NIS2Art. 21(2)(g)voice-validated
NIS2 Art21g: Art. 21(2)(g)
Network and Information Security Directive 2 (EU 2022/2555)
AL
Founder at SQUR · last verified 2026-10-06
Regulation text
Essential and important entities must implement basic cyber hygiene practices and cybersecurity training. This includes user awareness programs, secure password practices, multi-factor authentication where appropriate, and regular training on emerging threats and proper security behavior.
ATT&CK techniques this article tests · 15
| Technique | Why it maps | Confidence |
|---|---|---|
| T1566 | 1. User awareness programs and regular training, as mandated by Art. 21(2)(g), directly reduce the success rate of phishing attempts by educating users on identifying malicious communications. | 90% |
| T1133 | 1. Multi-factor authentication and secure password practices, required by Art. 21(2)(g), significantly harden external remote services against unauthorized access. | 80% |
| T1078 | 1. Secure password practices and multi-factor authentication, per Art. 21(2)(g), directly prevent unauthorized use of valid accounts by adversaries. | 90% |
| T1098 | 1. Secure password practices and MFA, as specified in Art. 21(2)(g), make it substantially more difficult for adversaries to manipulate or compromise accounts. | 80% |
| T1110 | 1. Multi-factor authentication and secure password practices, mandated by Art. 21(2)(g), directly mitigate brute force attacks by increasing credential complexity and requiring additional verification. | 90% |
| T1003 | 1. Basic cyber hygiene and user awareness, as per Art. 21(2)(g), reduce the likelihood of initial compromise, thereby limiting opportunities for OS credential dumping. | 70% |
| T1539 | 1. User awareness programs, outlined in Art. 21(2)(g), educate users on avoiding social engineering tactics that lead to session cookie theft. | 70% |
| T1027 | 1. Regular training on emerging threats and proper security behavior, as per Art. 21(2)(g), enhances user ability to identify and avoid obfuscated malicious content. | 70% |
| T1087 | 1. Secure password practices and MFA, required by Art. 21(2)(g), limit the utility of discovered accounts by making them harder to compromise. | 70% |
| T1021 | 1. Multi-factor authentication and secure password practices, specified in Art. 21(2)(g), protect remote services from unauthorized access, hindering lateral movement. | 80% |
| T1005 | 1. User awareness programs and proper security behavior, as per Art. 21(2)(g), reduce the risk of users inadvertently exposing or collecting sensitive data for adversaries. | 70% |
| T1105 | 1. User awareness and training on proper security behavior, mandated by Art. 21(2)(g), help prevent users from executing or allowing ingress of malicious tools. | 70% |
| T1041 | 1. General cyber hygiene and user awareness, as per Art. 21(2)(g), contribute to a more secure environment, making it harder for adversaries to establish and use C2 channels for exfiltration. | 60% |
| T1485 | 1. Comprehensive basic cyber hygiene practices, including secure passwords and MFA from Art. 21(2)(g), reduce the overall attack surface and likelihood of successful attacks leading to data destruction. | 60% |
| T1059 | 1. User awareness and training on proper security behavior, as per Art. 21(2)(g), help users identify and avoid executing malicious scripts or commands. | 70% |
Defending mitigations · 6
| Mitigation | What it does | Confidence |
|---|---|---|
| M1032 | 1. Art. 21(2)(g) explicitly requires the implementation of 'multi-factor authentication where appropriate,' directly addressing this mitigation. | 100% |
| M1027 | 1. Art. 21(2)(g) explicitly mandates 'secure password practices,' directly aligning with the establishment and enforcement of password policies. | 100% |
| M1017 | 1. Art. 21(2)(g) explicitly requires 'user awareness programs' and 'regular training on emerging threats and proper security behavior,' directly implementing user training. | 100% |
| M1038 | 1. Secure password practices and multi-factor authentication, as per Art. 21(2)(g), are fundamental components of effective user account management, ensuring secure access. | 90% |
| M1040 | 1. User awareness programs and training on emerging threats, as specified in Art. 21(2)(g), enhance the effectiveness of antivirus/antimalware by reducing user-initiated infections. | 70% |
| M1035 | 1. Secure password practices and multi-factor authentication, required by Art. 21(2)(g), are critical for limiting access to resources to authorized individuals. | 80% |
Underlying weaknesses · 7
| CWE | Why it persists | Confidence |
|---|---|---|
| CWE-521 | 1. Art. 21(2)(g)'s requirement for 'secure password practices' directly addresses and mitigates the weakness of weak password requirements. | 100% |
| CWE-287 | 1. The mandate for 'multi-factor authentication' and 'secure password practices' in Art. 21(2)(g) directly counters improper authentication vulnerabilities. | 100% |
| CWE-307 | 1. Secure password practices and multi-factor authentication, as per Art. 21(2)(g), significantly reduce the success of excessive authentication attempts like brute force attacks. | 90% |
| CWE-200 | 1. 'User awareness programs' and 'proper security behavior' training, as required by Art. 21(2)(g), aim to prevent the exposure of sensitive information by users. | 80% |
| CWE-798 | 1. 'Secure password practices,' as mandated by Art. 21(2)(g), discourage the use of hard-coded credentials by promoting proper credential management. | 70% |
| CWE-601 | 1. 'User awareness programs' and 'regular training on emerging threats,' specified in Art. 21(2)(g), help users identify and avoid malicious open redirects used in phishing. | 70% |
| CWE-306 | 1. 'Multi-factor authentication' and 'secure password practices,' as per Art. 21(2)(g), ensure that critical functions are protected by robust authentication mechanisms. | 80% |
What SQUR Covers
Web application + API pentesting for OWASP Top 10, business logic flaws, authentication bypass, injection attacks, and other application-layer vulnerabilities. €1,995 per scan, 24-hour turnaround, EU-only data.
What SQUR Does Not Cover
Internal network pentesting, endpoint security testing, physical security assessments, social engineering, or ICT third-party concentration risk reviews. Engage a complementary provider for those scope items.
Provenance
Mapped Q2.2026 using gemini-2.5-flash · €0.0187 compute · voice-rubric self-validated