Contact us

BOOK A PRESENTATION

Beyond Compliance: The Role of People in NIS2

October 5, 2026
NO NAME
By Dubravko Kovačić, Product Manager at ASEE

When cybersecurity is discussed at the organizational level, the conversation often starts with technology. Firewalls, endpoint protection, identity management, encryption, monitoring, incident response. The list is long, and for good reason. Technology is fundamental to protecting modern organizations.

But technology does not operate in isolation.

Behind every security control is a person who configures it, uses it, maintains it, responds to its alerts, or decides what to do when something goes wrong. And on the other side of many attacks is another person: someone who receives a convincing phishing email, approves a fraudulent login request, shares sensitive information with the wrong person, or simply does not recognize that something is unusual.

This is one of the reasons the human side of cybersecurity deserves more attention under the NIS2 Directive.

The human factor is part of the security equation

It is tempting to describe people as the weakest link in cybersecurity. I think that is too simplistic.

People can certainly introduce risk. But they can also identify threats, stop suspicious activity, report incidents early and help an organization recover when something goes wrong. The difference often comes down to whether they have the knowledge, tools and processes to do so.

Consider a phishing attempt. The technical controls surrounding an employee may be highly sophisticated, but eventually there may still be a moment when a person has to decide whether an email is legitimate, whether a login request makes sense or whether an unexpected attachment should be opened.

The same applies to social engineering, credential theft and other attacks that rely on manipulating human behavior.

This is why cybersecurity awareness should not be treated as an isolated training exercise. It is part of an organization's broader risk management approach.

NIS2 reflects this idea by taking a much broader view of cybersecurity. The Directive requires essential and important entities to implement appropriate and proportionate technical, operational and organizational measures to manage cybersecurity risks. It also specifically addresses governance and cybersecurity training.

In other words, the human element is not outside the security framework. It is part of it.

What NIS2 says about people

One of the clearest examples is Article 20, which addresses the role of management bodies.

Under NIS2, management bodies of essential and important entities are responsible for approving cybersecurity risk-management measures and overseeing their implementation. Members of these management bodies must also undergo cybersecurity training, while organizations are encouraged to provide similar training to employees on a regular basis.

Cybersecurity responsibility is no longer something that can simply be delegated downward to the security department. Leadership needs to understand the risks the organization is managing and the impact those risks can have on the services it provides.

The Directive also explicitly includes cybersecurity training and basic cyber hygiene among the measures organizations need to consider. Its broader approach encompasses practices such as identity and access management, user awareness, training, and awareness of threats including phishing and social engineering.

The important point, however, is not simply that organizations need to provide training.

It is what that training is supposed to achieve.

The objective is not to create employees who can recite a cybersecurity policy. It is to create people who can recognize risk, make informed decisions and know how to respond when something does not look right.

From security training to security culture

There is a big difference between security awareness and security culture.

An employee might know that phishing exists. That does not necessarily mean they will recognize a sophisticated phishing attempt when it arrives in their inbox.

They might know that passwords should be protected. That does not necessarily mean they will recognize a social engineering attempt designed to obtain their credentials.

They might know that incidents should be reported. But if the reporting process is unclear, slow or intimidating, they may still hesitate when they encounter something suspicious.

This is where organizations need to move beyond the idea of cybersecurity training as an annual checkbox.

A stronger approach is continuous and practical. It means reinforcing good security practices through regular communication, relevant training, realistic scenarios and clear processes for reporting suspicious activity. It means making security part of onboarding and everyday work rather than something employees hear about once a year.

Most importantly, it means creating an environment where reporting a mistake or a suspicious event is encouraged.

If an employee clicks on a malicious link but immediately reports it, the organization has an opportunity to contain the incident. If that employee is afraid of being blamed and says nothing, a relatively small security event can have much greater consequences.

A mature security culture therefore isn't about expecting people never to make mistakes. It is about making sure that when mistakes or suspicious situations happen, people know what to do next.

Leadership sets the tone

This is also why the role of management under NIS2 matters.

A security culture cannot be created by the security team alone.

Leadership determines which activities receive resources, how seriously security risks are treated and whether cybersecurity is considered part of business resilience or simply an IT concern.

When management participates in security training, asks meaningful questions about cyber risk and treats security as an organizational responsibility, that sends a much stronger message than another mandatory training email ever could.

The same principle applies to accountability. Employees need to understand their responsibilities, but organizations also need to give them the tools and processes required to meet those responsibilities.

You cannot ask people to make better security decisions while giving them inadequate authentication controls, unclear reporting procedures or systems that make secure behavior unnecessarily difficult.

Security awareness and security technology therefore need to reinforce one another.

People should not have to carry the burden alone

There is another side to this conversation that is sometimes overlooked.

Making people part of the security strategy does not mean expecting employees to identify every threat themselves.

Technology should make secure decisions easier.

Strong authentication can reduce the impact of compromised credentials. Application security controls can protect against threats that users may never see. Monitoring and detection capabilities can identify suspicious behavior. Fraud and spoofing protection can help organizations address attacks designed specifically to manipulate users.

The goal should not be to create employees who can defend an organization against every possible attack.

The goal is to build an environment where people, processes and technology work together to reduce risk.

That is ultimately a more realistic approach to cybersecurity. Humans will make mistakes. Attackers will adapt. New technologies will introduce new risks as well as new opportunities. A resilient organization is one that anticipates this rather than assuming that either its technology or its people will always get everything right.

Beyond compliance

It is easy to look at NIS2 as another regulatory deadline and another checklist of controls to implement.

But compliance is only the starting point.

The more interesting question is what organizations do with the framework once the immediate compliance work is complete.

  • Do employees understand the risks relevant to their roles?
  • Do they know how to recognize and report suspicious activity?
  • Does management understand cybersecurity well enough to make informed decisions?
  • Are security processes actually usable in day-to-day work?
  • And when something goes wrong, does the organization know how to respond?

These are questions that cannot be answered by technology alone.

NIS2 provides organizations with a regulatory framework for strengthening cybersecurity resilience. But resilience ultimately depends on how that framework becomes part of everyday behavior.

That is why cybersecurity awareness should not be limited to a month, a training session or a compliance exercise.

Cybersecurity is something people practice every day.

The organizations that recognize this will be better positioned not only to meet regulatory requirements, but to build security into the way they operate, turning compliance from an end goal into a foundation for long-term resilience.

ASEE Cybersecurity Awareness Month

This article is part of our Cybersecurity Awareness Month series.

Find the full series on our Blog.

Stay informed. Stay secure.

Want to learn more about cybersecurity trends and industry news?

SUBSCRIBE TO OUR NEWSLETTER

CyberSecurityhub

chevron-down linkedin facebook pinterest youtube rss twitter instagram facebook-blank rss-blank linkedin-blank pinterest youtube twitter instagram