Measure 5 of Annex II requires basic cyber hygiene practices and staff awareness raising. Most organisations satisfy it with an annual presentation and a list of signatures.
It formally passes. Behaviour does not change, and the next incident arrives through the same channel as the last one.
Why conventional training fails
It teaches signals that have disappeared
Material that teaches people to spot phishing by poor language and a strange address is out of date. Language errors are no longer a signal - messages are grammatically flawless and tailored to the recipient. What remains as a signal is context: an unexpected request, time pressure, a change of channel, a request for an exception to a rule.
It measures attendance, not behaviour
Records answer who was present. They do not answer whether that person would act differently. Those are different things, and only the second one shows up in an incident.
It punishes reporting
This is the biggest problem and the least discussed. In an organisation where the person who clicks a phishing link faces ridicule or a conversation with their manager, nobody will report next time - they will stay quiet and hope. Time to detection is then measured in weeks rather than minutes.
Ask a few staff: "If you had clicked a suspicious link yesterday, who would you tell and what do you think would happen?" The answer to the second half tells you more about your resilience than any training record.
What actually changes behaviour
- Short and frequent, instead of long and once. Fifteen minutes a quarter with one concrete scenario beats two hours once a year.
- Simulations with feedback, not consequences. Whoever clicks gets an explanation immediately, in place. Results are reported in aggregate, never per person.
- Reporting is rewarded. Anyone who reports a suspicious message, even one that turns out harmless, should be told they did the right thing. It is the only lever that shortens time to detection.
- Roles get their own content. Finance needs to know about bank detail change fraud, IT about attacks on privileged accounts, the board about fake executive instruction fraud.
- A procedure instead of vigilance. "Be careful with payments" does not work. "Any payment above X, or any change of bank details, is confirmed by telephone on the number in our register, never the number in the email" does work, because it does not depend on one person's judgement under pressure.
What to measure
| Instead of | Measure |
|---|---|
| Percentage of staff who completed training | Share of simulated messages reported |
| Quiz score | Average time to first report |
| Number of sessions held | Reports from teams that never reported before |
| Training satisfaction score | Share of payments verified through a second channel |
The left column satisfies the record. The right column shows whether resilience is changing.
The link to your obligations
Awareness raising falls under measure 5, and Article 29(3) of the Act requires responsible individuals to attend appropriate training themselves. In addition, Article 4 of the AI Act requires a sufficient level of AI literacy for staff operating AI systems.
All three require records. The good news is that a programme which genuinely changes behaviour produces richer records than one that does not, because it has more touchpoints across the year.
Role-based workshops - for the board, for IT and for all staff - are described on the Lectures and workshops page. Each produces records that satisfy measure 5.
Sources
Not sure where you stand?
Half an hour of conversation, with no obligation. By the end you know what needs doing and in what order.