Framework / TRAIN

Awareness & Skills — operationalised.

The European Cybersecurity Skills Framework, operationalised.

TRAIN

Role-based learning paths mapped to ECSF, CyberHEAD and ECSM — the spine of our Security Academy.

The European cybersecurity skills gap is structural — ENISA estimates a shortfall of hundreds of thousands of professionals across the EU. Closing it requires more than ad-hoc training: organisations need a role-based competency model, a measurable learning path per role, and a culture programme that reaches every employee. We anchor our Security Academy on three ENISA assets: the European Cybersecurity Skills Framework (ECSF), the CyberHEAD database of training programmes, and the European Cybersecurity Month (ECSM) campaign.

Open Education topic on ENISA
/ KEY.FACTS
ECSF
12 typical cybersecurity professional role profiles
CyberHEAD
EU-wide database of cybersecurity higher education
ECSM
European Cybersecurity Month — every October since 2012
NIS2 Article 20
Mandatory training for management bodies
NIS2 Article 21
Basic cyber hygiene & training for all staff
/ GUIDANCE

What this framework covers

§ 01

The 12 ECSF role profiles

ECSF defines twelve typical cybersecurity professional profiles, each with its mission, deliverables, tasks, skills, knowledge and competencies. We use these as the spine of role-based learning paths.

  • Chief Information Security Officer (CISO)
  • Cyber Incident Responder
  • Cyber Legal, Policy & Compliance Officer
  • Cyber Threat Intelligence Specialist
  • Cybersecurity Architect
  • Cybersecurity Auditor
  • Cybersecurity Educator
  • Cybersecurity Implementer
  • Cybersecurity Researcher
  • Cybersecurity Risk Manager
  • Digital Forensics Investigator
  • Penetration Tester
§ 02

Three-tier awareness programme

Effective awareness is segmented, not one-size-fits-all. We deliver a three-tier programme aligned to NIS2 obligations.

  • All staff — quarterly micro-learning, simulated phishing and culture campaigns aligned to ECSM
  • Technical roles — ECSF-mapped learning paths with hands-on labs and certifications
  • Management bodies — executive briefings, board war-games and personal liability training under NIS2 Article 20
§ 03

Measurable behavioural change

Awareness only matters if it changes behaviour. We track outcome KPIs, not completion rates — phishing click rates, report rates, time-to-report, secure-by-default adoption and incident near-miss reporting.

/ THECYBERCO.SERVICE

Security Academy components

  • Role-based learning paths mapped to all 12 ECSF profiles
  • Quarterly phishing simulations with behavioural KPIs, not vanity metrics
  • Executive briefings and board war-games for NIS2 Article 20 compliance
  • ECSM-aligned October culture campaign with bespoke content
  • Career pathway design using CyberHEAD as the reference
  • Annual maturity benchmarking against ENISA's awareness raising maturity model

Talk to a cyber advisor.

Confidential consultation with our senior team.

Request Assessment