60 % of confirmed breaches in 2024 involved a human element. That is the headline from Verizon DBIR 2025. 16 % of breaches started with phishing directly. Another 22 % began with credential abuse — most of those credentials harvested through phishing.
ENISA's Threat Landscape 2025 puts phishing at 60 % of all observed initial intrusions in the EU. Ransomware sits behind 81 % of confirmed cybercrime incidents. For an SMB under 100 employees, that math turns security awareness training from a compliance box into an operational must.
This article covers three things. What NIS2 actually asks a mid-sized team to do. What a realistic program costs. And two worked scenarios for teams of 25 and 80 employees.
What NIS2 asks for
The NIS2 directive is in force across the EU, with national transposition wrapped up in most Member States by mid-2025. Scope reaches well beyond NIS1's 18 sectors, covering thousands of new organisations in every Member State.
Article 21(2)(g) requires "basic cyber hygiene practices and cybersecurity training" for the entire workforce. Not just IT, not just management. Article 20 adds a specific obligation for management bodies to undergo training themselves and can hold them personally liable for a compliance failure.
Deadlines vary by country, but the pattern is consistent:
- Organisational measures first — policies, roles, workforce training — usually within 12 months of national transposition.
- Technical measures second — MFA, segmentation, backup and log management — inside 24 months.
Under-threshold companies still feel the pull indirectly. Cyber insurers, GDPR supervisory authorities and enterprise buyers all use supplier-security clauses that echo the same list. An SMB without a documented awareness program pays more for insurance and loses tenders.
What a realistic program costs
A bad awareness program does more harm than none. A 45-minute video pushes completion below 60 %. The follow-up phishing simulation then reveals the content never landed.
2026 market pricing:
- EUR 3–25 per employee per year for a self-serve platform with content and phishing simulations.
- EUR 3,000–6,000 per year total for a managed program covering 25–100 employees.
- EUR 500–2,000 per session for a live workshop with management or a specific team.
Volume brings discounts. A team of 25 typically pays around EUR 1.80 per seat per month. A team of 200 drops under EUR 1.00. Annual contracts save 20–60 % over monthly.
Building content in-house ("we'll put it in Notion") looks free but rarely is. One HR-week and a poor first-pass module cost more than a full year of the platform.
What the program must cover
Between 2024 and 2025, AI-supported phishing in Europe grew to more than 80 % of observed social engineering activity. Content that worked in 2022 no longer moves the needle. A 2026 program needs to cover:
- Phishing recognition — including quishing (QR-code phishing) and ClickFix attacks (PowerShell run through a fake CAPTCHA).
- Password hygiene and MFA — not theory; the specific case of MFA-prompt fatigue and how to report it.
- Data handling — what must never go into a public ChatGPT prompt, GDPR basics, retention rules.
- Incident reporting — a specific internal contact and a 24-hour clock.
- Remote work — home Wi-Fi hardening, separate device use, what to do the day a laptop is stolen.
A formal knowledge check at the end is non-negotiable. Without a quiz, a supervisor will not accept "everyone watched the video" as evidence of training.
Two concrete programs
Program 1: accounting firm, 25 employees
The firm processes client PII and bank data. Phishing risk is high — attackers specifically target accounting firms for their tax-portal and banking access. Program:
- Onboarding module (30 min) — phishing recognition, three sector-specific examples (IBAN-change fraud, fake tax-authority reminders, CEO fraud before a payment deadline).
- Password and MFA module (15 min) — mandatory MFA on the tax portal, password manager rollout, what to do when 15 push requests arrive at once.
- Monthly phishing simulation — one email per month, no more. Target: click rate below 5 % within six months.
- Quarterly 5-min refresher — one new technique each time (this year: quishing, ClickFix).
Cost: about EUR 1,200 per year for the self-serve platform, plus EUR 500 for a kick-off workshop with the managing partner. Roughly EUR 70 per employee in year one, EUR 50 every year after.
Program 2: e-commerce company, 80 employees
The business takes card payments (PCI-DSS applies) and has both an office team and a warehouse crew. The office side qualifies as a NIS2 "important entity" in most Member States. Program:
- Baseline for everyone (45 min) — phishing, password hygiene, incident reporting. Signed acknowledgement of the internal AI-and-security policy.
- Engineering module (60 min) — secure coding, handling production credentials, OWASP Top 10 in the e-commerce context.
- Customer support module (30 min) — social engineering over chat and phone ("reset my password, I lost my phone").
- Warehouse module (15 min) — physical security, USB safety, what to do with a found drive.
- Management (60 min with outside counsel) — NIS2 personal liability, internal audit trail, obligation to notify the national CSIRT within 24 hours.
- Monthly phishing simulation with real-time coaching on click.
Cost: about EUR 5,500 per year (platform plus managed service). That works out to EUR 70 per employee — squarely inside the range cyber insurers now use when pricing SMB policies.
Three mistakes we keep seeing
- "We ran a webinar in January." A phishing simulation three months later shows content did not land. The median click rate on simulations sits around 1.5 % per DBIR 2025. You cannot push lower without repeated micro-modules.
- "IT will handle it." IT teams write scripts, not curricula. HR must calibrate content by role and keep the attendance evidence a supervisor will ask for.
- "One-time training is enough." ENISA counted 82 new ransomware variants in 2025 and industrialised phishing through Phishing-as-a-Service platforms. Anyone training once a year is training on last year's playbook.
For the wider view on training obligations see NIS2 employee training requirements.
Where to start this week
If no program is in place, four steps take about five working days:
- Inventory who in the team has access to critical systems (banking, tax portal, admin CRM).
- Test your baseline with three phishing emails you send internally — not to punish anyone, to set a benchmark.
- Write five internal rules (password manager, MFA, incident report within 24 hours, allowed AI apps, handling of unknown USB drives).
- Book the first management session before month-end — same pattern that worked for AI Act and GDPR rollouts.
What consolidation actually solves
Awareness supervision under NIS2 is not an IQ test on end users; it is a documentation test. An LMS such as Mentor keeps role-based content in one place, tracks quizzes and auto-refreshes modules every quarter. The report exports for a national CSIRT or a cyber insurer to validate in half an hour. Without evidence, even a sensible internal policy does not count at inspection.