NIS2 and the Frontline: Why Compliance Now Depends on Every Employee in the Building

Part 4 of the NIS2 Compliance Series by Garzon Cyber Solutions. Part 1 examined the board’s exposure. Part 2 explored the CISO’s operational burden. Part 3 addressed the CTO’s infrastructure debt. This final instalment turns to the workforce itself and to the question that lies at the heart of every governance framework: does the organisation actually function as the documentation says it does?
Cybersecurity regulation in Europe is no longer a technical compliance exercise. It has become an operational-resilience question, and increasingly a commercial one. Boards that once treated cyber risk as a line item in the IT budget are discovering that investors, customers, regulators, and insurers now evaluate governance maturity as a proxy for business quality.
NIS2 sits at the centre of that shift. But the directive did not create the pressure. It codified something the market was already demanding: evidence that an organisation can protect itself, respond when things go wrong, and demonstrate accountability at every level of the business.
The first three parts of this series examined what that means for the board, the CISO, and the CTO. This final piece addresses the part of the organisation where compliance either holds or collapses: the people who use the systems every day.
The Operating Environment Has Changed
The threat landscape that NIS2 was designed to address is not static. According to ENISA’s 2025 Threat Landscape report, the agency analysed 4,875 incidents across the EU between July 2024 and June 2025. Phishing accounted for 60% of all intrusion access points. Ransomware remained the most impactful threat category, with 82 distinct variants deployed against EU member state organisations during the reporting period.
Verizon’s 2024 Data Breach Investigations Report, which analysed over 10,600 confirmed breaches across 94 countries, found that 68% involved a human element. Not just phishing. Social engineering, credential misuse, and simple operational error. When combined, ransomware and extortion now account for 32% of all confirmed breaches globally, according to the same report.
These are not fringe risks affecting a handful of sectors. They are structural features of the operating environment, and they are accelerating. AI-supported phishing campaigns represented more than 80% of observed social engineering activity worldwide by early 2025, according to ENISA. The industrialisation of attack tools through Phishing-as-a-Service platforms has effectively eliminated the barrier to entry for threat actors.
For organisations operating under NIS2, this is the context in which every governance, training, and access control decision is now evaluated.
The Compliance Gap Is Larger Than Most Boards Realise
CyberSmart’s 2026 NIS2 research, conducted across 670 business leaders in nine European countries, found that only 16% of in-scope organisations are fully compliant. 84% are not ready. 11% of respondents were unsure what NIS2 is, even though it falls within its scope.
That gap is not primarily a technology problem. Most organisations possess the technical capability to meet NIS2’s requirements. What they lack is a governance structure, operational discipline, and workforce readiness to make those capabilities function under pressure.
IBM’s 2024 Cost of a Data Breach Report illustrates the cost of that gap. The global average breach cost reached a record $4.88 million, a 10% year-on-year increase. Organisations with severe security staffing shortages paid $1.76 million more per breach than those with adequate teams. The ISC2 2024 Cybersecurity Workforce Study estimates a global shortage of 4.8 million security professionals and reports a 0.7% contraction in the European workforce during the reporting period.
The economics are straightforward. Organisations that cannot recruit, retain, and train security-aware professionals incur higher breach costs, experience longer detection cycles, and struggle to meet the regulatory timelines imposed by NIS2.

Where Frontline Readiness Fails
Article 20 of the NIS2 directive requires management bodies to undergo cybersecurity training and ensure that employees receive equivalent training regularly. Article 21 lists cyber hygiene practices and training among the ten mandatory risk management measures. The obligation extends, as ENISA’s 2025 guidance on mapping NIS2 to workforce role profiles makes clear, to every individual with access to the organisation’s networks: full-time employees, contractors, temporary staff, and external suppliers with credentials.
In practice, most organisations fall short in three areas.
The first is human-level detection capability. ENISA’s 60% phishing figure is not simply a technology failure. It is a training failure. The frontline employee who receives a well-crafted phishing email is the organisation’s first and often only opportunity to detect the intrusion before it progresses. An employee who recognises the attempt and reports it through the correct channel triggers the incident response process at the earliest possible stage. An employee who clicks triggers the 24-hour reporting clock, often without the security team knowing it has started.
The second is shadow IT. Gartner’s 2024 enterprise software analysis estimated that 75% of employees use applications outside their IT department’s visibility. CyberArk’s 2024 Identity Security Threat Landscape Report places that figure at 80% across mid-market and enterprise organisations. Each unapproved tool creates an unmonitored surface outside the CISO’s visibility, the CTO’s architecture, and the compliance team’s evidence base. The Cloud Security Alliance’s 2024 State of Cloud Security report found that 45% of data breaches now originate in cloud environments, with misconfiguration and shadow deployments accounting for a significant proportion.
Under NIS2, the organisation cannot provide evidence of monitoring systems it does not know exist. It cannot demonstrate access control over applications it has not assessed. And it cannot meet incident-reporting timelines for breaches originating in environments it is not monitoring.
The third is access hygiene. Verizon’s 2024 DBIR attributed 31% of all breaches over the past decade to stolen credentials. The Ponemon Institute’s 2024 Cost of Insider Threats study puts the average annual cost of credential misuse at $4.1 million per organisation. Article 21 of NIS2 requires multi-factor authentication, continuous or adaptive authentication, and secure communication systems. These are technical controls, but their effectiveness depends entirely on workforce compliance. Password reuse, shared accounts, and unmanaged personal devices are each both security risks and citable compliance failures.
The 24-Hour Clock and the Human Factor
Article 23 requires organisations to submit an early warning to their national CSIRT within 24 hours of becoming aware of a significant incident. That clock does not start when the CISO is informed. It starts when anyone in the organisation becomes aware.
IBM’s 2024 report found that organisations with trained incident response teams and tested playbooks reduced breach costs by an average of $2.66 million. Internal detection shortened the breach lifecycle by 61 days and saved nearly $1 million compared to breaches disclosed by the attacker.
The implication is clear. The speed at which a frontline employee recognises something unusual and escalates it through the correct channel directly determines whether the organisation meets its regulatory obligations. An employee who hesitates, who assumes it is probably nothing, who waits until Monday, who does not know the escalation path, has consumed hours of the 24-hour window before the security team knows the clock is running.
This is why NIS2’s training requirement is not about awareness in the abstract. It is about building the operational reflexes that enable the organisation to detect, escalate, and report at the speed required by regulation.
What This Means Commercially
There is a commercial dimension to workforce readiness that extends beyond the regulatory penalty framework.
75% of the business leaders surveyed in CyberSmart’s 2026 research see a competitive advantage in NIS2 compliance, with 27% describing that advantage as significant. Investors, enterprise customers, and procurement teams are increasingly evaluating governance maturity and cyber resilience as part of due diligence. In regulated sectors, the ability to demonstrate workforce training, access governance, and incident readiness is becoming a condition of doing business rather than a differentiator.
For individuals, the picture is equally clear. ENISA’s mapping of NIS2 obligations to the European Cybersecurity Skills Framework role profiles makes explicit what the talent market has been signalling for several years. Cybersecurity literacy is becoming a baseline professional requirement across regulated industries. The employee who demonstrates genuine competence in security awareness, access control, and incident reporting is more valuable in this regulatory environment than the employee who treats compliance training as a box to tick.
Closing the Gap
Garzon Cyber Solutions works with organisations to build the human and structural layers of cybersecurity resilience: the governance frameworks, compliance architectures, and specialist talent that turn regulatory obligations into operational capability.
Cybersecurity and Risk Advisory. We work alongside leadership teams to assess security posture, design monitoring and response strategies, and build incident readiness in line with NIS2 requirements. From phishing simulation programmes to full security architecture review, we help organisations understand where they are exposed and what it will take to close the gaps. Where specialist accreditation or deep technical capability is required, we work alongside trusted partners to deliver.
Compliance and Regulatory Readiness. We translate regulatory obligations into operational specifications that engineering, legal, and leadership teams can execute against. NIS2, DORA, ISO 27001, SOC 2, and the EU AI Act. Compliance is not a document. It is an operating model, and we help organisations build it.
Specialist Technology and Cybersecurity Recruitment. We source and place security professionals at every level: GRC analysts, security architects, DevSecOps engineers, IAM specialists, and senior leadership governing the programme. We understand the brief because we advise the organisations doing the work. In a market where ISC2 reports a global shortage of 4.8 million people, access to the right talent is not a convenience. It is a strategic requirement.
NIS2 enforcement does not stop at the boardroom. It reaches every desk, every device, and every employee with network access. The organisations that recognise this, that invest in their frontline, their governance, and their operational resilience, will be the ones that pass the audit, retain customer confidence, and build the institutional trust that compounds over time.
Those who treat compliance as a cost will eventually discover it was always an investment.
Sources: ENISA, Threat Landscape Report, 2025. ENISA, Mapping NIS2 Obligations with ECSF Role Profiles, 2025. NIS2 Directive (EU) 2022/2555, Articles 20, 21, and 23. Verizon, Data Breach Investigations Report, 2024. IBM, Cost of a Data Breach Report, 2024. ISC2, Cybersecurity Workforce Study, 2024. Ponemon Institute, Cost of Insider Threats Global Report, 2024. CyberArk, Identity Security Threat Landscape Report, 2024. Cloud Security Alliance, State of Cloud Security Report, 2024. Gartner, Enterprise Software Usage Analysis, 2024. CyberSmart, NIS2 Compliance Research, 2026.
Where does this sit on your own risk register?
A short, practical conversation about where the exposure actually is, and what a proportionate response looks like. No obligation and no product pitch.
Start the Conversation →