Ongoing training and awareness programs NHRIs with available resources should create formal and regular training and awareness activities where messages about data protection are conveyed and reinforced. This can be done in a fun way rather than a scolding way. Training and awareness activities could include a range of actions. Putting it into practice Doing a simple survey of staff to understand their level of knowledge should guide you on your awareness activities. Phishing simulations: Send staff fake phishing emails to assess their ability to recognise suspicious emails. These tests help staff practice identifying malicious messages and help those who “click the link” to learn from their mistake without real-world consequences. Immediate feedback can be provided on how to avoid falling for similar attacks in the future. Visual and routine reminders: Create and display posters, infographics, and digital content (e.g., short videos, social media posts, internal emails) that highlight key cybersecurity tips and risks, such as recognising phishing emails or creating strong passwords. Provide constant reminders of best practices in whatever format and location is appropriate. Examples could be: “Don’t Click on Suspicious Links!; Always Use Two-Factor Authentication; Lock Your Device Before You Leave.” Data Protection Guidelines for NHRIs Toolkit 22

Select target paragraph3