Skip to main content

Awareness is a compliance requirement

Regulations and standards such as NIS2, GDPR, DORA and ISO 27001 place clear requirements on security awareness, employee training and demonstrable risk management. Organisations are expected not only to define policies and controls, but also to demonstrate that employees are informed, trained and actively engaged in protecting the business.

How AwareShield supports regulatory and compliance requirements

GDPR

GDPR compliance goes beyond policies

The GDPR requires organisations not only to protect personal data technically, but also to implement appropriate organisational measures. Employees play a crucial role in this. That is why the GDPR emphasises the importance of awareness, training and the careful handling of personal data.

AwareShield helps organisations address, among others:

  • Article 5 – Principles relating to the processing of personal data (integrity and confidentiality)
  • Article 24 – Responsibility of the controller
  • Article 25 – Data protection by design and by default (Privacy by Design & Default)
  • Article 32 – Security of processing, including employee training and awareness
  • Article 39 – Tasks of the Data Protection Officer, including staff awareness and training

With GDPR training, privacy awareness modules, phishing simulations, practical use cases and audit-ready reporting, AwareShield helps employees process personal data securely, prevent data breaches and reduce privacy risks. In this way, you not only strengthen privacy awareness within your organisation, but also have demonstrable evidence for audits, inspections and compliance accountability.

ISO 27001

ISO 27001 compliance starts with aware employees

ISO 27001 requires organisations not only to implement technical security measures, but also to make employees aware of their role in information security. After all, a large proportion of security risks arise from human actions, such as phishing, careless handling of information, or failure to comply with security policies.

AwareShield helps organisations address the awareness and training requirements within ISO 27001. With Security Awareness training, Compliance modules, Phishing simulations and audit-ready reporting, you increase employees' knowledge and resilience and can demonstrate that information security is actively supported throughout the organisation.

Relevant ISO 27001:2022 controls:

  • Control 6.3 – Information Security Awareness, Education and Training
  • Control 5.1 – Policies for Information Security
  • Control 5.10 – Acceptable Use of Information and Other Associated Assets
  • Control 5.15 – Access Control
  • Control 5.17 – Authentication Information
  • Control 6.8 – Information Security Event Reporting
  • Control 6.7 – Remote Working
  • Control 8.1 – User Endpoint Devices

With AwareShield, you train employees on these topics, measure progress, and have access to the reporting required for internal audits, external audits and certification programmes.

NIS2

NIS2 compliance starts with a cyber-aware organisation

NIS2 introduces stricter requirements for cybersecurity, risk management and governance. An important part of this is increasing cybersecurity awareness within the organisation. Employees must be able to recognise cyber threats, act securely and understand the role they play in protecting business data, systems and services.

AwareShield helps organisations demonstrably fulfil these obligations through Security Awareness training, Compliance modules, Phishing simulations and comprehensive reporting. This increases employee cyber resilience, reduces human risk and provides clear reporting for audits, regulators and internal controls.

Relevant NIS2 obligations

AwareShield supports organisations in meeting the requirements of Article 21 of the NIS2 Directive, including:

  • Article 21(2)(g) – Awareness, training and cyber hygiene
  • Article 21(2)(d) – Supply chain security
  • Article 21(2)(h) – Cybersecurity policies and procedures
  • Article 21(2)(i) – Use of multi-factor authentication and secure authentication methods
  • Article 21(2)(j) – Secure communications and data protection

With training on phishing, social engineering, passwords, MFA, data security, AI usage, physical security and secure working practices, AwareShield helps organisations address an important part of the human component of NIS2. Thanks to comprehensive dashboards and audit-ready reporting, you can easily demonstrate that employees have been trained and that cybersecurity awareness is actively managed.

DORA

DORA compliance starts with cyber-aware employees

The Digital Operational Resilience Act (DORA) requires financial entities and ICT service providers to strengthen their digital resilience. Technology alone is not sufficient. Employees must be able to recognise cyber threats, report incidents correctly and handle business and customer data securely. Awareness and training are therefore an essential part of an effective DORA programme.

AwareShield helps organisations demonstrably fulfil these obligations through Security Awareness training, Compliance modules, Phishing simulations and comprehensive reporting. Employees learn how to recognise cyber risks, prevent incidents and contribute to the organisation's digital resilience. Thanks to audit-ready reporting, you also have the documentation required for internal controls, auditors and regulators.

Relevant DORA obligations

AwareShield supports organisations in meeting, among others:

  • Article 13 – Protection and Prevention (protective and preventive measures)
  • Article 14 – Detection (detection of ICT-related incidents)
  • Article 17 – ICT-related incident management process
  • Article 28 – ICT third-party risk management
  • Article 13(6) – Digital operational resilience testing programmes
  • Article 13(8) – Cybersecurity awareness and digital operational resilience training

With training on phishing, social engineering, password security, data protection, secure remote working, AI usage and incident reporting, AwareShield helps address the human factor within DORA. Through phishing simulations and reporting, you can also demonstrate that employees are actively trained and that awareness forms part of the risk management process.

BIO

Information security within government starts with secure behaviour

The BIO is based on ISO 27001 and ISO 27002 and forms the information security framework for Dutch government organisations. In addition to technical measures, the BIO places significant emphasis on the human factor. Employees must be able to recognise risks, report security incidents and handle information, personal data and organisational assets securely.

AwareShield helps government organisations demonstrably fulfil these obligations. With Security Awareness training, Compliance modules, Use Cases, Phishing simulations and comprehensive reporting, you increase employees' security awareness and have access to the documentation required for audits, accountability and controls.

AwareShield supports measures that align with, among others:

  • BIO 5.1 – Information Security Policy
  • BIO 5.10 – Acceptable Use of Information and Organisational Assets
  • BIO 5.17 – Authentication Information and Password Policy
  • BIO 6.3 – Information Security Awareness, Education and Training
  • BIO 6.7 – Secure Remote Working and Working from Home
  • BIO 6.8 – Reporting Information Security Incidents
  • BIO 8.1 – Secure Use of Workstations and End-User Devices

With training on phishing, social engineering, data protection, secure remote working, passwords, MFA, AI usage and incident reporting, AwareShield helps organisations strengthen the human component of information security in a structured and ongoing manner.

SOC 2 Type II

Demonstrable Security Awareness for SOC 2 Type II

During a SOC 2 Type II audit, auditors assess not only whether policies are in place, but also whether employees have been adequately trained and whether security processes are being consistently followed. As human behaviour is a significant factor in security incidents, auditors often expect evidence that employees receive regular training and are made aware of cyber security risks.

AwareShield supports organisations with a comprehensive programme of Security Awareness, Compliance Training, Phishing Simulations and audit-ready reporting. This not only strengthens employee resilience but also provides demonstrable evidence of participation, progress and the effectiveness of awareness programmes.

Relevant SOC 2 Controls

AwareShield primarily supports the Trust Services Criteria (TSC) related to:

  • CC2.2 Communication of security-related responsibilities
  • CC2.3 Employee awareness and training
  • CC3.2 Risk management and risk awareness
  • CC4.1 Monitoring of internal controls
  • CC5.2 Controls for managing human-related risks
  • CC6.7 Security awareness and user responsibilities

Through training on phishing, social engineering, data protection, password management, AI usage and incident reporting, AwareShield helps organisations systematically manage and demonstrate the human aspect of SOC 2 Type II compliance.

NEN 7510

Information security and privacy in healthcare start with secure behaviour

NEN 7510 is the leading standard for information security within healthcare and helps healthcare organisations protect patient data and other confidential information. In addition to technical security measures, the standard also sets clear requirements for employee awareness, training and secure behaviour. The secure handling of patient data, recognising phishing attempts and reporting incidents are essential elements.

AwareShield helps healthcare organisations demonstrably meet these requirements. With Security Awareness training, Compliance modules, practical Use Cases, Phishing simulations and comprehensive reporting, you increase employee awareness and have access to the documentation required for audits, certification and regulatory oversight.

AwareShield supports, among others, the following NEN 7510 controls:

  • Control 6.3 – Information security awareness, education and training
  • Control 5.1 – Information security policy
  • Control 5.10 – Acceptable use of information and organisational assets
  • Control 6.8 – Reporting information security incidents
  • Control 6.7 – Secure remote working and working from home
  • Control 5.17 – Authentication information and password management
  • Control 8.1 – Secure use of workstations and end-user devices

With training on phishing, social engineering, privacy, patient data, secure remote working, passwords, MFA, AI usage and incident reporting, AwareShield helps healthcare organisations strengthen the human factor within information security in a structured manner and demonstrably comply with key elements of NEN 7510.

CIS Controls

Support CIS Control 14 with AwareShield

a { text-decoration: none; color: #464feb; } tr th, tr td { border: 1px solid #e6e6e6; } tr th { background-color: #f5f5f5; }

The CIS Controls are among the most widely used cybersecurity frameworks in the world and provide organisations with a practical approach to reducing cyber risk. In addition to technical measures, the CIS Controls explicitly address security awareness, training and the development of cybersecurity skills among employees.

AwareShield helps organisations demonstrably support these controls through Security Awareness training, Compliance modules, Use Cases, Phishing simulations and comprehensive reporting. This increases employee cyber resilience and provides the insights and documentation required for audits, assessments and improvement programmes.

AwareShield supports, among others, the following CIS Controls:

  • Control 14 – Security Awareness and Cybersecurity Skills Training
  • Control 14.1 – Establish and Maintain a Security Awareness Programme
  • Control 14.2 – Train Workforce Members to Recognise Social Engineering Attacks
  • Control 14.3 – Train Workforce Members on Authentication Best Practices
  • Control 14.4 – Train Workforce Members on Data Handling Best Practices
  • Control 14.5 – Train Workforce Members on Causes of Unintentional Data Exposure
  • Control 14.6 – Train Workforce Members to Recognise and Report Security Incidents
  • Control 17 – Incident Response Management

With training on phishing, social engineering, password management, MFA, data protection, AI usage, secure remote working and incident reporting, AwareShield helps organisations strengthen the human factor within cybersecurity in a structured manner and support key CIS Controls.

ISO 27701

Privacy management starts with aware employees

ISO 27701 is the international standard for privacy information management and an extension of ISO 27001. The standard helps organisations process personal data in a controlled, secure and transparent manner. In addition to technical and organisational measures, employee awareness plays an important role in protecting personal data and complying with privacy legislation such as the GDPR.

AwareShield helps organisations strengthen privacy awareness in a structured way. With Privacy Awareness training, Compliance modules, practical Use Cases, Phishing simulations and comprehensive reporting, you increase employee knowledge and have access to the documentation required for audits, certification programmes and compliance accountability.

AwareShield supports, among others, the following ISO 27701 controls:

  • Control 7.2.2 – Privacy and personal data awareness, education and training
  • Control 7.3.2 – Assignment of privacy-related roles and responsibilities
  • Control 7.4.1 – Privacy management and protection of personal data
  • Control 7.4.6 – Privacy risk management
  • Control 7.4.7 – Notification processes for privacy and security incidents
  • Control 8.2.1 – Secure processing and protection of personal data
  • Control 8.2.8 – Support for data subject rights

With training on privacy, GDPR, data processing, data breaches, phishing, social engineering, AI usage and the secure handling of personal data, AwareShield helps organisations reduce privacy risks and address key elements of ISO 27701.

TISAX

Information security in the automotive supply chain starts with aware employees

TISAX (Trusted Information Security Assessment Exchange) is the information security standard for the automotive sector and is used by manufacturers, suppliers and service providers to demonstrate information security. In addition to technical security measures, TISAX also includes requirements for employee awareness, training and secure behaviour.

AwareShield helps organisations demonstrably meet these requirements. With Security Awareness training, Compliance modules, practical Use Cases, Phishing simulations and comprehensive reporting, you increase employees' security awareness and have access to the documentation required for TISAX assessments, audits and customer requirements.

AwareShield supports, among others, the following TISAX controls:

  • Control 6.3 – Information security awareness, education and training
  • Control 5.1 – Information security policy
  • Control 5.10 – Acceptable use of information and organisational assets
  • Control 5.17 – Authentication information and password management
  • Control 6.7 – Secure remote working and working from home
  • Control 6.8 – Reporting information security incidents
  • Control 8.1 – Secure use of workstations and end-user devices

With training on phishing, social engineering, information classification, secure data sharing, passwords, MFA, AI usage, remote working and incident reporting, AwareShield helps organisations strengthen the human factor within TISAX in a structured manner and demonstrably comply with key information security requirements from customers and supply chain partners.

PCI DSS

The secure handling of payment card data starts with employees

PCI DSS helps organisations protect payment card data and prevent fraud. In addition to technical security measures, the standard also requires employees to be aware of security risks and understand how to handle sensitive payment and customer data securely. Awareness and training therefore play an important role within a successful PCI DSS programme.

AwareShield helps organisations demonstrably fulfil these obligations. With Security Awareness training, Compliance modules, practical Use Cases, Phishing simulations and comprehensive reporting, you increase employees' security awareness and have access to the documentation required for audits, assessments and compliance accountability.

AwareShield supports, among others, the following PCI DSS requirements:

  • Requirement 8 – Strong authentication and secure use of passwords
  • Requirement 9 – Awareness of the physical security of systems and data
  • Requirement 12.6 – Security Awareness Programme for employees
  • Requirement 12.6.1 – Awareness of security policies and procedures
  • Requirement 12.6.2 – Training in recognising and reporting security incidents
  • Requirement 12.6.3 – Training on current cyber threats and attack techniques
  • Requirement 12.10 – Incident response and reporting procedures

With training on phishing, social engineering, password management, MFA, data protection, AI usage, payment card data and incident reporting, AwareShield helps organisations strengthen the human factor within PCI DSS in a structured manner and demonstrably meet key security awareness requirements.

EIC 62443

Industriële cybersecurity begint bij bewuste medewerkers.

a { text-decoration: none; color: #464feb; } tr th, tr td { border: 1px solid #e6e6e6; } tr th { background-color: #f5f5f5; }

IEC 62443 is the international standard for the security of industrial automation and control systems (OT/ICS). While the standard places significant emphasis on technical security measures, employees play a crucial role in preventing incidents. Recognising cyber threats, using systems securely and reporting incidents correctly are essential for maintaining a secure and reliable operational environment.

AwareShield helps organisations in manufacturing, industry, energy, logistics and critical infrastructure demonstrably meet these requirements. With Security Awareness training, Compliance modules, practical Use Cases, Phishing simulations and comprehensive reporting, you increase employees' cybersecurity awareness and have access to the documentation required for audits, assessments and compliance programmes.

AwareShield supports, among others, the following IEC 62443 topics:

  • SR 1.1 – User identification and authentication
  • SR 1.2 – User account management
  • SR 1.3 – Secure authentication and password management
  • SR 2.8 – Cybersecurity risk awareness
  • SR 6.1 – Protection against malware
  • SR 6.2 – Security update and vulnerability management
  • SR 6.3 – Secure use of systems and applications
  • SR 7.6 – Cybersecurity incident reporting and handling

With training on phishing, social engineering, OT security, the secure use of industrial systems, passwords, MFA, USB risks, physical security and incident reporting, AwareShield helps organisations strengthen the human factor within industrial cybersecurity in a structured manner.

Up for a good conversation? So are we!

Please fill out this form to contact us.