INTRA/AW/AW001Workforce awareness on insider risk
The instruction of the workforce in what the program is, what it asks of them, and what it protects.
| Control | Jurisdiction | Source | What it establishes | Prerequisite or recommendation |
|---|---|---|---|---|
| AW001/EUMandatory | European Union | Directive (EU) 2022/2555, article 21European Parliament and Council · read 29 Aug 2026Commission Implementing Regulation (EU) 2024/2690European Commission · read 29 Aug 2026 | That asset management, access control policies, human resources security, cryptography, and training are among the measures an entity in scope has to take, without saying what any of them holds. | Basic cyber hygiene practices and cybersecurity training are named among the measures an entity in scope has to take, and the implementing rules say what the awareness program holds: it is scheduled over time so that it repeats and reaches new employees, it covers the threats, the measures in place, and where to go for advice, it reaches direct suppliers and service providers as well as employees and the members of the management bodies, and it is tested for effectiveness where appropriate. What is asked to be taught is the security of systems, not insider risk. |
| AW001/ITMandatory | Italy | Determinazione ACN n. 379907 del 18 dicembre 2025Agenzia per la cybersicurezza nazionale · read 29 Aug 2026 | The baseline security measures an Italian NIS subject has to adopt, among them the recording of remote and administrative access and its central retention, the detection of privilege abuse, and the vetting of the people admitted to the systems that matter. | For a subject in the national NIS register, a training plan for the workforce, the administrative and management bodies included, is defined, implemented, kept current, and documented, and those bodies approve it. It sets out what is taught and, where any are provided for, how it is checked that the content was taken in. What it teaches is the security of systems, not insider risk. |
| AW001/ESMandatory | Spain | Real Decreto 311/2022, Esquema Nacional de SeguridadGobierno de España · read 29 Aug 2026 | The security measures a Spanish public sector body has to apply, graded by category, among them the concurrence of two people on critical tasks so that no single authorized individual can abuse their rights, an access control on the activity records themselves, and the recording of evidence where an incident may end in disciplinary action. | The workforce is reminded periodically of the security rules on the proper use of the equipment and of the commonest social engineering techniques, of how to identify an incident and the activities or behaviors that are suspicious and have to be reported so that specialized staff can deal with them, and of the procedure for reporting, whether what is reported turns out to be real or a false alarm. |
| Recommended | European Unionwhere written | Help2ProtectCoESS and partners, co-funded by the Internal Security Fund of the European Union · read 11 Aug 2026 | Awareness and program-building material for critical infrastructure operators, with templates, and no legal basis stated for any of it. | A Union-funded platform carries an awareness module and downloadable templates, addressed mainly to transport, energy, and other critical infrastructure operators. |
| Recommended | European Unionwhere written | Insider Threat Program Development ManualCoESS, co-financed by the Internal Security Fund of the European Union · read 11 Aug 2026 | The structure of an insider risk management program, as the closest thing to doctrine issued under European Union funding, unrevised since 2019. | The Union-funded manual addresses the structure of a program rather than the conditions attached to one, and has not been revised since 2019. |
| Recommended | Belgiumwhere written | CyberFundamentals 2025, EssentialCentre for Cybersecurity Belgium · read 29 Aug 2026 | What the Belgian centre sets out for the heaviest of its assurance levels, and the only place in this record where a national authority names the insider as something the detection tools are there to catch. | Insider threat awareness and reporting are to be included in the security training, by name, so that people can recognize and respond to internal risks. What the training covers is set out: how to recognize the behavioral signs, what an insider threat is, how and where to report suspicious activity and why reporting in time matters, and real cases or simulations used to show what an insider event costs. It reaches all staff, at onboarding and in the regular training, with an annual refresher. |
| Recommended | Netherlandswhere written | Baseline Informatiebeveiliging Overheid 2, versie 1.3Nederlandse overheid · read 29 Aug 2026 | The government measures Dutch public bodies add on top of the two information security standards, among them a screening policy, a detection use case named in the text, and a log retention set against the scenario that an attacker has been inside for a long time. | Everyone using the information systems, employees and contractors alike, has demonstrably completed an awareness training within three months of entering service. Management is to press the importance of it at appointment and at an internal transfer, and in work meetings and personnel discussions, and to encourage it being taken again periodically. |
| Recommended | Norwaywhere written | NSMs grunnprinsipper for IKT-sikkerhet 2.1Nasjonal sikkerhetsmyndighet · read 29 Aug 2026 | A set of principles for securing information systems, with the monitoring ones carrying what the collected data may be used for, what employees are to be told about it, and the requirement to verify that the collection is working. | Real cases from the handling of incidents are to be used in the training and the raising of awareness of staff, and the results of an evaluation are shared with those they concern. |
| Recommended | United Kingdomwhere written | Insider Risk Mitigation Digital LearningNPSA · read 12 Aug 2026 | The mitigation framework taught in nine modules, with governance and leadership set as the foundation of personnel security. | Awareness is delivered as a course rather than a notice, in modules of ten to twenty minutes, with governance and leadership taught before the controls. |
