Industries in Focus

Cyber Security Awareness Training: Scientific Foundations, NIS2 Obligations & Implementation | DeeplySecure

Cyber Security Awareness Training: Scientific Foundations, NIS2 Obligations & Implementation | DeeplySecure

Cyber Security Awareness Training: Scientific Foundations, NIS2 Obligations & Implementation | DeeplySecure

Last updated:

8 min.

Dr. Dr. Fabian Teichmann is a lawyer, researcher, and one of the leading experts on cybersecurity compliance in the German-speaking region. He advises companies on NIS2 and KRITIS and has published over 200 academic papers.

Dr. Dr. Fabian Teichmann is a lawyer, researcher, and one of the leading experts on cybersecurity compliance in the German-speaking region. He advises companies on NIS2 and KRITIS and has published over 200 academic papers.

Share

Brief Definition

Cyber Security Awareness Training is a systematic educational program that enables employees to recognize and properly respond to cyber threats such as phishing, social engineering, and ransomware initiation. It combines continuous educational content with simulated attacks to specifically secure humans as the most common attack vector. In Switzerland and Germany, it has now become a regulatory obligation for many companies via the NIS2 Directive and national KRITIS legislation.

1. Why Humans Are the Real Targets of Attacks

Technical defense systems—firewalls, endpoint security, network segmentation—have reached a high level of maturity in recent years. At the same time, attackers are consistently shifting their focus to the factor that cannot be technically patched: human beings.

The current status report of the German Federal Office for Information Security (BSI) for the period from July 2024 to June 2025 documents an average of 119 newly discovered security vulnerabilities per day in Germany—a 24 percent increase compared to the previous year. The Federal Criminal Police Office registered 950 ransomware attacks during the same period, with 80 percent of the affected organizations being small and medium-sized enterprises.

At the same time, the BSI is observing a shift in attack paths towards compromised websites: typo-squatting (typo domains like "facebok.com") and brand-jacking (abuse of well-known brand names in the URL) are now among the most common methods used to lure users to phishing sites.

This shift is no coincidence. It follows an economic logic: a single successful click opens the path to the corporate network for attackers—completely without any complex technical exploit. This is precisely why security awareness training is no longer a marginal topic for the IT department, but a company-wide executive task.

2. Scientific Background: Phishing Research by Dr. Teichmann

The cybersecurity research of Dr. iur. Dr. rer. pol. Fabian M. Teichmann has been intensively addressing the question of how phishing attacks structurally function and why they remain so effective despite technical advancements for several years. In the study "Phishing Attacks: Risks and Challenges for Law Firms" (Teichmann & Boticiu, 2024), published in the International Cybersecurity Law Review in 2024, the authors distinguish three key forms of attack, the logic of which can be directly applied to companies in any industry:

Spear Phishing

Unlike broad-appeal bulk emails, spear phishing attacks target specific individuals or organizations. The study shows that attackers use publicly available information from social networks to personalize messages so they can hardly be distinguished from legitimate communication—often by impersonating a supervisor or partner, combined with a payment or data request.

Pharming

Here, victims are redirected to fake websites not via email, but through compromised DNS records or modified host files—often without a single suspicious click being required. The study describes DNS poisoning as a method where the IP address of a legitimate domain is redirected to the attacker's infrastructure in the background.

Account Takeover

Mass-mailed phishing emails aim to harvest credentials. Once an email account is compromised, attackers frequently use it, according to the study, to redirect payment flows within existing business relationships or blackmail victims using confidential information.

The study comes to a conclusion central to awareness programs: the most effective single measure against all three forms of attack is not yet another technical control, but the systematic training of employees—complemented by email filters, up-to-date antivirus software, multi-factor authentication, and secure Wi-Fi practices. Technology reduces the attack surface, but only trained employees close the gap that remains at the end of every chain—the moment of human decision.

3. Understanding the Business Model Behind Cyberattacks

He who understands why attackers use phishing in the first place trains more effectively. In the paper "Cybersecurity of Critical Infrastructure in Europe: The NIS2 Directive in Focus" (Teichmann, 2025), published in the International Cybersecurity Law Review in 2025, the underlying business model is analyzed: ransomware has evolved from a simple access block into a highly specialized branch of economy based on the division of labor.

Under the "Ransomware-as-a-Service" model, developers provide malware and infrastructure, while so-called affiliates execute the actual attacks and share the revenues proportionally. This ecosystem is complemented by "Initial Access Brokers" who trade exclusively in stolen credentials—credentials that, in most cases, originate from the very phishing campaigns that awareness training is meant to protect against.

The study also classifies ransomware legally: at the EU level, Directive 2013/40/EU obliges member states to consistently criminalize unauthorized system access, data tampering, computer sabotage, and extortion; in Germany, Sections 202a, 253, and 303b of the Criminal Code (StGB) interlock. According to the study, the cross-border dimension remains particularly problematic: attackers, servers, and financial flows are often located in different jurisdictions.

As practical examples, the study cites, among others, the ransomware attack on the Irish health service HSE (2021) as well as the deliberate decision of the Norwegian aluminum group Norsk Hydro (2019) to refuse a ransom payment—a case in which consistent, transparent crisis management restored trust in the long run despite high costs.

For awareness practice, this means: every phishing simulation that sensitizes employees to a compromised credential request potentially interrupts an entire attack chain—from initial access acquisition to the actual ransomware encryption.

4. Legal Framework: NIS2, KRITIS, and the Obligation to Train

The NIS2 Directive (Directive (EU) 2022/2555) explicitly obliges operators of essential and important entities to implement "cyber hygiene practices and cybersecurity training". How this obligation is shaped for specific sectors is shown by Dr. Teichmann's research based on several concrete economic branches:

In the study "NIS-2 in der Energiewirtschaft: Pflichten und Haftungsregime für Kritis-Betreiber" (Teichmann, 2025, Zeitschrift für das gesamte Recht der Energiewirtschaft), published in 2025, it is elaborated that energy companies as essential entities are subject to the strictest obligations: comprehensive risk management systems, supply chain security extending to cloud and control technology suppliers, and a staged reporting obligation—initial report within 24 hours, intermediate report after 72 hours, final analysis within one month.

The study also identifies the personal liability of management: fines of up to 10 million euros or 2 percent of global annual turnover are just as possible as individual sanctions ranging up to a professional disqualification for responsible persons.

For the banking sector, the study "Umsetzung der NIS-2-Richtlinien im deutschen Bankensektor" (Teichmann, 2025, Zeitschrift für Bank- und Kapitalmarktrecht) examines the interfaces between NIS2 and already existing regulations such as DORA. For the public sector, the paper "Cybersicherheit in Kommunen – Regelungsdefizite und Reformbedarf" (Teichmann, 2025, Zeitschrift für Rechtspolitik 6/2025, pp. 184–187) reveals that many municipalities are structurally underfunded to meet the new demands on personnel and processes.

The common denominator of all three studies: awareness measures are not an optional add-on to technical compliance, but an independent risk management component subject to documentation requirements under NIS2—regardless of whether it is an energy provider, a bank, or a municipal administration.

5. Preparation, Response, Recovery—The Three Phases

The study "Adequate Responses to Cyber-Attacks" (Teichmann & Boticiu, 2024, International Cybersecurity Law Review), published in 2024, provides a phase model that can be directly applied to setting up an awareness program:

Before an Attack

The study names tested backup procedures on physically disconnected storage media, documented incident response and business continuity plans, as well as intrusion detection systems as cornerstones. As an independent, equal component, the study explicitly lists "cybersecurity training"—with the specific goal of enabling employees to recognize phishing emails and consciously restrict access rights to sensitive information.

During and Immediately After an Attack

The study recommends the immediate isolation of compromised network segments, the involvement of legal counsel for communication with regulatory authorities, and seamless forensic documentation—factors that are also relevant for NIS2 reporting deadlines.

After an Attack

According to the study, the focus is on a complete cleanup of systems, a mandatory password reset, the activation of two-factor authentication, and—as the final step in the cycle—updating awareness measures based on the insights gained from the incident.

An awareness program oriented towards this triad is not a unique training event, but a self-improving cycle.

6. Cyber Threat Intelligence as a Complement to Awareness Training

Awareness training only unfolds its full impact in combination with Cyber Threat Intelligence (CTI). The study "Cyber Threat Intelligence: Existing Benefits and Challenges for Law Firms and Businesses" (Teichmann & Boticiu, 2024, International Cybersecurity Law Review) describes CTI as a structured process for collecting and analyzing information about the targets, motives, and attack patterns of threat actors, structured into six phases: defining intelligence requirements, collection, processing, analysis, dissemination to relevant parties, and feedback for continuous improvement.

For awareness programs, the "dissemination" phase is particularly relevant: up-to-date knowledge about new phishing campaigns or attack patterns in a specific industry can be directly fed into training content and simulation scenarios. The study also identifies typical challenges—such as data overload from too many unstructured sources or a lack of specialized staff—which should be taken into account when selecting a provider.

7. Industry-Specific Analysis


Industry

Key Regulatory Requirement

Scientific Source

Energy Sector / KRITIS

Strictest NIS2 obligations, 24-hour reporting deadline, supply chain security

Teichmann (2025), Zs. f. d. ges. Recht der Energiewirtschaft

Banking / Financial Sector

Intersection of NIS2 and DORA, tightened reporting requirements

Teichmann (2025), Zs. f. Bank- und Kapitalmarktrecht

Municipalities / Public Sector

Structural underfunding, regulatory reform needed regarding responsibilities

Teichmann (2025), Zs. f. Rechtspolitik 6/2025

Law Firms

High-priority target for spear phishing due to sensitive client data

Teichmann & Boticiu (2024), Int. Cybersecurity Law Review

Healthcare

Ransomware threat with direct relevance to patient safety

Teichmann (2025), Betriebs-Berater Compliance

(Note for the web designer: This table is set up so that it can later link to industry-specific subpages. Each row can become a link once the corresponding subpage is live.)

8. The Three Core Components of an Effective Awareness Program

Continuous Learning Content Instead of One-Time Training

An annual mandatory video does not change behavior. Effective programs work with short, recurring learning units (microlearning) that consolidate knowledge throughout the year—a principle that aligns with the feedback phase described in the CTI study: content is continuously adjusted to new threat situations instead of being defined once.

Phishing Simulations with Practical Relevance

Realistic simulations adapted to current attack patterns—such as typo-squatting domains, which the 2025 BSI status report describes as an increasingly widespread method—deliver measurable metrics (click rate, reporting rate) instead of just participation confirmations.

Verifiable Compliance Documentation

For NIS2 and KRITIS verifications, seamless documentation is needed: who was trained when, with what result, and what measures were taken in the case of repeated conspicuous anomalies.

9. How to Recognize a Good Provider


Criterion

What to Look For

Regulatory Foundation

Is the training supervised in terms of content by recognized legal and compliance experts with a verifiable history of publications?

Certification

Is the provider state-approved (e.g., ZFU-certified)?

Linguistic Specialization

Was the content genuinely developed for DACH law and language, or is it translated from English?

Simulation Realism

Do phishing simulations map current regional attack patterns (e.g., current BSI trends)?

Scientific Relevance

Are new research results continuously incorporated into training content?

Reporting

Does the platform deliver NIS2-compliant verification documentation?

10. On the Scientific Foundation of DeeplySecure

DeeplySecure is designed as a ZFU-certified continuing education program, with content managed by Dr. iur. Dr. rer. pol. Fabian M. Teichmann. Teichmann's research on phishing, ransomware, Cyber Threat Intelligence, and NIS2 implementation in various industries—regularly published in the International Cybersecurity Law Review, the Neue Juristische Wochenschrift, and the Zeitschrift für Rechtspolitik, among others—flows directly into the platform's training content and phishing simulations.

This close integration of academic research and practical training implementation distinguishes DeeplySecure from providers that work exclusively with marketing expertise rather than peer-referenced publications.

11. Frequently Asked Questions

How much does security awareness training cost for an SME?

The costs depend on the number of employees and the range of functions. Reliable providers calculate based on employee count rather than flat-rate packages without scaling.

Is security awareness training mandatory for all companies?

It is mandatory primarily for operators of essential and important entities under NIS2 and for KRITIS operators. For all other companies, it remains voluntary, but is increasingly demanded by cyber insurance providers as a prerequisite.

How often should phishing simulations be performed?

We recommend monthly to quarterly simulations with varying attack patterns to achieve a lasting learning effect rather than a one-time surprise effect.

What distinguishes spear phishing from classic phishing?

Spear phishing targets specific individuals or organizations and uses personalized, publicly available information, whereas classic phishing is broadly distributed and less individualized.

What is the difference between security awareness training and phishing simulation?

Security awareness training is the general term for the overall training program; the phishing simulation is an individual measure within this program that tests behavior under realistic conditions.

What reporting deadlines apply under NIS2 in the event of a security incident?

An initial report is due within 24 hours, an intermediate report after 72 hours, and a final analysis at the latest after one month.

Who is liable in the absence of awareness training and in the event of a cyber incident?

For NIS2-obligated companies, management can be held personally liable. Fines of up to 10 million euros or 2 percent of global annual turnover are possible, as well as individual sanctions up to a professional disqualification.

What is Cyber Threat Intelligence and how does it relate to awareness training?

Cyber Threat Intelligence is the structured collection and analysis of information about threat actors. Current insights ideally flow directly into training content and phishing simulations so that they map real, up-to-date attack patterns.

12. List of References

Teichmann, F. M. & Boticiu, S. R. (2024): Phishing Attacks: Risks and Challenges for Law Firms. International Cybersecurity Law Review, 07.02.2024.

Teichmann, F. M. & Boticiu, S. R. (2024): Adequate Responses to Cyber-Attacks. International Cybersecurity Law Review, 04.04.2024.

Teichmann, F. M. & Boticiu, S. R. (2024): Cyber Threat Intelligence: Existing Benefits and Challenges for Law Firms and Businesses. International Cybersecurity Law Review, 05.04.2024.

Teichmann, F. M. (2025): Cybersecurity of Critical Infrastructure in Europe: The NIS2 Directive in Focus. International Cybersecurity Law Review, 10.07.2025. DOI: 10.1365/s43439-025-00154-4

Teichmann, F. M. (2025): NIS-2 in der Energiewirtschaft: Pflichten und Haftungsregime für Kritis-Betreiber. Zeitschrift für das gesamte Recht der Energiewirtschaft.

Teichmann, F. M. (2025): Umsetzung der NIS-2-Richtlinien im deutschen Bankensektor. Zeitschrift für Bank- und Kapitalmarktrecht.

Teichmann, F. M. (2025): Cybersicherheit in Kommunen – Regelungsdefizite und Reformbedarf. Zeitschrift für Rechtspolitik, 6/2025, pp. 184–187.

Teichmann, F. M. (2026): Platform governance under NIS2 and the Cyber Resilience Act: cybersecurity by design as social practice. Information, Communication & Society. DOI: 10.1080/1369118X.2025.2609780

Federal Office for Information Security (BSI) (2025): The State of IT Security in Germany 2025. Reporting period July 1, 2024 – June 30, 2025.

Dr. Dr. Fabian Teichmann is a lawyer, researcher, and one of the leading experts on cybersecurity compliance in the German-speaking region. He advises companies on NIS2 and KRITIS and has published over 200 academic papers.

Share

We use cookies to improve your experience. By continuing, you agree to our cookie policy.