Skip to content
NIS2 Made Staff Training a Legal Duty. The Evidence Says Most of It Does Not Work.
Training & Exercises

NIS2 Made Staff Training a Legal Duty. The Evidence Says Most of It Does Not Work.

Admin User
·
Aug 06, 2026
·
10 min read

The Line Item You Are About to Approve

Somewhere in the NIS2 gap analysis sitting on your desk there is a line that reads something like "cybersecurity training for the management body and all staff." It is one of the cheapest-looking items on the list. A per-seat licence for an e-learning platform, a library of five-minute video modules, a quarterly simulated phishing campaign, an automatic reminder to anyone who has not completed their annual module. Twenty euros a head, a signature, and the gap closes.

Before you sign it, it is worth knowing what the research says about that exact product. The largest controlled study of enterprise anti-phishing training ever conducted was published at the 2025 IEEE Symposium on Security and Privacy by a team from UC San Diego. It followed more than 19,500 employees at UC San Diego Health across eight months and ten simulated phishing campaigns. It measured two things almost every organisation in Luxembourg is about to buy: mandatory annual cybersecurity awareness training, and embedded anti-phishing training, the short lesson that appears when someone clicks a simulated phish.

Annual awareness training showed no significant relationship with whether an employee failed a phishing simulation. Employees who had completed it within the past month performed no better than employees who were more than a year overdue. Embedded training performed better than nothing, but only just: it reduced the likelihood of clicking by roughly 1.7 percentage points on average.

That is the honest baseline. It does not mean training is worthless, and it certainly does not mean you can skip it, because in Luxembourg you now legally cannot. It means the default version of it is a compliance artefact rather than a control, and if you buy it believing otherwise, you will have paid for a false sense of security on top of a real legal obligation.

What Luxembourg Law Actually Requires

The Law of 5 May 2026 on measures to ensure a high level of cybersecurity transposed NIS2 into Luxembourg law and entered into force on 10 May 2026. In-scope entities, broadly those with 50 or more employees or annual turnover above €10 million operating in one of eighteen listed sectors, had until 10 July 2026 to self-register with their competent authority, in most cases the Institut Luxembourgeois de Régulation. Failure to register is itself a sanctionable breach, so if that date passed without anyone in your organisation confirming your position, that is the first conversation to have.

On training specifically, two obligations matter and they are not the same obligation.

The first is governance. Under Article 20 of the Directive, management bodies must approve the cybersecurity risk-management measures the entity takes, oversee their implementation, and can be held liable for the entity's failures. Members of those management bodies are required to follow training so that they gain sufficient knowledge and skills to identify risks, assess the organisation's cybersecurity risk-management practices, and understand their impact on the services the entity provides. Entities are, in turn, expected to offer similar training to employees on a regular basis. Sanctions are not limited to fines: national authorities can impose temporary bans on individuals exercising management functions.

The second is operational. Cyber hygiene practices and cybersecurity training appear as one of the ten mandatory categories of risk-management measures, sitting alongside risk analysis, incident handling, business continuity, supply-chain security, access control and multi-factor authentication. All ten apply to essential and important entities alike. The supervisory difference is in how they are checked: essential entities face both proactive and reactive supervision, important entities only reactive, which in practice means the first serious look at an important entity's training records often happens after an incident notification. Administrative fines run up to €10 million or 2% of worldwide annual turnover for essential entities, and up to €7 million or 1.4% for important entities.

Read those two obligations carefully and you will notice something the e-learning brochure does not mention. The board-level obligation is about judgement: can these people assess whether the organisation's security measures are adequate? A twenty-minute video on recognising suspicious links does not produce that, and no auditor examining a director's competence will accept a completion certificate as evidence of it. If you have not yet mapped your obligations end to end, our NIS2 compliance service for Luxembourg organisations and our earlier practical NIS2 guide for SMEs cover the wider scope question.

Why the Standard Programme Fails

The UC San Diego data explains the failure mechanism clearly enough that it is worth being specific.

Roughly three-quarters of employees who landed on an embedded training page spent a minute or less on it, and about a third closed it immediately without engaging with the material at all. This is not a story about careless staff. It is a story about what an interruption feels like when you are mid-task: the training appears at the exact moment the employee has been told they made a mistake, is embarrassed, and wants to get back to work. The instructional design fights the moment it was designed for.

The second finding is the one that should reset your expectations permanently. In the first month of the study, about 10% of employees clicked a simulated phishing link. By the eighth month, more than half had clicked at least once. Given enough attempts and enough time, almost everyone eventually clicks something. That is not a training gap you can close. It is a property of human attention under workload, and any programme whose success depends on eliminating it is going to fail.

Design for the click, not against it. Assume that a competent, well-meaning employee will eventually click a malicious link or approve a fraudulent request. Your programme's job is to make that moment survivable and recoverable, not to make it impossible.

The researchers' own conclusion pointed the same way: shift the burden off the user and onto technical countermeasures. They singled out two in particular, hardware and application-based two-factor authentication, and password managers that only autofill on the correct domain. Both work by removing the requirement for a human to notice something subtle at the wrong moment.

There is field evidence behind that. Google moved its workforce of more than 85,000 employees to mandatory FIDO security keys in early 2017 and has since reported no successful phishing of employee work accounts. The mechanism is not persuasion. A FIDO authenticator is bound to the legitimate domain, so a credential captured on a lookalike site cannot be replayed against the real one. The employee can be fully deceived and the attack still fails.

What to Build Instead

None of this argues for skipping training. It argues for putting the effort where it changes an outcome, and keeping the paperwork the ILR needs as a by-product rather than the goal.

1. Spend the security budget on authentication before content

Multi-factor authentication is already one of the ten mandatory measure categories, so this is not an optional extra you are trading against training. It is a requirement you have to meet anyway, and the version you choose determines whether phishing remains a live risk. Phishing-resistant methods, FIDO2 security keys or passkeys, resist credential relay and adversary-in-the-middle attacks in a way that SMS codes, one-time passcodes and push approvals do not. Start with the accounts that carry the most damage: administrators, finance and payment approvers, email accounts with delegated access, and anything reachable from the internet. Critically, remove the weaker fallback methods for those accounts. A phishing-resistant primary with an SMS backup is an SMS control.

2. Measure reporting, not clicking

Click rate is the metric every awareness platform sells because it is the one that improves fastest and matters least. The number that predicts how an incident actually goes is how quickly someone tells you. Make reporting a one-click action in the mail client, never punish the person who reports, and publish two figures to management: what proportion of a simulated campaign was reported, and the median time from first delivery to first report. If your median is measured in hours, your detection depends on luck. If it is measured in minutes, your staff are functioning as sensors, which is the only role in this system where humans genuinely outperform software.

3. Train the roles that carry the risk, properly

Generic annual modules treat a warehouse supervisor and a payments clerk as the same risk. They are not. Concentrate real training time, with real scenarios, on the small number of roles where a single bad decision is expensive: finance staff who can move money, administrators who hold privileged credentials, HR staff who handle personal data, developers who ship code, and anyone with access to customer systems. For those roles, an hour of specific, plausible, locally relevant scenarios beats twelve months of general content. The patterns we see across the Greater Region, and which we described in our analysis of social engineering attacks in the Greater Region, are worth building those scenarios around, because attackers here reuse local context: real supplier names, cross-border payroll quirks, the multilingual switching that makes an odd phrasing seem unremarkable.

4. Give the management body decision practice, not a video

The Article 20 obligation is about the board's ability to assess and approve. The format that produces that is a facilitated exercise where the management body has to make real decisions under incomplete information: do we notify the ILR within 24 hours on what we currently know, do we take the customer portal offline, who speaks to the press, do we pay. Two hours of that reveals more about your governance than any assessment, and it produces exactly the kind of documented, dated, minuted evidence a supervisor will ask for. We have written before about how to run a crisis simulation, and the same approach adapts directly to the NIS2 governance obligation. For technical teams, the equivalent is hands-on work in a realistic environment rather than a slide deck, which is what our cyber range exercises are built for.

5. Keep the evidence an auditor can actually read

Whatever you run, record it in a form that survives a supervisor's question two years later: who attended, when, what was covered, what decisions the management body took as a result, and what changed afterwards. Board minutes recording approval of the risk-management measures, dated attendance records for management training, and a short written summary of each exercise's findings and follow-up actions are worth more than a dashboard showing 98% module completion. Completion rates prove people opened a page. Minutes and remediation actions prove the organisation is governed.

The Uncomfortable Reframe

The reason this matters beyond compliance is that the standard programme creates a specific and dangerous illusion. When the dashboard shows a falling click rate, the organisation concludes its people are the defence and quietly deprioritises the controls that would actually contain an incident. Then a well-crafted request arrives on a Friday afternoon, someone reasonable approves it, and the post-incident review discovers that nothing behind that person was designed to catch it.

The organisations that handle this well have made a quiet but decisive shift. They train their management bodies to govern, train their high-risk roles on scenarios that could plausibly happen to them, make reporting effortless, and then put their real money into authentication, segmentation, monitoring and rehearsed response, so that the inevitable click is contained rather than catastrophic. That combination satisfies the law and reduces the risk, in that order of paperwork and that order of importance.

If you are working through your NIS2 measures now and want a training programme built on this basis rather than a licence you renew annually, we can help you design it, run the management-body exercises, and produce the documentation your supervisor will ask for. Our security training services in Luxembourg cover the full range, from board-level exercises to role-specific technical work. Get in touch and we will start with an honest review of what you already have and where it will not hold.

NIS2 training security awareness training phishing simulation NIS2 Luxembourg ILR cybersecurity training management body training phishing-resistant MFA cyber hygiene staff training
A

Admin User

Author

Related Posts

CONTACT US

Get in Touch with Us

At Obsidiancorps, we fuse innovative technology with trusted security practices to create tailored solutions that protect and elevate your business. Reach out and let's secure a brighter future together.

Phone Number

+352 691 165 856

Email Address

info [at] obsidiancorps.com

Location

Differdange, Luxembourg

We typically respond within 24 hours

Send Us a Message

We'd love to hear from you! Fill out the form below and our team will get back to you as soon as possible.

captcha