CYB-27 · Cyber security
Human error and social engineering are implicated in over 80% of successful cyber attacks. All staff must complete cyber security awareness training at onboarding and annually thereafter. Training must cover: phishing recognition, BEC, password hygiene, safe data handling, and incident reporting. Completion must be tracked per individual.
Trigger
No cyber awareness training programme; staff training records absent; training not completed within last 12 months; new staff not trained within 30 days of joining
Applicability gate
This is a readiness rule mapped to JS2 themes. Its presence in the library does not establish that JS2 applies directly to the firm.
Citation
This control maps to the public instruments below. The mapping does not establish entity applicability.
Remediation
Implement a cyber awareness training programme (KnowBe4, Proofpoint Security Awareness, or similar). Track completion per staff member. Include assessment with minimum pass score. Integrate into new staff onboarding checklist.
Evidence required