Human decisions can contribute to security incidents: an ill-timed click, a shared password or an unquestioningly approved payment. A security-aware culture complements technical controls. It develops through leadership behaviour, repeated practice and clear expectations. This article explores management’s role, the value of targeted learning and the link to NIS2 accountability.
Why is annual compliance training not enough?
Course completion alone does not demonstrate safe behaviour. A generic annual module can fulfil an administrative requirement without developing practical habits. People need relevant examples and opportunities to practise applying the rules.
An effective programme is:
- continuous, using short, recurring learning activities;
- practical, including simulations to develop recognition and response;
- role-specific, reflecting different threats for accountants, developers and executives;
- measurable, so improvement is supported by evidence.
The aim is for people to make sound decisions at critical moments, even when no one is watching.
Why does security culture start with leadership?
People judge priorities by how management behaves. This is the principle of “tone from the top”. A policy requiring multifactor authentication loses credibility if executives exempt themselves or treat security procedures as an inconvenience.
Leadership commitment becomes visible through four channels:
- Example: managers follow the same rules as everyone else.
- Resources: training, tools and staff receive appropriate time and funding.
- Accountability: security is reflected in objectives and responsibilities across the business.
- Communication: leaders regularly explain security as a business priority.
Without these foundations, even strong training material has limited effect.
Why should training differ by role?
Different roles face different threats, risks and decisions. A useful programme distinguishes at least three audiences:
| Audience | Learning focus | Typical threats |
|---|---|---|
| All employees | Phishing recognition, password hygiene, data handling, device use and reporting | Social engineering and accidental data disclosure |
| IT and development teams | Secure development, access, logging, patching and response | Misconfiguration, vulnerabilities and misuse of privileges |
| Senior management | Risk accountability, approvals, NIS2 obligations and crisis communication | CEO fraud, targeted attacks and strategic risk |
Why a separate executive module?
Executives are both valuable targets and influential decision-makers. Targeted fraud can cause financial and reputational damage, while NIS2 places explicit accountability on management. Executive training should focus on risk, decisions and legal responsibilities rather than technical configuration.
What does management need to understand?
Leaders need enough knowledge to oversee the security programme meaningfully:
- the organisation’s most important information assets and principal risks;
- their own approval and decision-making responsibilities;
- incident reporting procedures and deadlines;
- relevant obligations under NIS2, sectoral rules and ISO/IEC 27001;
- the basics of crisis communication.
This allows them to supervise implementation as well as approve the programme.
How can security culture be measured?
Measure behaviour and attitudes alongside completion rates. Useful indicators include:
- simulated phishing click and reporting rates over time;
- numbers of incident and suspicion reports, where an increase may indicate greater attention and trust;
- time between recognising a concern and reporting it;
- training coverage and repetition by audience;
- anonymous surveys of security attitudes;
- policy knowledge and learning assessment results.
Treat results as trends. Cultural change takes time and needs ongoing feedback.
How does this relate to NIS2 and the security officer?
NIS2 explicitly requires management oversight and includes training within risk management measures. Management bodies approve cybersecurity measures, oversee implementation and undertake cybersecurity training themselves. Signing a policy is only one part of the responsibility.
Failures may result in regulatory action and fines, depending on classification, the infringement and applicable Hungarian rules. Traceable actions and active oversight matter.
The Information Security Officer helps design, segment, deliver and measure the programme, giving management clear, decision-ready reports. Learning becomes part of the management system. Our in-house versus outsourced guide explores how to provide that role.
How zemITis helps
Our CISA, CISM and ISO 27001 / 42001 Lead Auditor specialists create role-specific programmes, measure progress through simulated phishing and provide an executive module covering NIS2 responsibilities.
Explore our security officer service and NIS2 preparation, or book a free consultation to assess your starting point and develop a programme supported by leadership.