NOUSEC is a human risk management platform used across financial services, healthcare, the public sector, and manufacturing and energy. The platform is the same in every sector — phishing simulation across eight channels, adaptive training with a server-side completion gate, and a single 0–100 Human Risk Score with a published methodology. What differs by sector is the evidence you must produce, the people you must reach, and the channel the attacker uses. Financial services face DORA's compulsory training modules and voice-cloned payment fraud; healthcare's largest human exposure is error in email as much as deception; the public sector has the highest human-element share of any sector and the heaviest evidentiary burden; manufacturing and energy carry the highest third-party involvement in the Verizon DBIR.
Three things change. The platform is not one of them.
Every vendor sells you an industry page. Here is what actually varies underneath one.
What you have to prove
NIS2 makes cyber hygiene and training a minimum mandatory measure for essential and important entities. DORA goes further for financial entities and names awareness training as a compulsory module. A public body may face neither a fine nor a management ban, and still has to satisfy an auditor.
Who you have to reach
A trading desk reads email all day. A nurse on a night shift does not. A machine operator may not have a workstation at all. Reach is a content-format and channel problem before it is a training problem.
What the attacker actually uses
Phishing is the second most common initial access vector in financial services, healthcare and public administration alike — but the pretext differs, and in manufacturing the way in is more often a supplier than an inbox.
Four sectors, side by side
Every figure below is from the sector's own section of the report named beneath it. Nothing is averaged, smoothed or estimated.
| Financial & Insurance (52) | Healthcare (62) | Public Administration (92) | Manufacturing (31–33) | |
|---|---|---|---|---|
| Breaches involving the human element | 65% | 54% | 69% | 56% |
| Phishing as initial access | 20% | 14% | 20% | 13% |
| External actors | 88% | 81% | 56% | 95% |
| Internal actors | 12% | 19% | 44% | 5% |
| Espionage motive | 3% | 2% | 33% | 15% |
| Third-party involvement | 34% | 32% | 36% | 61% |
| Top-three patterns cover | 81% of breaches | 81% | 80% | 91% |
| The human patterns inside that top three | Social Engineering | Misc. Errors, Social Engineering | Misc. Errors, Privilege Misuse | Social Engineering |
Verizon 2026 Data Breach Investigations Report, industry section, p. 84[1]. Corpus: 31,000+ incidents, 22,000+ confirmed breaches, 145 countries, Oct 2024 – Nov 2025. The DBIR is a convenience sample of contributed cases, not a representative sample of all breaches; industry sections are for prioritisation, not prediction. A dot marks the highest value in a row; the bottom two rows are not a ranking.
Start where your regulator does.
Financial services
Your controls held. The voice authorising the payment was cloned. DORA names awareness training as a compulsory module, and the board has its own obligation on top.
Healthcare
Error sits alongside social engineering in healthcare's top three breach patterns. And a clinician between shifts will not sit through twenty minutes.
Public sector
The most targeted sector in the EU, with the highest human-element share and the highest internal-actor share of the four. The hard part is not the training — it is the evidence.
Manufacturing & energy
The highest third-party involvement of any sector in the DBIR, and adversaries who pretext operational staff directly. Many of the people at risk have no assigned workstation.
Which rule actually names training.
Four instruments, four different demands. The article numbers matter more than the acronyms.
“Basic cyber hygiene practices and cybersecurity training” is a minimum mandatory risk-management measure. No “where appropriate” qualifier.
Art. 20(2) is the board's duty, and it only encourages employee training. The enforceable employee hook is 21(2)(g).
Management bodies must approve and oversee the measures, and can be held liable for infringements.
Art. 32(5)'s temporary ban on managerial functions applies to essential entities only, and not to public administration.
ICT security awareness programmes and digital operational resilience training as compulsory modules in staff training schemes, for all employees and senior management.
Art. 5(4) separately obliges the management body to keep its own ICT-risk knowledge current.
Staff awareness-raising and training sit inside the DPO's compliance-monitoring remit.
A security failure under Art. 32 is the 2% / €10m tier, not 4% / €20m.
Competence, awareness, and the control “Information security awareness, education and training”.
Certification auditors ask for evidence of effectiveness, not attendance.
Written for the regulator you actually report to.
European Union
NIS2 across 18 sectors in Annexes I and II; DORA since 17 January 2025; GDPR; the ISO 27001:2022 control set. Data resident in Frankfurt.
Türkiye
KVKK to the article, not in translation: Article 12 obligations, the 72-hour notification window, and the 2026 penalty range. BDDK for regulated banking.
Everywhere else
SOC 2 and ISO 27701 selectable per tenant, full white-label and automatic currency handling.
Questions
What buyers ask before they pick a sector page.
Every figure on this page, and where it came from
Title, publisher, edition year, link, and what each one was used for. If a figure is not here, it is not on the page.
Last reviewed: 11 August 2026. Regulatory citations are checked against the consolidated text at EUR-Lex on each review.
- 2026 Data Breach Investigations ReportVerizon Business — industry section, p. 84 for Financial and Insurance (NAICS 52). Corpus: 31,000+ incidents, 22,000+ confirmed breaches, 145 countries, Oct 2024 – Nov 2025 · 2026Used for: The sector comparison table and the four sector cards — human-element, phishing, actor, motive, third-party and top-three-pattern figures for Financial and Insurance (52), Healthcare (62), Public Administration (92) and Manufacturing (31–33). Corpus 31,000+ incidents and 22,000+ confirmed breaches across 145 countries, Oct 2024 – Nov 2025.
- Threat Landscape 2025ENISA — 13th edition, v1.2, 4,875 incidents, 1 Jul 2024 – 30 Jun 2025 · 2025Used for: Public administration as the most targeted EU sector. 4,875 incidents, 1 Jul 2024 – 30 Jun 2025.
- Directive (EU) 2022/2555 (NIS2)Official Journal of the European Union, OJ L 333, 27.12.2022 · 2022Used for: Articles 2, 3, 20, 21(2)(g), 32(5) and 34; Annexes I and II.
- Regulation (EU) 2022/2554 (DORA)Official Journal of the European Union — applicable from 17 January 2025 · 2022Used for: Articles 5(4) and 13(6).
- ISO/IEC 27001:2022 and ISO/IEC 27002:2022International Organization for Standardization — 3rd edition · 2022Used for: Clauses 7.2 and 7.3; the title of Annex A control 6.3.
- Annual Report to Congress on Breaches of Unsecured Protected Health Information, CY2024US Department of Health and Human Services, Office for Civil Rights — pp. 8–14 · 2024Used for: The healthcare sector card — 663 large breaches, of which 164 occurred in email.