Build a Security- Conscious Organization. Technology alone cannot stop cyber threats, your people are the last line of defense. ARLITECH's training programs build the human layer of your security architecture.
Interactive, role-based training covering phishing recognition, password hygiene, social engineering and safe browsing habits for all staff.
C-suite and board-level briefings on cyber risk, regulatory obligations (NIS2, GDPR) and strategic security investment decisions.
Hands-on technical training for IT and security teams covering threat hunting, incident response, SIEM operation and secure development.
Role-specific NIS2 training covering obligations, incident reporting procedures and security risk management requirements.
Facilitated incident response simulations testing your team's ability to detect, contain and recover from cyber incidents under realistic scenarios.
Specialized training for OT/ICS engineers and operators on industrial cybersecurity threats, best practices and secure configuration.
One mandatory e-learning a year does not change behaviour. Measurable results require a baseline measurement, targeted content and repeated reinforcement, in that order.
A phishing simulation and short knowledge assessment establish where the organisation stands today. This provides the reference point and shows which groups are most exposed.
Not everyone needs the same thing. Separate modules for management (in the form NIS2 requires), finance, IT, engineers and general staff.
On-site or online workshops built on real cases, not theory. The incident response tabletop exercise is a separate block for management and IT.
Quarterly phishing simulation, micro-learning reminders, and metric tracking. Improvement becomes quantifiable, which also satisfies the NIS2 effectiveness measurement obligation.
Training is not only risk reduction: several regulations require it explicitly and demand documentation. Attendance records and measurement reports can be attached directly to audit material.
| Requirement | Source | What it expects |
|---|---|---|
| Cyber hygiene and training | NIS2: measure 7 | Regular, documented training for all employees |
| Management training | NIS2: management liability | Mandatory, evidenced attendance by the management body |
| Effectiveness measurement | NIS2: measure 6 | Measurable indicators of training effectiveness |
| Awareness | ISO 27001 A.6.3 | Role-appropriate, repeated training |
| Data protection awareness | GDPR Article 39 | Training for staff involved in processing |
| Incident readiness | ISO 27035 | Exercises, scenario testing |
Because behaviour is not a knowledge problem. Most people know not to click a suspicious link, yet they do, if the timing and context of the message are plausible. Change requires repetition and reinforcement: regular simulation, immediate feedback, and short targeted reminders. An annual click-through module ticks the audit box but does not move the click rate.
Yes. NIS2 explicitly requires the management body to attend regular cybersecurity training and to ensure comparable training for employees. This is not a formality: management liability is one of the biggest changes NIS2 brings, and documenting the training is among the first things a regulatory inspection asks for. Our management module is therefore a separate block with different content, focused on decision situations and accountability.
The core module is 60–90 minutes, plus 30–60 minutes of role-specific content. Quarterly reinforcement is short: 5–10 minutes of micro-learning, plus the phishing simulation, which requires no dedicated time. The management module and tabletop exercise take half a day. In our experience the shorter, more frequent format works better than a full-day training.
We track three indicators. The phishing click rate is the most obvious, but misleading on its own. More important is the report rate: how many people report the suspicious message, this shows the organisation actively defends rather than merely passively avoiding mistakes. The third is time to report. These indicators are comparable quarter on quarter and directly satisfy the NIS2 effectiveness measurement expectation.
Both are available. Materials and simulation campaigns are produced in Hungarian, but we also provide English versions for international teams. In mixed organisations, a Hungarian core module is typically combined with English-language management and IT modules.