Awareness training and vulnerability management under Section 30 of the BSIG

Section 30 of the BSIG requires cyber hygiene, training, and systematic vulnerability management. What that means in practice — from phishing simulations to a clinically prioritized vulnerability scan.

Awareness Training and Vulnerability Management: What Section 30 BSIG Demands Operationally

Section 30 BSIG is the normative backbone of NIS2 — ten mandatory areas that every affected entity must implement. From risk registers to supply chain security and multi-factor authentication. The majority of these ten points remain abstract for management boards and IT directors: What does "risk analysis" mean in practice? How deep must "supply chain security" go?

Two obligations are different. They are operationally immediately tangible, they produce weekly measurable data, and they form the interface where cybersecurity meets daily hospital life: cyber hygiene and training (Point 7) and security in acquisition, development, and maintenance (Point 5). In practice, this translates into two central disciplines: Awareness Training and Vulnerability Management.

This guide shows what Section 30 BSIG operationally demands for these two areas — and what a NIS2-compliant implementation in a hospital, a medical care center (MVZ), or a pharmaceutical company practically means. Not as an abstract compliance discussion, but as a concrete playbook.

Three preliminary remarks. First: Awareness and VM are not two independent obligations, but rather two halves of the same task. Human and machine are the two major attack surfaces — securing only one does not solve the problem. Second: Both areas are the first to be inspected in the event of an audit because they have tangible artifacts (training records, scan reports). Third: NIS2 has raised the bar — a one-off e-learning course or an annual vulnerability scan is no longer sufficient.

Awareness — What Section 30 BSIG Demands

Section 30 (2) No. 7 BSIG demands "concepts and procedures for cyber hygiene as well as training in the area of security of network and information systems". The NIS2 Directive concretizes this in Art. 21 (2)(g): Training must enable staff to "detect, prevent, and minimize the impact of cyberattacks".

This sounds general — and is often interpreted too generally. In practice, BSI auditors, certified public accountants, and cyber insurers ask for concrete evidence:

  • Who was trained when, with what content, and for what duration?

  • How is the learning effect measured?

  • What adjustments are made when click rates increase?

  • How are new employees onboarded into the system?

  • How is the management itself trained (obligation under Section 38 BSIG)?

What is not enough. A one-off 30-minute mandatory video during onboarding with a checkbox confirmation. This was still standard in 2018, but by 2026 it is neither regulatorily nor practically sufficient. Yesterday's typical phishing clicker does not learn from today's quiz questions — they learn from concrete, realistic simulations taking place in daily hospital routine.

What is enough. A combination of three components:

  1. Annual core course with consistent content (phishing detection, password hygiene, data protection, reporting channels) and documented participation.

  2. Regular phishing simulations (typically monthly) that reflect real attack patterns from the healthcare sector — fake HIS emails, forged duty roster changes, fake e-prescription notifications.

  3. Microlearning spotlights several times a year on current topics (cloud phishing, MFA bypass, AI-generated emails, sectoral threats).

This triple combination virtually documents itself: training system logs for Point 1, phishing platform reports for Point 2, spotlight participation for Point 3. Prepared as an audit report — done.

Important: Awareness is not an IT task, but rather one of personnel development. IT provides the platform, but content, frequency, and tone belong in HR's hands. Otherwise, awareness very quickly becomes technical compliance theater that staff experience as patronizing.

Awareness in Operational Implementation

What does this look like in practice? Four components that together form a NIS2-compliant awareness architecture:

Format: Microlearning instead of frontal lecturing. A 60-minute webinar once a year that nobody listens to is not proof of training — it is a compliance fiction. What has proven successful: Four to five short modules of 4 to 5 minutes each, completed on the end device, with a small knowledge check per module. Staff can integrate this during waiting periods or breaks — acceptance is significantly higher than with mandatory appointment formats.

Frequency: Annual core course plus three spotlights per year. The core course covers the basics (phishing, password, data protection, reporting channel). The spotlights complement the program with three short refreshers — one to two minutes long, in quarters without a core course, without repeating the previous year. This means the training obligation applies all year round, not just once in January.

Target Groups: Differentiated, not one-size-fits-all. Nursing, medical services, administration, IT, and management have different attack vectors and different learning needs. Nursing staff need examples from daily ward routine (fake HIS warnings, forged duty roster changes). Administration needs CEO fraud scenarios and invoice manipulation. IT needs privileged account risks. Management needs whaling examples plus a regulatory overview.

Phishing Simulation as an Effectiveness Measurement. Training without subsequent measurement is training in the dark. Phishing simulations are the only method that reliably shows whether training content has sunk in. The central key metrics:

  • Click rate: Who clicks on simulated phishing links? (Expected trend: 25% to 35% baseline → below 10% after 12 months)

  • Reporting rate: Who actively reports suspicious emails? (Expected trend: below 5% baseline → over 30% after 12 months)

  • Repeat click rate: Do employees repeatedly click after receiving training feedback? (Indicator of structural risk in individual teams)

Important to know: In Germany, phishing simulations are subject to codetermination under Section 87 (1) No. 6 BetrVG. A clean works agreement featuring anonymization, definition of purpose, and a prohibition of use for personnel measures is a prerequisite for launching.

Documentation for Audits. Concrete artifacts that must be kept in the ISMS file:

  • List of conducted training sessions with date, content, duration, participants

  • Individual training certificates (anonymized or pseudonymized)

  • Quarterly analysis of phishing simulations showing trends

  • Annual evaluation of awareness program effectiveness

  • Proof of management training according to Section 38 BSIG (with agenda and participant list)

Vulnerability Management — What Section 30 BSIG Demands

Vulnerability management is not named as a separate obligation in Section 30 BSIG. It is distributed across two points:

  • Point 5: Security in acquisition, development, and maintenance of network and information systems. This is where patch management, vulnerability treatment, and secure configuration reside.

  • Point 10: Multi-factor authentication and secured voice, video, and text communications. This is where MFA hygiene and secured remote access land — both closely integrated with vulnerability management.

What the standard leaves open: Frequency, depth, SLAs. NIS2 deliberately avoids detailed specifications in favor of "state of the art". This is regulatorily elegant — but operationally confusing, because "state of the art" is not an audit criterion you can simply tick off.

In practice, the following translation has established itself:

Asset Inventory as a Mandatory Basis. Vulnerability management without an asset inventory is blind. If you do not know which devices are connected to the network — servers, workstations, medical devices, IoT, mobile endpoints — you cannot scan for vulnerabilities. A complete asset inventory with categorization (type, OS, patch level, location, owner) is the first mandatory deliverable.

Scanning Frequency. State of the art is continuous scanning for IT infrastructure, not selective checks. External (internet-exposed) systems: daily. Internal systems: weekly. Scanning once a year does not meet the state of the art. Medical devices, on the other hand, are not actively scanned — industry best practice (HHS 405(d)) is passive network discovery combined with CVE comparison and SBOM analysis, because active scans on IoMT devices can cause failures in clinical operations.

Authenticated Scanning. Not all vulnerabilities are visible from the outside. Authenticated scanning — meaning: with valid login credentials on the target systems — uncovers configuration weaknesses, outdated libraries, local patch levels, and default credentials. Unauthenticated scanning only sees the exterior and regularly underestimates the actual risk.

Clinically Weighted Prioritization. A CVSS score of 9.8 on an office printer web interface is less critical than a CVSS 7.2 in the PACS server. The generic CVSS rating must be clinically contextualized — proximity to patients, criticality of care, backup options. Otherwise, IT teams patch spectacular but uncritical gaps first and medium-sized but care-critical ones last.

Remediation SLAs. State of the art does not dictate "patch everything immediately", but "risk-prioritized treatment with SLAs". Common in NIS2-compliant setups: critical vulnerabilities (CVSS ≥ 9, exploitable, exposed) within 7 to 14 days, high vulnerabilities within 30 days, medium within 90 days. If you document that you are not patching, you document compensating measures — additional network segmentation, intensified monitoring, restricted access.

Vulnerability Management in Operational Implementation

In practical implementation, four critical components emerge:

Continuous Asset Discovery, Not Selective. Hospital networks change daily. New medical devices are connected, maintenance personnel bring laptops, cloud workloads come and go. Classic inventory Excel files are outdated 24 hours after creation. State of the art: agent-based asset tracking combined with network discovery.

Medical Devices as a Special Case (IEC 80001-1). In the clinical environment, a special rule applies: patches on medical devices are subject to the MDR and can affect the manufacturer's conformity assessment procedure. An unauthorized security patch by the hospital IT can technically mean a modification of the medical device — with liability consequences. Solution: Document patch requests to the manufacturer, measure response times, implement compensating measures (network segmentation, monitoring) in the event of patch delays.

Authenticated Scanning of Critical Systems. HIS, PACS, LIS, Active Directory, backup systems — the core infrastructure must be authenticated scanned, not just from the outside. Common findings in hospital setups:

  • Outdated libraries in Java and Python-based applications (Log4Shell class)

  • Missing patches on workstations because updates only run during maintenance windows

  • Default credentials on medical devices ("admin/admin", "service/service")

  • Unsecured maintenance interfaces (Telnet, old SMB versions)

  • Inconsistent permissions in Active Directory

Remediation with SLA and Escalation. Every critical vulnerability is assigned an owner, an SLA, and an escalation path. If the manufacturer does not deliver a patch within 14 days, the hospital escalates to compensating measures — additional network segmentation, intensified monitoring, or temporary decommissioning of the affected system if necessary.

Documentation for Audits. Concrete artifacts:

  • Asset inventory with patch status and owners

  • Weekly scan reports with diff compared to the previous month

  • Quarterly trend reports by care area

  • List of open vulnerabilities with risk assessment, SLA, and compensating measures

  • Manufacturer correspondence regarding medical device patches

  • Annual penetration test or external validation

The separation between "we scan" and "we manage vulnerabilities" is essential here. The scan is the simpler half. The harder half is the accompaniment from detection to closure — and the documentation that not everything can be fixed, but everything has been assessed.

Awareness and Vulnerability Management as a Double Lever

Why not just one of the two? Because human and machine are two structurally different attack surfaces that do not compensate for each other.

The Human is the Initial Vector. Verizon Data Breach Investigations Report 2024: 68 percent of all incidents involved a human element — mostly phishing or credential theft. Awareness without VM means: employees recognize phishing emails, but if an attacker gets in anyway, they find an unpatched system in which they can move freely.

The Machine is the Amplifier. Verizon DBIR 2024 showed a 180 percent increase in vulnerability exploitation as an initial vector; in the 2025 report, this share grew by another 34 percent to 20 percent of all breaches. VM without awareness means: no successful phishing click opens the door — but web server vulnerabilities or VPN gaps are directly exploitable.

Both Support Section 32 BSIG Preparation. In the event of an incident, BSI auditors ask for both training records and vulnerability treatment reports. If you cannot produce awareness documentation during an incident, you have no protective shield in fine proceedings — and the same applies if you cannot produce VM data.

Connection to Section 38 BSIG Managing Director Liability. In the event of a dispute, the personal liability of the management is not assessed on abstract strategies, but on concrete operational evidence. Awareness and VM are the two areas that produce the most evidence — clean reports show duty of supervision fulfilled, missing reports show breach of duty.

Operational Synergy. Awareness and VM share data: those who click in the phishing simulation are often sitting at a system with uninstalled patches. Those who report vulnerabilities have usually been through awareness training beforehand. The two disciplines complement each other not only regulatorily, but operationally — when set up as an overall system rather than two isolated projects.

What Is Asked in an Audit

In a BSI audit or a financial audit regarding NIS2, awareness and VM are the first areas to be checked — because they produce operationally tangible artifacts. Typical questions:

Awareness:

  • Who was trained last year? Present list with date and content.

  • How do you measure the effectiveness of your training? Present phishing simulation reports from the last 12 months.

  • How is management itself trained? Present training log with agenda and list of participants.

  • What happens to employees who repeatedly fail phishing tests? Show escalation concept.

  • How are new employees onboarded into the awareness system? Document onboarding process.

Vulnerability Management:

  • Is there an asset inventory? Is it complete and up to date?

  • When did the last scan take place? Authenticated or unauthenticated?

  • How are vulnerabilities prioritized? Present list of currently open critical findings.

  • How is SLA compliance? Trend over the last twelve months.

  • How are medical devices treated? Present manufacturer correspondence.

  • When did the last penetration test take place? Report and remediation status.

Three points typically lead to audit findings:

1. Training without effectiveness measurement. If you roll out content but do not run phishing simulations, you cannot provide proof of effectiveness.

2. Incomplete asset inventory. Forgotten medical devices, mobile endpoints not captured, cloud workloads outside the inventory logic.

3. Patch SLA is pure theory. On paper a 14-day SLA, in practice a 90-day reality without documented compensating measures.

These points are not found out of spite — they are the most common real vulnerabilities.

Common Mistakes

"We have an awareness platform, after all." Owning a license is not an awareness program. If you have a platform but do not run it systematically, you have not solved the compliance risk.

"Vulnerability management is handled by the MSSP." A common assumption, often wrong. Many managed service contracts only cover detection, not remediation. Clarify in the contract: Who scans, who prioritizes, who closes, who documents?

"Awareness is a mandatory exercise." Staff detect this within weeks. If you treat awareness as a formal compliance task, you get formal compliance — not behavior change.

"Patches block hospital operations." Sometimes this is true. But in that case: risk assessment, compensating measures, documentation. Do not just ignore the patch and hope for the best.

"We want to avoid audit theater overhead." Understandable — and wrong. Without documentation, there is neither insurance coverage nor a line of defense against Section 38 BSIG liability in the event of an incident.

"We will do managing director training next year." Section 38 BSIG is not postponed — the obligation has applied since December 6, 2025. Anyone who has not yet documented training is without proof in the event of an incident.

Conclusion

Awareness training and vulnerability management are the two halves of an operational NIS2 implementation that become visible first in the event of an audit. Section 30 BSIG requires them, Art. 21 NIS2 concretizes them, Section 38 BSIG tightens responsibility via the personal liability of the management.

What both areas share: They only work as continuous ongoing operations, not as a project with a start and an end. Awareness without monthly phishing simulations and quarterly spotlights fizzles out. VM without weekly scanning and SLA tracking is compliance theater.

What both areas share: They produce data that are the most important evidence in an audit. Those who have the data are regulatorily prepared. Those who do not have it are without a protective shield in fine proceedings.

What both areas share: They are demanding in terms of internal implementation because they require ongoing operations. A hospital with three IT staff can rarely manage 24/7 vulnerability management alongside daily business — and a systematic awareness program with differentiated target groups, monthly campaigns, and management reporting even less so. This is precisely where managed services come in: they deliver continuous operations without the facility having to employ specialists themselves.

At Entropy CS, we offer Managed Awareness Training and Managed Vulnerability Management specially for the healthcare sector — hospital-specific phishing scenarios, monthly cadence, NIS2-compliant documentation, and reporting for management and audits. Our free Risk Assessment takes 30 minutes and provides an honest evaluation of your current maturity level in both areas — including concrete priorities for the next 12 months.