Security Awareness Training in the Nordics: What the Law Now Requires
For twenty years, security awareness training was a discretionary spend justified by risk arguments and bought by people who had to persuade a finance director. In the space of nine months across 2025 and 2026, it became a legal obligation in both Finland and Sweden, with a named duty holder and personal consequences for failure.
That is the change worth understanding, because it moved the buying decision from IT to the board, and because most of the content published on this topic is still marketing for phishing simulation platforms written before any of it happened.
What actually changed
Finland transposed NIS2 through the cyber security act, kyberturvallisuuslaki 124/2025, in force from 8 April 2025. In-scope entities had to register with their sector supervisory authority by 8 May 2025 and have a cyber security risk management model by 8 July 2025. Traficom’s National Cyber Security Centre acts as the national point of contact and CSIRT alongside sector authorities. Senior management must approve the risk management measures, oversee them, and take part in training, and can be held personally accountable, in serious cases through a temporary prohibition on holding management functions until deficiencies are corrected.
Sweden transposed through cybersäkerhetslagen (2025:1506), in force from 15 January 2026, covering entities across eighteen sectors, with MSB coordinating nationally and sector authorities supervising. The Swedish drafting made a deliberate choice on training: the preparatory inquiry had proposed a broader duty reaching wider employee groups, and the act as passed narrowed the mandatory cyber security training obligation to the management body, meaning the board and chief executive.
So the position today is that in both countries the management body has a training obligation that is explicit, personal and documentable, while staff-level training sits inside the broader risk management duty and is scoped by your own risk assessment rather than by a blanket statutory requirement.
Anyone telling you NIS2 mandates annual awareness training for all employees is overstating it. Anyone telling you your board can skip it is understating it considerably.
The obligation nobody had planned for
Board-level cyber security training is a genuinely new product requirement in the Nordics and most organisations were not set up to deliver it.
It cannot be discharged by putting directors through the same module as the workforce. A board module is not about phishing recognition. It is about being able to interrogate the organisation’s risk picture, understand what the risk management measures in the legislation actually require, know the incident reporting timelines and what happens when they are missed, and understand the specific personal exposure that attaches to approving measures without oversight.
It needs to be delivered as its own session, documented individually and by name rather than as part of an aggregate completion figure, and repeated when the board composition changes. A completion export showing 96 percent of employees trained does not demonstrate that a specific director received specific training, and that is what a supervisor will ask for.
Why simulated phishing does not change behaviour on its own
Phishing simulation is the dominant product in this market and it is genuinely useful, but it measures susceptibility rather than producing competence, and the way most organisations run it actively works against the outcome they want.
Three problems recur. Click rate is a poor metric because it is easily gamed by making the simulations easier, and because a click is a single data point about a person on a single day. Punitive framing suppresses reporting, which is the behaviour you actually need, because an employee who fears consequences for clicking will stay quiet and the organisation loses the hours that matter most. And simulation trains recognition of simulated phishing, which has historically been cruder than the real thing and is now considerably cruder than what generative tooling produces.
The metrics worth tracking instead are reporting rate, meaning the proportion of suspicious messages that get reported, and time to report, meaning how long it takes from receipt to someone raising it. Both measure the behaviour that limits damage.
An organisation with a 12 percent click rate and a five-minute median reporting time is in far better shape than one with a 4 percent click rate and nobody reporting anything.
Designing for the workflow, not the threat catalogue
The structural mistake in most awareness programmes is organising content by attack type. Employees are taught about phishing, then ransomware, then social engineering, then insider threat. This is how a security professional thinks about the world and it is not how an employee encounters it.
Employees encounter security decisions inside their work. A finance assistant receives a request to change a supplier’s bank details. A recruiter opens an attachment from a stranger, which is their job. A developer needs test data. A salesperson wants to work on a customer list from a personal device on a train. Each of these is a specific moment with a specific right answer, and training that addresses the moment produces behaviour, while training that addresses the threat category produces awareness of the category.
Build the curriculum by asking each function what they actually do, then identifying the three or four decision points where a wrong choice creates real exposure. The resulting modules are shorter, more specific and considerably more useful than a comprehensive threat overview.
Role-based depth
All staff need a short common layer: authentication and why password reuse matters, recognising and reporting suspicious contact, keeping data in approved systems, physical awareness in shared spaces, and above all how and how fast to report. Keep it to the essentials and repeat it often rather than delivering it comprehensively once a year.
Finance needs the payment fraud module, because business email compromise and invoice fraud target them specifically and the losses are immediate and often unrecoverable. Verification procedure for any change to payment details, out of band and by a known number, is the single highest-value control an awareness programme can install.
HR and recruitment open attachments from unknown senders continuously and hold the most sensitive data in the organisation.
IT and developers need depth on access management, secrets handling, test data and secure configuration.
Anyone who might notice an incident first needs the reporting timeline drilled, because the NIS2 early warning is measured in 24 hours from awareness and an employee who waits until the next morning has consumed a substantial share of it.
The management body needs its own session, as above.
Evidencing it
Supervisors look for a system rather than a certificate. Keep the risk assessment that determined who needs what. Keep the management body training documented separately and by name, because in Sweden it answers a specific statutory duty. Keep content with version dates. Keep delivery records including new joiners and relevant contractors. Keep the review cycle showing when the programme was last checked against the current threat picture and what changed.
Where you decided a group needed less, record why. A documented proportionate decision is defensible. An undocumented gap is not.
The supplier question
If you are not in scope of NIS2, you may still be inside its reach. Supply chain security is one of the risk management measures in-scope entities must implement, which they discharge by passing requirements down through contracts. The result is that smaller Nordic companies with no statutory obligation receive security questionnaires and contractual clauses that assume a trained workforce.
If that describes you, the practical answer is to be able to evidence the same things an in-scope entity evidences. Doing so is also a commercial asset, because a supplier that can answer the security questionnaire quickly wins tenders from ones that cannot.
Frequency
Neither national law fixes an interval for staff training. What both frameworks look for is that measures are appropriate and current.
An annual module is the convention and it is weak on its own, because recognition decays and the threat picture moves faster than twelve months. The pattern that works is a substantive module at onboarding, short reinforcement through the year, targeted content when something changes materially, and a documented annual review of whether the programme still matches the risk. Management body training should be repeated on appointment and refreshed on a defined cycle.
Frequently asked questions
Is security awareness training a legal requirement in Finland and Sweden?
Training for the management body is explicitly required under both countries’ NIS2 implementations. Staff cyber hygiene and training sit within the risk management obligations, so their scope follows from your own risk assessment rather than a blanket statutory rule.
Does the board need cyber security training?
Yes. This is the clearest training duty in the regime, and in Sweden the statutory obligation is specifically directed at the management body rather than at the wider workforce.
How often should security awareness training be done?
No interval is fixed in either national law. Onboarding, reinforcement through the year, event-triggered updates and a documented annual review is a defensible pattern.
Does phishing simulation work?
It measures susceptibility usefully but does not by itself change behaviour, and punitive framing suppresses the reporting you actually need. Track reporting rate and time to report alongside click rate.
What should security awareness training cover?
Work outward from what each function actually does and the specific decision points where a wrong choice creates exposure, rather than covering attack categories in the abstract.
We are not in scope of NIS2. Do we still need this?
Probably yes, contractually. In-scope customers pass security requirements down through supply chain provisions, and being able to answer them is increasingly a condition of winning the work.
How do we prove our training to a supervisor?
Keep the risk assessment, dated content versions, delivery records, the management body training documented by name, and evidence of a review cycle.
Sources and further reading
- Directive (EU) 2022/2555 (NIS 2 Directive) – full text on EUR-Lex; Article 20 sets the management-body governance and training duty
- Kyberturvallisuuslaki 124/2025 – Finnish Cybersecurity Act, Finlex
- Cybersecurity Act passed by Parliament, obligations under the NIS 2 Directive enter into force 8 April 2025 – Traficom, with registration and risk-management deadlines
- Cybersäkerhetslag (2025:1506) – Swedish Cybersecurity Act, Sveriges riksdag
- Cybersäkerhetslagen – PTS overview, with a link to the government bill (Prop. 2025/26:28)
- Cybersäkerhet (NIS2) – Transportstyrelsen, an example of a Swedish sector supervisory authority
