Almost every framework you have to comply with includes its own requirement for staff awareness and training. We give you the programme that covers it, linked to the specific clauses of each standard, along with the evidence to prove it when someone asks.
Request a demo See all 13 frameworksCybersecurity compliance is the set of obligations an organisation has to meet, and be able to demonstrate, against a law or a security standard. Part of it is settled with technical controls and the rest falls on people. According to the Verizon DBIR report, the human element is involved in close to 6 out of every 10 security breaches, and that second part is the harder one to evidence for an auditor.
An auditor does not review what your programme intended to do, they review its record. Three elements build that record.
Every training module, exam and newsletter is linked to the clauses it covers. There are currently 194 clauses from 12 frameworks mapped in the platform, so the degree of compliance is read clause by clause rather than as a general estimate.
What a board needs in order to make risk decisions looks very little like what the rest of the staff needs for their daily work. Each framework comes with separate tracks, at the level of detail and in the language that suits each group.
From the platform’s regulations management you can check the degree of compliance according to the training assigned to each person, with the detail of who completed what, the result they got and how they responded to a simulation.
Each framework has its own page covering what it demands of people and the programme that satisfies it. The catalogue grows as new frameworks come into force and we map their evidence.
For over 10 years we have worked with organisations across banking, healthcare, the public sector and critical infrastructure to reduce human risk and leave auditable evidence that they do. When an organisation has to answer to several frameworks at once, the same programme covers the clauses of all of them without duplicating the work.
Almost every cybersecurity framework includes staff awareness and training as an enforceable requirement. ISO/IEC 27002:2022 covers it in control 6.3, PCI DSS in requirement 12.6, HIPAA in §164.308(a)(5), and the NIS 2 Directive requires it of essential and important entities. The form changes from one framework to the next and the substance repeats across all of them. People have to be trained periodically, and you have to be able to prove it.
It counts when it leaves a record. A one-off campaign that nobody can document beyond remembering it happened will not do. What an auditor can review is the record of who completed each piece of content, on what date, with what result in the assessment and how they responded to a simulation. That record is what turns the claim that you train your staff into something verifiable.
No. The obligations that fall on people overlap heavily between frameworks, so a single piece of content usually covers clauses from several standards at the same time. Because every piece is linked to the clauses it satisfies, one programme feeds the compliance report for every framework that applies to you.
The content is already produced and mapped, so there is nothing to write and no need to work out who to assign it to from scratch. The frameworks in the catalogue come with automatic programmes that assign and schedule themselves. The real work concentrates on defining the groups of people and the calendar that suits your organisation. We are also refining the Compliance Center with our first teams, where a dashboard shows compliance in real time and an agent builds the Compliance Plan and works through the gaps. We cover it in detail in this article.
Leave us your details and we will show you how to cover the obligations of each framework with content linked to its clauses, ready for your organisation.