue asks whether the catalogue is complete.

    Annual re-baseline. Repeat 3.3 in full once a year, with the same methods, and reset the comparison point.

    Retirement. An intervention that has not moved its measure across two consecutive periods is dropped, and the reason recorded. Its absence is why calendars only ever grow.

    Where a measure does not move because the underlying control is missing, that is a finding, not an awareness problem. ISO/IEC 27001:2022 clause 10.2, Nonconformity and corrective action, separates reacting to the nonconformity, examining its cause, acting on the cause and reviewing effectiveness 19. A campaign aimed at a missing control fails the second of those.

    • Input: incident log; the quarterly measure sets; the intervention calendar; the finding register.
    • Activity: review the affected intervention within a month of each matching incident; re-baseline annually; drop interventions that have not moved a measure over two periods. Raise a finding where the cause is a missing control.
    • Output: updated behaviour catalogue and intervention calendar, with a dated retirement note per dropped item.
    • Owner: security officer; the sponsor approves retirements.

    4. Deliverables

    Seven artefacts carry the method. Retention periods are organisational choices, not requirements of any instrument cited here.

    DeliverableProduced byFormatRetention
    Behaviour catalogueStep 3.1, revised in 3.8registercurrent version, plus one cycle
    Audience mapStep 3.2gridcurrent version
    Measure definitions and baselineStep 3.3, reset in 3.8register plus data extractwhole cycle
    Intervention calendar and simulation rulesStep 3.4plan plus published ruleswhole cycle
    Management-body programme and AI-literacy statementStep 3.5syllabus plus attendancewhole cycle, plus one
    Quarterly measure setStep 3.6data extract with decisionswhole cycle, plus one
    Training record set, in three partsStep 3.7per-person plus effectiveness recordsper the retention policy

    5. What the auditor or authority will ask

    Every clause, article and subcategory below is verified where it is first cited, in sections 2, 3 or 7. The phrasing follows an assessor's line of enquiry: a request for the record, then for the decision behind it.

    An enquiry that stays on the syllabus is going well. One that moves to the measures, and then to the cohort that did not improve, is where a completion-based programme runs out of answers.

    6. Failure modes and how they surface as findings

    Five patterns account for most avoidable findings. Each is the pattern, the wording it tends to produce, and the smallest change that removes it.

    The root of all five is the same: the programme was designed backwards from a number that was easy to produce.

    7. Mapping behaviour to requirement, intervention, measure and evidence

    Clause and control titles below were read from the sources named in the References section, on the dates shown. Guidance text is paraphrased; only titles are quoted.

    BehaviourRequirementInterventionMeasureEvidenceVerified
    Report a suspected event promptlyISO/IEC 27002:2022 control 6.8One-click reporting in the mail clientReports per hundred staff; time-to-reportReporting channel extract13
    Keep every work credential in the managed storeDirective (EU) 2022/2555 Art. 21(2)(g)Enrolment at joining; shared-account clean-upStaff fully enrolled; shared accountsCredential store extract3
    Verify payment and access changes out of bandISO/IEC 27002:2022 control 5.4Confirmation step on first-time payeesChanges verified on a second channelApproval records12
    Place confidential data only in sanctioned storesNIST CSWP 29 PR.AT-01Prompt on external sharing; role sessionsConfidential items outside sanctioned storesData store scan and sharing log20
    Patch, lock and report a lost device same dayISO/IEC 27002:2022 controls 6.8, 7.9 and 8.8Endpoint prompt; one-click loss reportingPatch compliance at day fourteen; time to reportEndpoint estate report21
    Put every production change through approvalNIST CSWP 29 PR.AT-02Role session for engineers; gate in the pipelineChanges with recorded approval; emergency ratioChange record extract22
    Use only registered AI systems, within instructionsRegulation (EU) 2024/1689 Art. 4(1)AI-literacy session per role; registration pathShare of AI use cases registeredAI use-case register; gateway logs17
    Management body: challenge and approve the measuresDirective (EU) 2022/2555 Art. 20(1)Assessment-focused syllabus, fixed cadenceAttendance per member; challenges recordedMinuted approval15
    Programme: prove effectiveness, not deliveryISO/IEC 27001:2022 clause 9.1Quarterly review, one decision per interventionMovement per measure per cohortQuarterly measure set1
    Programme: put security into people processesNIST CSWP 29 GV.RR-04Joiner and mover triggers wired to the mapJoiners and movers reached at the right momentJoiner and delivery records23
    Target behaviour to requirement to intervention to measure to evidence

    Two notes. Regulation (EU) 2024/2847 places no article-level training duty on manufacturers, so it is not mapped. The Annex A awareness control is cited through ISO/IEC 27002:2022, which carries the same numbering and is the text that was read.

    8. Checklist

    Each item is observable. "Staff are aware" is not; a dated measure with a recorded method is.

    References

    Primary sources only. The European instruments were read at the EU Publications Office, the framework at the publisher, the ISO/IEC 27001 clause titles on the publisher's contents listing, and the ISO/IEC 27002 controls in a licensed copy.

    1. European Parliament and Council. Directive (EU) 2022/2555 of 14 December 2022 on measures for a high common level of cybersecurity across the Union (NIS 2 Directive). OJ L 333, 27.12.2022, p. 80. Articles 20 and 21 and recital 49 read at https://publications.europa.eu/resource/celex/32022L2555 24
    2. European Parliament and Council. Regulation (EU) 2022/2554 of 14 December 2022 on digital operational resilience for the financial sector (DORA). OJ L 333, 27.12.2022, p. 1. Articles 5 and 13 read at https://publications.europa.eu/resource/celex/32022R2554 25
    3. European Parliament and Council. Regulation (EU) 2024/1689 laying down harmonised rules on artificial intelligence (Artificial Intelligence Act), consolidated text of 27 July 2026. Article 4 read at https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX:02024R1689-20260727 26
    4. National Institute of Standards and Technology. The NIST Cybersecurity Framework (CSF) 2.0. NIST CSWP 29. Appendix A, the CSF Core, read at https://doi.org/10.6028/NIST.CSWP.29 27
    5. ISO/IEC. Information security, cybersecurity and privacy protection — Information security management systems — Requirements. ISO/IEC 27001:2022. Contents and clause titles read at https://www.iso.org/obp/ui/#iso:std:iso-iec:27001:ed-3:v1:en 28
    6. ISO/IEC. Information security, cybersecurity and privacy protection — Information security controls. ISO/IEC 27002:2022. Controls 5.4, 6.3, 6.4, 6.8 and 8.7 read in a licensed copy; catalogue entry at https://www.iso.org/standard/75652.html 29
    7. European Parliament and Council. Regulation (EU) 2024/2847 (Cyber Resilience Act). Checked for a manufacturer-side training duty: recital 23 says manufacturers should ensure their staff has the necessary skills, and no article imposes one 30

    Retention periods, cadences and cohort definitions above are organisational choices, not requirements of any instrument or standard cited here.

    Sources

    1. 1ISO/IEC 27001:2022 clause 9.1, iso.org/obp · verified 2026-09-03
    2. 2ISO/IEC 27002:2022 control 6.3, licensed copy · verified 2026-09-05
    3. 3EU Publications Office CELEX 32022L2555 Art. 21(2)(g) · verified 2026-09-05
    4. 4EU Publications Office CELEX 32022L2555 Art. 21(2)(f) · verified 2026-09-05
    5. 5ISO/IEC 27001:2022 clause 7.3, iso.org/obp · verified 2026-09-03
    6. 6ISO/IEC 27001:2022 clause 7.2, iso.org/obp · verified 2026-09-03
    7. 7EU Publications Office CELEX 32022L2555 recital 49 · verified 2026-09-05
    8. 8EU Publications Office CELEX 32022L2555 Art. 20(2) · verified 2026-09-05
    9. 9ISO/IEC 27001:2022 clause 7, iso.org/obp · verified 2026-09-03
    10. 10EU Publications Office CELEX 32022R2554 Art. 13(6) · verified 2026-09-05
    11. 11ISO/IEC 27002:2022 control 6.4, licensed copy · verified 2026-09-05
    12. 12ISO/IEC 27002:2022 control 5.4, licensed copy · verified 2026-09-05
    13. 13ISO/IEC 27002:2022 control 6.8, licensed copy · verified 2026-09-05
    14. 14ISO/IEC 27002:2022 control 8.7, licensed copy · verified 2026-09-05
    15. 15EU Publications Office CELEX 32022L2555 Art. 20(1) · verified 2026-09-05
    16. 16EU Publications Office CELEX 32022R2554 Art. 5(4) · verified 2026-09-05
    17. 17EU Publications Office CELEX 02024R1689-20260727 Art. 4(1) · verified 2026-09-05
    18. 18NIST CSWP 29 Appendix A PR.AT, nvlpubs.nist.gov · verified 2026-09-05
    19. 19ISO/IEC 27001:2022 clause 10.2, iso.org/obp · verified 2026-09-03
    20. 20NIST CSWP 29 Appendix A PR.AT-01, nvlpubs.nist.gov · verified 2026-09-05
    21. 21ISO/IEC 27002:2022 controls 6.8, 7.9 and 8.8, licensed copy · verified 2026-09-05
    22. 22NIST CSWP 29 Appendix A PR.AT-02, nvlpubs.nist.gov · verified 2026-09-05
    23. 23NIST CSWP 29 Appendix A GV.RR-04, nvlpubs.nist.gov · verified 2026-09-05
    24. 24EU Publications Office CELEX 32022L2555 · verified 2026-09-05
    25. 25EU Publications Office CELEX 32022R2554 · verified 2026-09-05
    26. 26EU Publications Office CELEX 02024R1689-20260727 · verified 2026-09-05
    27. 27NIST CSWP 29 Appendix A, nvlpubs.nist.gov · verified 2026-09-05
    28. 28ISO/IEC 27001:2022 contents, iso.org/obp · verified 2026-09-03
    29. 29ISO/IEC 27002:2022 controls 5.4, 6.3, 6.4, 6.8 and 8.7, licensed copy · verified 2026-09-05
    30. 30EU Publications Office CELEX 32024R2847 recital 23 · verified 2026-09-05