Executive Security Training: Why the Board Goes First
Executives are the most targeted, least trained people in a company. What NIS2, DORA and the SEC require — and how to train a board without wasting time.

There is a person in your organization who can approve a nine-figure payment, whose calendar is public, whose voice is on every earnings call, whose travel is announced on LinkedIn — and who skipped the last three security training cycles because they were busy. Attackers know exactly who that person is. In most companies, the security team knows too, and has quietly accepted it.
That acceptance is becoming untenable. The most expensive social-engineering incidents of the past three years ran through executives — their identities, their authority, or their inboxes. And regulators on both sides of the Atlantic have stopped treating leadership training as optional: the EU now mandates it for management bodies, and the SEC requires boards to describe their oversight of cyber risk in public filings. This guide covers what changed, what executive training should actually contain, and how to deliver it without wasting the board's time — because wasting it is how the exemption culture started.
The exemption problem
Executives sit at the intersection of maximum privilege and maximum exposure. They hold the approval authority that business email compromise depends on — a category the FBI's Internet Crime Complaint Center calls the $55 billion scam, with $55.5 billion in exposed losses across a decade of reported incidents. Their public footprint gives attackers everything needed for convincing pretexting: org charts, deal announcements, conference schedules, speech recordings.
That last item matters more every quarter. In the Arup case, an employee in Hong Kong transferred $25.6 million after a video call in which every other participant — including the CFO — was a deepfake. Ferrari came within one question of a similar loss when an executive challenged a cloned voice of the CEO with a verification question the impostor could not answer. The FBI has warned that generative AI now amplifies these schemes and explicitly recommends verification phrases for exactly this scenario. Voice-first attacks are growing fast — CrowdStrike's threat reporting recorded a 442% increase in vishing between the first and second half of 2024 — and the highest-value pretext in a vishing call is an executive identity.
Yet in many organizations the people whose identities anchor these attacks are the least prepared to recognize them. The SANS 2025 Security Awareness Report found that 80% of organizations rank social engineering as their number one human risk — while awareness teams remain understaffed and leadership engagement remains one of their most-cited obstacles. Meanwhile the Verizon DBIR still puts the human element in 62% of breaches. Whoever the attacker impersonates, a human approves the wire.
Regulators have ended the debate
For years, executive training was a culture argument. It is now a compliance requirement in a growing set of jurisdictions — with personal consequences attached.
| Requirement | What it says | Why it reaches the boardroom |
|---|---|---|
| NIS2 Art. 20(2) | Members of management bodies "are required to follow training" on cybersecurity risk | Training for leadership is mandatory, not encouraged — encouragement is what the article reserves for regular employees |
| NIS2 Art. 20(1) | Management bodies approve and oversee risk measures and "can be held liable for infringements" | Personal liability makes cyber literacy a fiduciary skill |
| DORA Art. 13(6) | Security awareness and resilience training as "compulsory modules", applicable to senior management | EU financial entities must train the top of the house, explicitly |
| SEC cyber disclosure rules (Item 106) | Annual reports must describe "the board of directors' oversight of risks from cybersecurity threats" | Oversight you must publicly describe is oversight you must actually be competent to perform |
| SEC Form 8-K Item 1.05 | Material incidents disclosed within four business days of the materiality determination | The materiality call is an executive decision made under pressure — it can be rehearsed |
The EU provisions have teeth in practice, not just on paper: the Commission has moved through infringement steps against late member states and in July 2026 referred four countries to the Court of Justice over NIS2 transposition. The direction of travel is unambiguous.
The gap between that expectation and current board capability is wide. A NightDragon and Diligent analysis of S&P 500 boards found that 88% had no director with specialized cybersecurity experience, and only seven companies had a current or former CISO on the board. Training does not close that gap by turning directors into practitioners — it closes it by making directors capable of asking the right questions and making the decisions that are theirs to make.
The board does not need to know how an attack works. It needs to know what it will be asked to decide during one — and to have decided most of it in advance.
What executive training must cover that staff training doesn't
An executive wears three hats in a human-risk program, and a useful curriculum addresses all of them.
The target. Executives and their assistants face a distinct attack surface: whaling emails engineered around live deals, voice clones built from earnings calls, urgent requests that exploit the fact that saying no to a CEO feels dangerous. Training here is concrete: the out-of-band verification protocol for any payment or credential request, the verification-question habit that saved Ferrari, a review of what their public footprint gives an attacker, and explicit permission — stated by the CEO, to the whole company — that declining an unverified "executive" request is always safe. Our guide to deepfake voice attacks on finance teams covers the mechanics in depth.
The decision-maker. When an incident lands, the executive team owns the decisions no runbook can automate: whether an incident is material, when the 8-K clock or NIS2's 24-hour early-warning clock starts, what gets said to customers, when to involve law enforcement. These decisions go badly when made for the first time at 2 a.m. — and well when rehearsed. That is the case for one social-engineering tabletop exercise per year with genuine executive participation, built around a scenario your own simulation data says is plausible.
The example. Gartner has projected that by 2027, half of large-enterprise CISOs will adopt human-centric security design. No such program survives visible executive exemption. When leadership completes training first, appears in simulation cohorts, and asks for human-risk metrics in business reviews, the security team stops selling the program — the organization's status structure sells it for them.
How to build the program: six steps
1. Brief the board like a board. Directors process risk, money and liability all day; awareness videos insult that competence. Replace them with a 45-minute briefing built on your own data — simulation outcomes by department, real reported attacks, one anonymized near-miss — plus the two or three decisions you need from the board. Frameworks like NIST's guidance on cybersecurity learning programs emphasize role-based content; the board is the most role-specific audience you have.
2. Sequence leadership first, visibly. Whatever the annual program is, the management body completes it before the rest of the company, and internal comms say so. Under NIS2 Article 20 this ordering is close to what the law implies anyway: the body that approves the risk measures trains on them.
3. Harden the executive office as a system. The target is rarely just the executive — it is the executive's assistant, the delegated inbox, the family office, the personal phone used for MFA. Map who can act in the executive's name, then apply the same verification rules to that whole surface. Attackers who fail against the CFO routinely succeed against the person who manages the CFO's calendar.
4. Simulate against executives — with consent. Run targeted phishing and vishing simulations against the leadership cohort under agreed rules of engagement: channels in scope, confidentiality of individual results, no public scoreboards. The output is doubly valuable — it measures the most consequential attack surface you have, and nothing earns board attention for the wider program like their own results.
5. Rehearse the clock. Once a year, tabletop a scenario that forces the decisions above: a deepfake-authorized payment discovered on day three, a materiality determination with incomplete facts, a 24-hour early-warning deadline landing on a Friday night. Capture every hesitation as a finding and fix the process, not the people.
6. Measure the cohort like any other. Executive results — simulation outcomes, report rates, verification-protocol adherence, training currency — belong in the same human risk score framework as everyone else's, reported back to the board as a trend. A leadership cohort that watches its own risk score fall stays engaged in a way no compliance attestation achieves.
Where these programs fail
Three failure modes account for most dead executive-training initiatives. The first is the generic module: sending the board the same e-learning as the warehouse team signals that the exercise is compliance theater, and directors respond accordingly. The second is the gotcha simulation: an unannounced test that embarrasses a named executive converts your most important sponsor into your most motivated opponent — consent and confidentiality are what make executive simulation sustainable. The third is training the executive but not the office: the assistant with delegated inbox access and the controller who executes payments are part of the same target system, and a program that hardens only the principal leaves the attack path intact.
The pattern behind all three is the same: executive training works when it respects the audience's time, uses their own data, and treats them as owners of decisions rather than consumers of content. The organizations that get this right tend to discover a compounding return — because when the top of the house takes verification seriously, everyone below suddenly finds it much easier to say "let me call you back."
Frequently asked questions
Is security training for boards and executives legally required?
Increasingly, yes. Under NIS2 Article 20(2), members of the management bodies of essential and important entities in the EU are required to follow cybersecurity training; Article 20(1) makes management approve and oversee risk measures and makes members personally liable for infringements. DORA Article 13(6) requires financial entities to include ICT security awareness and resilience training as compulsory modules for all employees and senior management. In the US there is no federal training mandate for boards, but SEC rules require public companies to describe the board's oversight of cybersecurity risk in their annual report, which is hard to do credibly if the board has never been trained.
How is executive security training different from standard awareness training?
It has to cover three roles at once. Executives are targets, so they need attack-specific preparation: whaling, voice cloning, requests routed through assistants. They are decision-makers, so they need to rehearse incident decisions such as materiality calls and regulatory notification deadlines. And they are examples, so their visible participation matters as much as their knowledge — training completed first by the leadership team changes how the rest of the organization treats the program. A generic annual module addresses none of these.
How often should executives receive security training?
Treat it as a rhythm, not an event. A practical cadence is one focused board briefing per year tied to the organization's own incident and simulation data, one tabletop exercise per year that rehearses an executive-level decision, and short just-in-time updates when the threat picture changes — for example when finance-team deepfake fraud or a new regulatory deadline becomes relevant. Regulators that mandate training, like NIS2, expect it to be regular rather than one-off.
Should executives be included in phishing simulations?
Yes, and they should be told so in advance. Exempting executives creates exactly the blind spot attackers exploit, and simulation data from targeted campaigns is the most persuasive briefing material a security team can bring to a board. Agree rules of engagement first: which channels are in scope, who sees individual results, and how findings are reported. The goal is measurement and rehearsal, not embarrassment — results should feed the same risk metrics used for everyone else.
NOUSEC simulates attacks across 8 channels and turns the results into one number your board can read.
Book a demo