{"id":43899,"date":"2026-07-23T12:47:14","date_gmt":"2026-07-23T10:47:14","guid":{"rendered":"https:\/\/smartfense.com\/?p=43899"},"modified":"2026-07-23T12:47:19","modified_gmt":"2026-07-23T10:47:19","slug":"spain-ens-security-awareness-requirements","status":"publish","type":"post","link":"https:\/\/smartfense.com\/en\/blog\/spain-ens-security-awareness-requirements\/","title":{"rendered":"What Spain&#8217;s National Security Framework demands on security awareness, and how to prove it"},"content":{"rendered":"<p>Royal Decree 311\/2022, of 3 May, regulates Spain\u2019s National Security Framework (Esquema Nacional de Seguridad, ENS) and set a twenty-four-month window for pre-existing systems to reach full conformity. That window closed in May 2024. ENS conformity stopped being a horizon and became an enforceable state, verifiable through audit for systems in the medium and high categories.<\/p>\n<p>Within that framework, staff awareness and training are not an optional extra. The ENS lists them as security measures with their own name and number, and treats them like any technical control: they have to be applied, and they have to be demonstrable.<\/p>\n<p>This piece does not explain what e-government is or how the ENS is implemented end to end. It assumes that ground is covered. It focuses on something narrower: what the National Security Framework requires on staff awareness and training, how that requirement scales with the system\u2019s category, and what evidence an entity has to be able to put on the table once the auditor starts asking.<\/p>\n<h2>Who is bound by the National Security Framework?<\/h2>\n<p>The National Security Framework is the framework that sets the security policy for the use of electronic means by Spanish public-sector entities. It binds the whole administration, whether central, regional or local, and the public-law bodies linked to or dependent on it.<\/p>\n<p>The relevant boundary for the private sector lies in the supply chain. Royal Decree 311\/2022 extends its scope to private entities when they provide services or supply solutions to public bodies for the exercise of their competences. In practice, that obligation enters through procurement clauses: a technology provider that wants to work with a public administration has to demonstrate ENS conformity for the part of its systems that supports the service. The obligation stops being a public-sector matter alone and reaches its ecosystem of providers.<\/p>\n<h2>What does the ENS require on awareness and training?<\/h2>\n<p>The ENS separates two measures within the personnel management group of Annex II. Measure mp.per.3, \u00abAwareness\u00bb, requires keeping staff alert to their role in information security through periodic reminders and awareness actions. Measure mp.per.4, \u00abTraining\u00bb, requires regular training for all staff in the subjects they need to perform their role securely, proportional to that role.<\/p>\n<p>The distinction is not cosmetic. Raising awareness means sustaining attention on risks day to day; training means giving each person the concrete knowledge their position requires. The ENS asks for both, and it asks for them continuously, not as a single event at onboarding.<\/p>\n<p>The decree reinforces this from its first additional provision, which tasks the National Cryptologic Centre (CCN) and the National Institute of Public Administration (INAP) with developing awareness and training programmes for public-sector staff. The rule does not just require the activity; it recognizes that sustaining it needs a programme behind it.<\/p>\n<h2>Requirements scale with the system\u2019s category<\/h2>\n<p>The ENS does not apply a single yardstick. It classifies each system into one of three security categories, basic, medium or high, according to the impact an incident would have on the dimensions of confidentiality, integrity, traceability, authenticity and availability. The higher the category, the stricter the measures and, with them, the expected depth of the awareness and training programme.<\/p>\n<table>\n<thead>\n<tr>\n<th>Category<\/th>\n<th>How conformity is accredited<\/th>\n<th>Requirement on staff<\/th>\n<\/tr>\n<\/thead>\n<tbody>\n<tr>\n<td>Basic<\/td>\n<td>Self-assessment and declaration of conformity<\/td>\n<td>Awareness and training proportional to the role<\/td>\n<\/tr>\n<tr>\n<td>Medium<\/td>\n<td>Certification audit<\/td>\n<td>Greater formalization and traceability of the programme<\/td>\n<\/tr>\n<tr>\n<td>High<\/td>\n<td>Certification audit<\/td>\n<td>Reinforced programme, reviewed and evidenced in depth<\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<p>The most important operational difference lies in how it is verified. Systems in the medium or high category need an audit to certify their conformity; in the basic category, a self-assessment with a declaration of conformity is enough. For anyone running a medium- or high-category system, that means awareness will have to withstand the scrutiny of a third party that asks for proof, not just internal goodwill.<\/p>\n<h2>The gap between the stated policy and actual behaviour<\/h2>\n<p>The point where most programmes break is not a lack of activity but the gap between what the policy states and what staff actually do. An entity can have an impeccable security policy approved, an annual course and a sign-in sheet, and still be unable to demonstrate that the training changed anything in everyday conduct.<\/p>\n<p>That is where an ENS audit finds the critical point. The auditor does not assess good intentions; it contrasts declared knowledge with actual behaviour. A programme that only accredits attendance answers the wrong question. The question that matters is whether staff recognize a phishing attempt when it is in front of them, whether they know who to report an incident to, and whether that reaction improves over time. That is the ground the ENS shares with other frameworks, as we broke down when analysing <a href=\"https:\/\/smartfense.com\/en\/blog\/iso-27001-2022-control-6-3-awareness\/\">control 6.3 of ISO 27001:2022<\/a> and the awareness requirements of <a href=\"https:\/\/smartfense.com\/en\/blog\/nis2-security-awareness-compliance-deep-dive\/\">the NIS2 Directive<\/a>.<\/p>\n<h2>How is compliance evidenced in an ENS audit?<\/h2>\n<p>For measures mp.per.3 and mp.per.4, the evidence that supports conformity usually rests on these elements:<\/p>\n<ul>\n<li>A record of who received awareness and training, when and on what, covering the whole workforce.<\/li>\n<li>Content tied to the entity\u2019s policies and to the real risks of each role, not a generic syllabus.<\/li>\n<li>Defined, sustained periodicity, with reminders and awareness actions throughout the year.<\/li>\n<li>Proof of comprehension and behaviour, such as assessments or simulation results, that goes beyond attendance.<\/li>\n<li>Traceability proportional to the system\u2019s category, stricter in medium and high.<\/li>\n<\/ul>\n<p>The fragile point is almost always the same: the entity has the activity but not the trail in order on the day the auditor asks for it. Designing the programme from the start around what data will be recorded is what separates complying from being able to prove it.<\/p>\n<p>SMARTFENSE, as a security awareness platform with presence in Spain and Latin America, is built around that idea. Every awareness action, every piece of content delivered, every phishing simulation and every assessment is recorded and available as evidence, so the responsible team does not have to rebuild the trail by hand before an ENS audit. You can see how it comes together in the <a href=\"https:\/\/smartfense.com\/en\/platform\/\">SMARTFENSE security awareness platform<\/a>.<\/p>\n<p>The adaptation deadline has passed, and with it ended the room to treat awareness as internal communication. The ENS set it as a security measure with evidence attached, and the scale of that evidence grows with the system\u2019s category. What decides an audit is not how many training hours were delivered, but what trail the entity can show that its staff act differently.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>Spain&#8217;s National Security Framework (ENS) treats staff awareness and training as auditable security measures. What mp.per.3 and mp.per.4 require and how to evidence them.<\/p>\n","protected":false},"author":31,"featured_media":43896,"comment_status":"open","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"_acf_changed":false,"footnotes":""},"categories":[3,686],"tags":[1362,456,2063,448],"class_list":["post-43899","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-blog","tag-cumplimiento-normativo-en","tag-cyber-security","tag-riesgo-humano","tag-security-awareness"],"acf":[],"yoast_head":" \n<title>Spain&#039;s ENS: security awareness requirements and evidence<\/title>\n<meta name=\"description\" content=\"Spain&#039;s National Security Framework (ENS) treats staff awareness and training as auditable security measures. What mp.per.3 and mp.per.4 require and how to evidence them.\" \/>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/smartfense.com\/en\/blog\/spain-ens-security-awareness-requirements\/\" \/>\n<meta property=\"og:locale\" content=\"en_US\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"Spain&#039;s ENS: security awareness requirements and evidence\" \/>\n<meta property=\"og:description\" content=\"Spain&#039;s National Security Framework (ENS) treats staff awareness and training as auditable security measures. What mp.per.3 and mp.per.4 require and how to evidence them.\" \/>\n<meta property=\"og:url\" content=\"https:\/\/smartfense.com\/en\/blog\/spain-ens-security-awareness-requirements\/\" \/>\n<meta property=\"og:site_name\" content=\"SMARTFENSE\" \/>\n<meta property=\"article:published_time\" content=\"2026-07-23T10:47:14+00:00\" \/>\n<meta property=\"article:modified_time\" content=\"2026-07-23T10:47:19+00:00\" \/>\n<meta property=\"og:image\" content=\"https:\/\/smartfense.com\/file\/2026\/07\/hero-1-21.jpg\" \/>\n\t<meta property=\"og:image:width\" content=\"1376\" \/>\n\t<meta property=\"og:image:height\" content=\"768\" \/>\n\t<meta property=\"og:image:type\" content=\"image\/jpeg\" \/>\n<meta name=\"author\" content=\"Andrea Sona\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:label1\" content=\"Written by\" \/>\n\t<meta name=\"twitter:data1\" content=\"Andrea Sona\" \/>\n\t<meta name=\"twitter:label2\" content=\"Est. reading time\" \/>\n\t<meta name=\"twitter:data2\" content=\"5 minutes\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\\\/\\\/schema.org\",\"@graph\":[{\"@type\":\"Article\",\"@id\":\"https:\\\/\\\/smartfense.com\\\/en\\\/blog\\\/spain-ens-security-awareness-requirements\\\/#article\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/smartfense.com\\\/en\\\/blog\\\/spain-ens-security-awareness-requirements\\\/\"},\"author\":{\"name\":\"Andrea Sona\",\"@id\":\"https:\\\/\\\/smartfense.com\\\/en\\\/#\\\/schema\\\/person\\\/3d5d7dc2e569f5c1af2daef92f35de00\"},\"headline\":\"What Spain&#8217;s National Security Framework demands on security awareness, and how to prove it\",\"datePublished\":\"2026-07-23T10:47:14+00:00\",\"dateModified\":\"2026-07-23T10:47:19+00:00\",\"mainEntityOfPage\":{\"@id\":\"https:\\\/\\\/smartfense.com\\\/en\\\/blog\\\/spain-ens-security-awareness-requirements\\\/\"},\"wordCount\":1087,\"commentCount\":0,\"publisher\":{\"@id\":\"https:\\\/\\\/smartfense.com\\\/en\\\/#organization\"},\"image\":{\"@id\":\"https:\\\/\\\/smartfense.com\\\/en\\\/blog\\\/spain-ens-security-awareness-requirements\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/smartfense.com\\\/wp-content\\\/uploads\\\/2026\\\/07\\\/hero-1-21.jpg\",\"keywords\":[\"Cumplimiento Normativo\",\"cyber security\",\"riesgo humano\",\"security awareness\"],\"articleSection\":[\"Blog\",\"Blog\"],\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"CommentAction\",\"name\":\"Comment\",\"target\":[\"https:\\\/\\\/smartfense.com\\\/en\\\/blog\\\/spain-ens-security-awareness-requirements\\\/#respond\"]}]},{\"@type\":\"WebPage\",\"@id\":\"https:\\\/\\\/smartfense.com\\\/en\\\/blog\\\/spain-ens-security-awareness-requirements\\\/\",\"url\":\"https:\\\/\\\/smartfense.com\\\/en\\\/blog\\\/spain-ens-security-awareness-requirements\\\/\",\"name\":\"Spain's ENS: security awareness requirements and evidence\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/smartfense.com\\\/en\\\/#website\"},\"primaryImageOfPage\":{\"@id\":\"https:\\\/\\\/smartfense.com\\\/en\\\/blog\\\/spain-ens-security-awareness-requirements\\\/#primaryimage\"},\"image\":{\"@id\":\"https:\\\/\\\/smartfense.com\\\/en\\\/blog\\\/spain-ens-security-awareness-requirements\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/smartfense.com\\\/wp-content\\\/uploads\\\/2026\\\/07\\\/hero-1-21.jpg\",\"datePublished\":\"2026-07-23T10:47:14+00:00\",\"dateModified\":\"2026-07-23T10:47:19+00:00\",\"description\":\"Spain's National Security Framework (ENS) treats staff awareness and training as auditable security measures. What mp.per.3 and mp.per.4 require and how to evidence them.\",\"breadcrumb\":{\"@id\":\"https:\\\/\\\/smartfense.com\\\/en\\\/blog\\\/spain-ens-security-awareness-requirements\\\/#breadcrumb\"},\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\\\/\\\/smartfense.com\\\/en\\\/blog\\\/spain-ens-security-awareness-requirements\\\/\"]}]},{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/smartfense.com\\\/en\\\/blog\\\/spain-ens-security-awareness-requirements\\\/#primaryimage\",\"url\":\"https:\\\/\\\/smartfense.com\\\/wp-content\\\/uploads\\\/2026\\\/07\\\/hero-1-21.jpg\",\"contentUrl\":\"https:\\\/\\\/smartfense.com\\\/wp-content\\\/uploads\\\/2026\\\/07\\\/hero-1-21.jpg\",\"width\":1376,\"height\":768,\"caption\":\"Edificio institucional de administraci\u00f3n p\u00fablica al atardecer, con hileras de ventanas iluminadas de forma desigual, que sugiere una organizaci\u00f3n donde no todas las \u00e1reas mantienen el mismo nivel de atenci\u00f3n\"},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\\\/\\\/smartfense.com\\\/en\\\/blog\\\/spain-ens-security-awareness-requirements\\\/#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Portada\",\"item\":\"https:\\\/\\\/smartfense.com\\\/en\\\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"What Spain&#8217;s National Security Framework demands on security awareness, and how to prove it\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\\\/\\\/smartfense.com\\\/en\\\/#website\",\"url\":\"https:\\\/\\\/smartfense.com\\\/en\\\/\",\"name\":\"SMARTFENSE - Concienciaci\u00f3n en Ciberseguridad\",\"description\":\"\",\"publisher\":{\"@id\":\"https:\\\/\\\/smartfense.com\\\/en\\\/#organization\"},\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\\\/\\\/smartfense.com\\\/en\\\/?s={search_term_string}\"},\"query-input\":{\"@type\":\"PropertyValueSpecification\",\"valueRequired\":true,\"valueName\":\"search_term_string\"}}],\"inLanguage\":\"en-US\"},{\"@type\":\"Organization\",\"@id\":\"https:\\\/\\\/smartfense.com\\\/en\\\/#organization\",\"name\":\"SMARTFENSE\",\"url\":\"https:\\\/\\\/smartfense.com\\\/en\\\/\",\"logo\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/smartfense.com\\\/en\\\/#\\\/schema\\\/logo\\\/image\\\/\",\"url\":\"https:\\\/\\\/smartfense.com\\\/wp-content\\\/uploads\\\/2023\\\/08\\\/logo-smartfense-240x40-1.png\",\"contentUrl\":\"https:\\\/\\\/smartfense.com\\\/wp-content\\\/uploads\\\/2023\\\/08\\\/logo-smartfense-240x40-1.png\",\"width\":241,\"height\":40,\"caption\":\"SMARTFENSE\"},\"image\":{\"@id\":\"https:\\\/\\\/smartfense.com\\\/en\\\/#\\\/schema\\\/logo\\\/image\\\/\"}},{\"@type\":\"Person\",\"@id\":\"https:\\\/\\\/smartfense.com\\\/en\\\/#\\\/schema\\\/person\\\/3d5d7dc2e569f5c1af2daef92f35de00\",\"name\":\"Andrea Sona\",\"image\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/smartfense.com\\\/wp-content\\\/uploads\\\/2026\\\/05\\\/andrea-sona-avatar-150x150.png\",\"url\":\"https:\\\/\\\/smartfense.com\\\/wp-content\\\/uploads\\\/2026\\\/05\\\/andrea-sona-avatar-150x150.png\",\"contentUrl\":\"https:\\\/\\\/smartfense.com\\\/wp-content\\\/uploads\\\/2026\\\/05\\\/andrea-sona-avatar-150x150.png\",\"caption\":\"Andrea Sona\"},\"description\":\"Da anni nel settore informatico, Analista Informatica di professione, negli ultimi anni specializzata in cybersecurity awareness e formazione digitale, attualmente collaborando in SMARTFENSE. Con esperienza nel supportare aziende e organizzazioni nella diffusione della cultura della sicurezza informatica. Appassionata di innovazione e comunicazione tecnologica, contribuisce attivamente al dibattito sulla sicurezza digitale attraverso contenuti divulgativi.\",\"sameAs\":[\"https:\\\/\\\/www.linkedin.com\\\/in\\\/andrea-sona-58238b83\\\/\"],\"url\":\"https:\\\/\\\/smartfense.com\\\/en\\\/author\\\/andrea-sona\\\/\"}]}<\/script>\n ","yoast_head_json":{"title":"Spain's ENS: security awareness requirements and evidence","description":"Spain's National Security Framework (ENS) treats staff awareness and training as auditable security measures. What mp.per.3 and mp.per.4 require and how to evidence them.","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/smartfense.com\/en\/blog\/spain-ens-security-awareness-requirements\/","og_locale":"en_US","og_type":"article","og_title":"Spain's ENS: security awareness requirements and evidence","og_description":"Spain's National Security Framework (ENS) treats staff awareness and training as auditable security measures. What mp.per.3 and mp.per.4 require and how to evidence them.","og_url":"https:\/\/smartfense.com\/en\/blog\/spain-ens-security-awareness-requirements\/","og_site_name":"SMARTFENSE","article_published_time":"2026-07-23T10:47:14+00:00","article_modified_time":"2026-07-23T10:47:19+00:00","og_image":[{"width":1376,"height":768,"url":"https:\/\/smartfense.com\/file\/2026\/07\/hero-1-21.jpg","type":"image\/jpeg"}],"author":"Andrea Sona","twitter_card":"summary_large_image","twitter_misc":{"Written by":"Andrea Sona","Est. reading time":"5 minutes"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"Article","@id":"https:\/\/smartfense.com\/en\/blog\/spain-ens-security-awareness-requirements\/#article","isPartOf":{"@id":"https:\/\/smartfense.com\/en\/blog\/spain-ens-security-awareness-requirements\/"},"author":{"name":"Andrea Sona","@id":"https:\/\/smartfense.com\/en\/#\/schema\/person\/3d5d7dc2e569f5c1af2daef92f35de00"},"headline":"What Spain&#8217;s National Security Framework demands on security awareness, and how to prove it","datePublished":"2026-07-23T10:47:14+00:00","dateModified":"2026-07-23T10:47:19+00:00","mainEntityOfPage":{"@id":"https:\/\/smartfense.com\/en\/blog\/spain-ens-security-awareness-requirements\/"},"wordCount":1087,"commentCount":0,"publisher":{"@id":"https:\/\/smartfense.com\/en\/#organization"},"image":{"@id":"https:\/\/smartfense.com\/en\/blog\/spain-ens-security-awareness-requirements\/#primaryimage"},"thumbnailUrl":"https:\/\/smartfense.com\/file\/2026\/07\/hero-1-21.jpg","keywords":["Cumplimiento Normativo","cyber security","riesgo humano","security awareness"],"articleSection":["Blog","Blog"],"inLanguage":"en-US","potentialAction":[{"@type":"CommentAction","name":"Comment","target":["https:\/\/smartfense.com\/en\/blog\/spain-ens-security-awareness-requirements\/#respond"]}]},{"@type":"WebPage","@id":"https:\/\/smartfense.com\/en\/blog\/spain-ens-security-awareness-requirements\/","url":"https:\/\/smartfense.com\/en\/blog\/spain-ens-security-awareness-requirements\/","name":"Spain's ENS: security awareness requirements and evidence","isPartOf":{"@id":"https:\/\/smartfense.com\/en\/#website"},"primaryImageOfPage":{"@id":"https:\/\/smartfense.com\/en\/blog\/spain-ens-security-awareness-requirements\/#primaryimage"},"image":{"@id":"https:\/\/smartfense.com\/en\/blog\/spain-ens-security-awareness-requirements\/#primaryimage"},"thumbnailUrl":"https:\/\/smartfense.com\/file\/2026\/07\/hero-1-21.jpg","datePublished":"2026-07-23T10:47:14+00:00","dateModified":"2026-07-23T10:47:19+00:00","description":"Spain's National Security Framework (ENS) treats staff awareness and training as auditable security measures. What mp.per.3 and mp.per.4 require and how to evidence them.","breadcrumb":{"@id":"https:\/\/smartfense.com\/en\/blog\/spain-ens-security-awareness-requirements\/#breadcrumb"},"inLanguage":"en-US","potentialAction":[{"@type":"ReadAction","target":["https:\/\/smartfense.com\/en\/blog\/spain-ens-security-awareness-requirements\/"]}]},{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/smartfense.com\/en\/blog\/spain-ens-security-awareness-requirements\/#primaryimage","url":"https:\/\/smartfense.com\/file\/2026\/07\/hero-1-21.jpg","contentUrl":"https:\/\/smartfense.com\/file\/2026\/07\/hero-1-21.jpg","width":1376,"height":768,"caption":"Edificio institucional de administraci\u00f3n p\u00fablica al atardecer, con hileras de ventanas iluminadas de forma desigual, que sugiere una organizaci\u00f3n donde no todas las \u00e1reas mantienen el mismo nivel de atenci\u00f3n"},{"@type":"BreadcrumbList","@id":"https:\/\/smartfense.com\/en\/blog\/spain-ens-security-awareness-requirements\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Portada","item":"https:\/\/smartfense.com\/en\/"},{"@type":"ListItem","position":2,"name":"What Spain&#8217;s National Security Framework demands on security awareness, and how to prove it"}]},{"@type":"WebSite","@id":"https:\/\/smartfense.com\/en\/#website","url":"https:\/\/smartfense.com\/en\/","name":"SMARTFENSE - Concienciaci\u00f3n en Ciberseguridad","description":"","publisher":{"@id":"https:\/\/smartfense.com\/en\/#organization"},"potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/smartfense.com\/en\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"en-US"},{"@type":"Organization","@id":"https:\/\/smartfense.com\/en\/#organization","name":"SMARTFENSE","url":"https:\/\/smartfense.com\/en\/","logo":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/smartfense.com\/en\/#\/schema\/logo\/image\/","url":"https:\/\/smartfense.com\/file\/2023\/08\/logo-smartfense-240x40-1.png","contentUrl":"https:\/\/smartfense.com\/file\/2023\/08\/logo-smartfense-240x40-1.png","width":241,"height":40,"caption":"SMARTFENSE"},"image":{"@id":"https:\/\/smartfense.com\/en\/#\/schema\/logo\/image\/"}},{"@type":"Person","@id":"https:\/\/smartfense.com\/en\/#\/schema\/person\/3d5d7dc2e569f5c1af2daef92f35de00","name":"Andrea Sona","image":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/smartfense.com\/file\/2026\/05\/andrea-sona-avatar-150x150.png","url":"https:\/\/smartfense.com\/file\/2026\/05\/andrea-sona-avatar-150x150.png","contentUrl":"https:\/\/smartfense.com\/file\/2026\/05\/andrea-sona-avatar-150x150.png","caption":"Andrea Sona"},"description":"Da anni nel settore informatico, Analista Informatica di professione, negli ultimi anni specializzata in cybersecurity awareness e formazione digitale, attualmente collaborando in SMARTFENSE. Con esperienza nel supportare aziende e organizzazioni nella diffusione della cultura della sicurezza informatica. Appassionata di innovazione e comunicazione tecnologica, contribuisce attivamente al dibattito sulla sicurezza digitale attraverso contenuti divulgativi.","sameAs":["https:\/\/www.linkedin.com\/in\/andrea-sona-58238b83\/"],"url":"https:\/\/smartfense.com\/en\/author\/andrea-sona\/"}]}},"_links":{"self":[{"href":"https:\/\/smartfense.com\/en\/wp-json\/wp\/v2\/posts\/43899","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/smartfense.com\/en\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/smartfense.com\/en\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/smartfense.com\/en\/wp-json\/wp\/v2\/users\/31"}],"replies":[{"embeddable":true,"href":"https:\/\/smartfense.com\/en\/wp-json\/wp\/v2\/comments?post=43899"}],"version-history":[{"count":2,"href":"https:\/\/smartfense.com\/en\/wp-json\/wp\/v2\/posts\/43899\/revisions"}],"predecessor-version":[{"id":43908,"href":"https:\/\/smartfense.com\/en\/wp-json\/wp\/v2\/posts\/43899\/revisions\/43908"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/smartfense.com\/en\/wp-json\/wp\/v2\/media\/43896"}],"wp:attachment":[{"href":"https:\/\/smartfense.com\/en\/wp-json\/wp\/v2\/media?parent=43899"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/smartfense.com\/en\/wp-json\/wp\/v2\/categories?post=43899"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/smartfense.com\/en\/wp-json\/wp\/v2\/tags?post=43899"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}