Awareness & Skills — operationalised.
The European Cybersecurity Skills Framework, operationalised.
Role-based learning paths mapped to ECSF, CyberHEAD and ECSM — the spine of our Security Academy.
The European cybersecurity skills gap is structural — ENISA estimates a shortfall of hundreds of thousands of professionals across the EU. Closing it requires more than ad-hoc training: organisations need a role-based competency model, a measurable learning path per role, and a culture programme that reaches every employee. We anchor our Security Academy on three ENISA assets: the European Cybersecurity Skills Framework (ECSF), the CyberHEAD database of training programmes, and the European Cybersecurity Month (ECSM) campaign.
Open Education topic on ENISA- ECSF
- 12 typical cybersecurity professional role profiles
- CyberHEAD
- EU-wide database of cybersecurity higher education
- ECSM
- European Cybersecurity Month — every October since 2012
- NIS2 Article 20
- Mandatory training for management bodies
- NIS2 Article 21
- Basic cyber hygiene & training for all staff
What this framework covers
The 12 ECSF role profiles
ECSF defines twelve typical cybersecurity professional profiles, each with its mission, deliverables, tasks, skills, knowledge and competencies. We use these as the spine of role-based learning paths.
- ›Chief Information Security Officer (CISO)
- ›Cyber Incident Responder
- ›Cyber Legal, Policy & Compliance Officer
- ›Cyber Threat Intelligence Specialist
- ›Cybersecurity Architect
- ›Cybersecurity Auditor
- ›Cybersecurity Educator
- ›Cybersecurity Implementer
- ›Cybersecurity Researcher
- ›Cybersecurity Risk Manager
- ›Digital Forensics Investigator
- ›Penetration Tester
Three-tier awareness programme
Effective awareness is segmented, not one-size-fits-all. We deliver a three-tier programme aligned to NIS2 obligations.
- ›All staff — quarterly micro-learning, simulated phishing and culture campaigns aligned to ECSM
- ›Technical roles — ECSF-mapped learning paths with hands-on labs and certifications
- ›Management bodies — executive briefings, board war-games and personal liability training under NIS2 Article 20
Measurable behavioural change
Awareness only matters if it changes behaviour. We track outcome KPIs, not completion rates — phishing click rates, report rates, time-to-report, secure-by-default adoption and incident near-miss reporting.
Security Academy components
- Role-based learning paths mapped to all 12 ECSF profiles
- Quarterly phishing simulations with behavioural KPIs, not vanity metrics
- Executive briefings and board war-games for NIS2 Article 20 compliance
- ECSM-aligned October culture campaign with bespoke content
- Career pathway design using CyberHEAD as the reference
- Annual maturity benchmarking against ENISA's awareness raising maturity model