Glossary · NIS2
Cyber Hygiene
The Article 21(g) measure covering basic security practices and cybersecurity training for all staff.
Explained in depth: The 10 NIS2 security requirements
Article 21(2)(g) requires "basic cyber hygiene practices and cybersecurity training". Cyber hygiene refers to the routine, foundational practices that prevent the majority of common attacks: timely software updates and patching, strong password policies combined with MFA, least-privilege access, hardware and software inventories, network segmentation, and regular awareness training so employees recognise phishing and social engineering. The directive's recitals describe cyber hygiene as a common baseline that should be maintained across the organisation. Combined with the training duty for management bodies under Article 20, NIS2 effectively requires security awareness at every level, from the board to every employee with a mailbox.
Why it matters
Most successful attacks still start with an unpatched system or a phished credential. Cyber hygiene is the cheapest of the ten measures to get right, and documented patch routines and training records are quick wins in any audit.
