Ongoing training and awareness programs
NHRIs with available resources should create formal and regular training and awareness activities
where messages about data protection are conveyed and reinforced. This can be done in a fun way
rather than a scolding way.
Training and awareness activities could include a range of actions.
Putting it into practice
Doing a simple survey of staff to understand their level of knowledge should
guide you on your awareness activities.
Phishing simulations: Send staff fake phishing emails to assess their ability
to recognise suspicious emails. These tests help staff practice identifying
malicious messages and help those who “click the link” to learn from their
mistake without real-world consequences. Immediate feedback can be
provided on how to avoid falling for similar attacks in the future.
Visual and routine reminders: Create and display posters, infographics, and
digital content (e.g., short videos, social media posts, internal emails) that
highlight key cybersecurity tips and risks, such as recognising phishing emails
or creating strong passwords.
Provide constant reminders of best practices in whatever format and location
is appropriate. Examples could be: “Don’t Click on Suspicious Links!; Always
Use Two-Factor Authentication; Lock Your Device Before You Leave.”
Data Protection Guidelines for NHRIs Toolkit
22