Regulated Incident Management Ecosystem Versão portuguesa

Service sheet SO-07

Awareness and Security Culture Programme

An annual awareness programme, with themed campaigns, phishing simulations and measurement of results by team.

The problem it solves

Awareness amounts to one mandatory session a year that nobody remembers by March. Without measurement, nobody knows whether anything changed.

Who it is for

  • HR and security leadership;
  • Organisations with many external touchpoints;
  • Entities with training obligations.

Deliverables

  • Annual awareness plan;
  • Themed campaigns and dedicated materials;
  • Phishing simulations with follow-up;
  • Indicator report by team.

Method

  1. 01

    Assess

    Behaviours and risks.

  2. 02

    Plan

    Calendar and topics.

  3. 03

    Run

    Campaigns and simulations.

  4. 04

    Measure

    Indicators and adjustments.

Regulatory basis

  • Article 39(1)(b) GDPR, on awareness-raising and training;
  • ISO/IEC 27001:2022 and ISO/IEC 27002:2022.

Expected results

  • Behaviours measured and improving;
  • Fewer human-origin incidents;
  • Evidence of training for audits.

Security that is not measured is not managed

Start with a maturity assessment or ask for a proposal to structure the role.