Lesson 4.6 · 5 min
Cyber hygiene and training
Open in the coursewith narrated slides, a checklist to tick off and a quiz
At a glance
- An awareness programme. For all staff, the management included, and for direct service providers where appropriate. Repeated, and planned so that it reaches newcomers.
- Threats, rules, contacts. Current threats, your own measures, whom to turn to and the cyber hygiene rules for everyday work.
- Specialist training for security-relevant tasks. Whoever runs or administers systems gets training in secure configuration, known threats and what to do in an incident.
- Check that it lands. Awareness and training are tested for effectiveness and adjusted to the threat situation.
- Record who learned what and when. Failing to provide training risks the high fine range. Attendance lists and content are the simplest proof.
In detail
What the act requires
The minimum elements include basic cyber hygiene practices and cyber security training § 32(4)(g) NISG 2026. Entities must also offer their staff training regularly so that they can recognise and assess risks § 31(2) NISG 2026; the management's own training duty from lesson 3.1 comes on top.
The awareness programme
Under the EU catalogue § 2 NISV 2026 the entity makes sure its staff, including the management, and its direct suppliers are aware of the risks and practise cyber hygiene. To do so it offers an awareness programme that (Implementing Regulation (EU) 2024/2690, Annex point 8.1):
- is scheduled so that it is repeated and reaches new staff;
- fits the security policy and your own procedures;
- covers current threats, the existing measures, contacts and the cyber hygiene rules;
- is tested for effectiveness where appropriate and updated for the threat situation and procedures.
This also means training the team regularly in how to report anything suspicious (Annex point 3.3.2), and making sure everyone understands and follows the cyber hygiene rules (point 10.1.2).
Training for security-relevant roles
Staff whose roles need security skills are trained regularly, under a programme that sets the needs for each role. The training fits the job, its effectiveness is assessed, and it covers the secure configuration and operation of systems including mobile devices, known threats and what to do in security events; anyone moving into such a role is trained (Annex point 8.2).
What "cyber hygiene" means day to day
The act gives no exhaustive list. Typical content, as examples: install updates promptly; use MFA; recognise phishing and report it rather than delete it; a password manager instead of reusing passwords; lock the screen; no unknown USB sticks; store data only in approved services; call back on unusual payment instructions.
Proving it
Failing to provide training for the management or for staff is an administrative offence § 45(1) nos. 1 and 2 NISG 2026. As proof, the Federal Office names among other things certificates and records of training and awareness measures (Federal Office, FAQ on measures): who, when, what content, with what result.
Checklist
- We have an awareness programme with fixed dates that also reaches newcomers when they join.
- The management takes part in the programme, on top of its own training.
- Whoever runs or administers systems has role-specific training.
- We check that training works, for example with a phishing exercise or a short test.
- Attendance and content are documented.
Quiz
Whom should the awareness programme reach under the EU catalogue?
- All staff including the management, and direct suppliers where appropriate
- Only staff who work at screens
- Only new staff
- Only the IT department
Show the answer
The answer is A: All staff including the management, and direct suppliers where appropriate. Implementing Regulation (EU) 2024/2690, Annex points 8.1.1 and 8.1.2, through § 2 NISV 2026.
Sources
This lesson's statements rest on:
- Network and Information System Security Act 2026 (NISG 2026) § 31, Federal Legal Information System (RIS), in German, version of 6 October 2026
- Network and Information System Security Act 2026 (NISG 2026) § 32, Federal Legal Information System (RIS), in German, version of 6 October 2026
- Network and Information System Security Act 2026 (NISG 2026) § 45, Federal Legal Information System (RIS), in German, version of 6 October 2026
- Network and Information System Security Regulation (NISV 2026) § 2, RIS, in German, version of 6 October 2026
- Implementing Regulation (EU) 2024/2690, Art. 2 and Annex, EUR-Lex (also in English)
- Federal Office for Cyber Security, FAQ: measures, in German (read on 6 October 2026)
Not legal advice. What counts is the NISG 2026 and the NISV 2026 in the Federal Legal Information System and Implementing Regulation (EU) 2024/2690 (read on 6 October 2026). Not covered are the special rules for banks and financial entities (DORA), for critical entities under the RKE Act, for domain name registration services and for the public administration. Not an offer of the Federal Office for Cyber Security, a CERT or the Chamber of Commerce.