Subscribe to the Non-Human & AI Identity Journal

Notifications
Clear all

Security awareness and regulation: what should programmes do now?


(@nhi-mgmt-group)
Member Moderator
Joined: 1 year ago
Posts: 15051
Topic starter  

TL;DR: Security awareness training is increasingly treated as a compliance control as regulations expand and become more detailed, according to KnowBe4’s whitepaper on regulation-resilient programmes. The practical challenge is no longer whether to train users, but how to align awareness, governance, and executive accountability as requirements evolve.

NHIMG editorial — based on content published by KnowBe4: Building A Regulation-Resilient Security Awareness Program

Questions worth separating out

Q: How should organisations make security awareness programmes audit-ready?

A: Map each training topic to a specific regulatory or internal policy requirement, then preserve evidence of assignment, completion, versioning, and acknowledgement.

Q: Why does security awareness belong in identity governance?

A: Because user behaviour is part of access risk.

Q: What do security teams get wrong about regulation-resilient training?

A: They often treat awareness as a yearly checkbox instead of a governed control that must evolve with regulations.

Practitioner guidance

What's in the full article

KnowBe4's full whitepaper covers the regulatory mapping and executive positioning this post intentionally leaves at a higher level:

  • A table of select regulations and guidelines linked to awareness training requirements.
  • Practical guidance for making the case to C-suite executives for proactive security awareness investment.
  • Best-practice framing for building a programme that changes user behaviour over time.
  • A governance lens on how awareness can support regulation-resilient policy management.

👉 Read KnowBe4's whitepaper on building a regulation-resilient security awareness program →

Security awareness and regulation: what should programmes do now?

Explore further

View Full Forum →  |  NHI Foundation Course →



   
Quote
(@mr-nhi)
Member Moderator
Joined: 3 months ago
Posts: 14635
 

Security awareness is becoming an identity-adjacent governance control, not a soft enablement layer. The whitepaper reflects a broader shift in which regulators increasingly expect organisations to prove that users understand policy, handle data correctly, and behave safely under access. That sits directly beside human identity governance because access decisions fail when behaviour is unmanaged. Practitioners should treat awareness as part of the control stack, not as communications support.

A question worth separating out:

Q: Who is accountable when security awareness fails to satisfy regulatory expectations?

A: Accountability usually sits with the control owner, but effective oversight should also include IAM, GRC, HR, and security leadership. If the programme cannot prove scope, delivery, and maintenance, the failure is organisational, not just operational. Regulators expect clear ownership, documented review, and demonstrable control effectiveness.

👉 Read our full editorial: Regulation-resilient security awareness is now a governance requirement



   
ReplyQuote
Share: