NISG 2026 course All courses

Lesson 4.6 · 5 min

Cyber hygiene and training

Open in the coursewith narrated slides, a checklist to tick off and a quiz

At a glance

In detail

What the act requires

The minimum elements include basic cyber hygiene practices and cyber security training § 32(4)(g) NISG 2026. Entities must also offer their staff training regularly so that they can recognise and assess risks § 31(2) NISG 2026; the management's own training duty from lesson 3.1 comes on top.

The awareness programme

Under the EU catalogue § 2 NISV 2026 the entity makes sure its staff, including the management, and its direct suppliers are aware of the risks and practise cyber hygiene. To do so it offers an awareness programme that (Implementing Regulation (EU) 2024/2690, Annex point 8.1):

This also means training the team regularly in how to report anything suspicious (Annex point 3.3.2), and making sure everyone understands and follows the cyber hygiene rules (point 10.1.2).

Training for security-relevant roles

Staff whose roles need security skills are trained regularly, under a programme that sets the needs for each role. The training fits the job, its effectiveness is assessed, and it covers the secure configuration and operation of systems including mobile devices, known threats and what to do in security events; anyone moving into such a role is trained (Annex point 8.2).

What "cyber hygiene" means day to day

The act gives no exhaustive list. Typical content, as examples: install updates promptly; use MFA; recognise phishing and report it rather than delete it; a password manager instead of reusing passwords; lock the screen; no unknown USB sticks; store data only in approved services; call back on unusual payment instructions.

Proving it

Failing to provide training for the management or for staff is an administrative offence § 45(1) nos. 1 and 2 NISG 2026. As proof, the Federal Office names among other things certificates and records of training and awareness measures (Federal Office, FAQ on measures): who, when, what content, with what result.

Checklist

Quiz

Whom should the awareness programme reach under the EU catalogue?

  1. All staff including the management, and direct suppliers where appropriate
  2. Only staff who work at screens
  3. Only new staff
  4. Only the IT department
Show the answer

The answer is A: All staff including the management, and direct suppliers where appropriate. Implementing Regulation (EU) 2024/2690, Annex points 8.1.1 and 8.1.2, through § 2 NISV 2026.

Sources

This lesson's statements rest on:

Not legal advice. What counts is the NISG 2026 and the NISV 2026 in the Federal Legal Information System and Implementing Regulation (EU) 2024/2690 (read on 6 October 2026). Not covered are the special rules for banks and financial entities (DORA), for critical entities under the RKE Act, for domain name registration services and for the public administration. Not an offer of the Federal Office for Cyber Security, a CERT or the Chamber of Commerce.