SolutionsOne platform. Four very different risk shapes.

The product does not change by sector. What changes is which framework you have to evidence, which of your people are hardest to reach, and which channel the attacker actually uses on them. Pick your sector and we will show you all three, with the source next to every number.

Verizon DBIR 2026 · ENISA Threat Landscape 2025 · 4 sectors compared
GDPR native · EU data residency (Frankfurt) · No endpoint agents
Financial servicesHealthcarePublic sectorManufacturing & energy
Constant. 0–100, published methodology.
Score components
Simulation failures
34201816
Real-world behaviour
22183220
Credential hygiene
14121614
Training
18342018
Exposure
12161432
Illustrative. Bar proportions show the shape of a sector's risk profile, not measured client data.
Financial servicesHealthcarePublic sectorManufacturing & energy
Constant. 0–100, published methodology.
Score components
Simulation failures
34201816
Real-world behaviour
22183220
Credential hygiene
14121614
Training
18342018
Exposure
12161432
Illustrative. Bar proportions show the shape of a sector's risk profile, not measured client data.
Human risk by industry

NOUSEC is a human risk management platform used across financial services, healthcare, the public sector, and manufacturing and energy. The platform is the same in every sector — phishing simulation across eight channels, adaptive training with a server-side completion gate, and a single 0–100 Human Risk Score with a published methodology. What differs by sector is the evidence you must produce, the people you must reach, and the channel the attacker uses. Financial services face DORA's compulsory training modules and voice-cloned payment fraud; healthcare's largest human exposure is error in email as much as deception; the public sector has the highest human-element share of any sector and the heaviest evidentiary burden; manufacturing and energy carry the highest third-party involvement in the Verizon DBIR.

How sectors differ

Three things change. The platform is not one of them.

Every vendor sells you an industry page. Here is what actually varies underneath one.

01 · Obligation

What you have to prove

NIS2 makes cyber hygiene and training a minimum mandatory measure for essential and important entities. DORA goes further for financial entities and names awareness training as a compulsory module. A public body may face neither a fine nor a management ban, and still has to satisfy an auditor.

02 · Workforce

Who you have to reach

A trading desk reads email all day. A nurse on a night shift does not. A machine operator may not have a workstation at all. Reach is a content-format and channel problem before it is a training problem.

03 · Channel

What the attacker actually uses

Phishing is the second most common initial access vector in financial services, healthcare and public administration alike — but the pretext differs, and in manufacturing the way in is more often a supplier than an inbox.

The data

Four sectors, side by side

Every figure below is from the sector's own section of the report named beneath it. Nothing is averaged, smoothed or estimated.

Verizon DBIR 2026 industry section
Human element, phishing, actor, motive, third-party involvement and breach patterns compared across four industry sections of the Verizon 2026 DBIR
Financial & Insurance (52)Healthcare (62)Public Administration (92)Manufacturing (31–33)
Breaches involving the human element65%54%69%56%
Phishing as initial access20%14%20%13%
External actors88%81%56%95%
Internal actors12%19%44%5%
Espionage motive3%2%33%15%
Third-party involvement34%32%36%61%
Top-three patterns cover81% of breaches81%80%91%
The human patterns inside that top threeSocial EngineeringMisc. Errors, Social EngineeringMisc. Errors, Privilege MisuseSocial Engineering

Verizon 2026 Data Breach Investigations Report, industry section, p. 84[1]. Corpus: 31,000+ incidents, 22,000+ confirmed breaches, 145 countries, Oct 2024 – Nov 2025. The DBIR is a convenience sample of contributed cases, not a representative sample of all breaches; industry sections are for prioritisation, not prediction. A dot marks the highest value in a row; the bottom two rows are not a ranking.

Read the bottom row. In financial services and manufacturing, the human pattern in the top three is deception. In healthcare, error joins it. In the public sector, so does misuse of access already held. Same phrase — “human risk” — three different problems underneath it.
Choose your sector

Start where your regulator does.

Financial services

65%[1]
breaches involving the human element

Your controls held. The voice authorising the payment was cloned. DORA names awareness training as a compulsory module, and the board has its own obligation on top.

NIS2GDPRISO 27001SOC 2BDDK
See the sector page for financial services

Healthcare

164 of 663[6]
large US breaches occurred in email

Error sits alongside social engineering in healthcare's top three breach patterns. And a clinician between shifts will not sit through twenty minutes.

NIS2GDPRISO 27001ISO 27701
See the sector page for healthcare

Public sector

69%[1]
breaches involving the human element

The most targeted sector in the EU, with the highest human-element share and the highest internal-actor share of the four. The hard part is not the training — it is the evidence.

NIS2GDPRISO 27001ISO 27701
See the sector page for public sector

Manufacturing & energy

61%[1]
breaches involving a third party

The highest third-party involvement of any sector in the DBIR, and adversaries who pretext operational staff directly. Many of the people at risk have no assigned workstation.

NIS2 (Annex I & II)GDPRISO 27001
See the sector page for manufacturing & energy
Constant across sectors

The mechanisms are the same everywhere. That is the point.

Completion is verified, not reported.

A video is complete at ≥ 90% unique-second watch coverage, computed server-side. Scrubbing to the end leaves coverage near zero.

Effectiveness is a correlation, not a completion rate.

Per-module Pearson r against real phishing click rate, suppressed below ten data points.

The score shows its working.

0–100, published methodology, never rendered without its component breakdown — including to the employee being scored.

Nothing is installed on a device.

No endpoint agents. EU data residency in Frankfurt.

Same mechanisms, whichever sector page you came from. See how each one works →

Obligations

Which rule actually names training.

Four instruments, four different demands. The article numbers matter more than the acronyms.

NIS2 — Directive (EU) 2022/2555
Art. 21(2)(g)

“Basic cyber hygiene practices and cybersecurity training” is a minimum mandatory risk-management measure. No “where appropriate” qualifier.

Art. 20(2) is the board's duty, and it only encourages employee training. The enforceable employee hook is 21(2)(g).

NIS2 — governance
Art. 20(1)

Management bodies must approve and oversee the measures, and can be held liable for infringements.

Art. 32(5)'s temporary ban on managerial functions applies to essential entities only, and not to public administration.

DORA — Regulation (EU) 2022/2554
Art. 13(6)

ICT security awareness programmes and digital operational resilience training as compulsory modules in staff training schemes, for all employees and senior management.

Art. 5(4) separately obliges the management body to keep its own ICT-risk knowledge current.

GDPR — Regulation (EU) 2016/679
Art. 39(1)(b)

Staff awareness-raising and training sit inside the DPO's compliance-monitoring remit.

A security failure under Art. 32 is the 2% / €10m tier, not 4% / €20m.

ISO/IEC 27001:2022
Cl. 7.2, 7.3 · Annex A 6.3

Competence, awareness, and the control “Information security awareness, education and training”.

Certification auditors ask for evidence of effectiveness, not attendance.

On NIS2 fines.
Article 34 requires member states to provide for maximum fines of at least €10,000,000 or 2% of total worldwide annual turnover, whichever is higher, for essential entities — and at least €7,000,000 or 1.4% for important entities. It is a floor on the national ceiling, not an EU-wide cap, and under Article 34(7) each member state decides whether fines apply to public administration entities at all. Also worth knowing: being listed in Annex I does not make you an essential entity. Size does, under Article 3.[3]
Regional fit

Written for the regulator you actually report to.

European Union

NIS2 across 18 sectors in Annexes I and II; DORA since 17 January 2025; GDPR; the ISO 27001:2022 control set. Data resident in Frankfurt.

Türkiye

KVKK to the article, not in translation: Article 12 obligations, the 72-hour notification window, and the 2026 penalty range. BDDK for regulated banking.

Everywhere else

SOC 2 and ISO 27701 selectable per tenant, full white-label and automatic currency handling.

More on the regional fit →

Questions

What buyers ask before they pick a sector page.

Do the sector pages describe different products?

No. One platform, one price structure, one score. The sector pages differ in which obligations you have to evidence, which content formats and channels reach your people, and which pretexts we simulate first.

Which regulation actually requires security awareness training?

For essential and important entities under NIS2, Article 21(2)(g) lists “basic cyber hygiene practices and cybersecurity training” as a minimum mandatory measure. For financial entities under DORA, Article 13(6) makes ICT security awareness and digital operational resilience training compulsory modules for all employees and senior management. NIS2 Article 20(2) is a separate duty on the management body, and it only encourages employee training.

We are in more than one sector. Which page applies?

All of them — the platform is one tenant. Frameworks are selected per tenant and you can enable several at once; the compliance scorecard reports against each.

Can you evidence compliance to an auditor?

Yes: policy acknowledgement with version tracking, a compliance scorecard showing raw and audit-adjusted completion, certificates with a public verification page, an audit log, and SIEM export in CSV, NDJSON or JSON.

Do you need to install anything on employee devices?

No. There are no endpoint agents. The phishing report button is an optional mail-client add-in.

Where is our data stored?

Frankfurt, with tenant-level export and erasure.

Receipts

Every figure on this page, and where it came from

Title, publisher, edition year, link, and what each one was used for. If a figure is not here, it is not on the page.

Last reviewed: 11 August 2026. Regulatory citations are checked against the consolidated text at EUR-Lex on each review.

  1. 2026 Data Breach Investigations Report
    Verizon Business — industry section, p. 84 for Financial and Insurance (NAICS 52). Corpus: 31,000+ incidents, 22,000+ confirmed breaches, 145 countries, Oct 2024 – Nov 2025 · 2026
    Used for: The sector comparison table and the four sector cards — human-element, phishing, actor, motive, third-party and top-three-pattern figures for Financial and Insurance (52), Healthcare (62), Public Administration (92) and Manufacturing (31–33). Corpus 31,000+ incidents and 22,000+ confirmed breaches across 145 countries, Oct 2024 – Nov 2025.
  2. Threat Landscape 2025
    ENISA — 13th edition, v1.2, 4,875 incidents, 1 Jul 2024 – 30 Jun 2025 · 2025
    Used for: Public administration as the most targeted EU sector. 4,875 incidents, 1 Jul 2024 – 30 Jun 2025.
  3. Directive (EU) 2022/2555 (NIS2)
    Official Journal of the European Union, OJ L 333, 27.12.2022 · 2022
    Used for: Articles 2, 3, 20, 21(2)(g), 32(5) and 34; Annexes I and II.
  4. Regulation (EU) 2022/2554 (DORA)
    Official Journal of the European Union — applicable from 17 January 2025 · 2022
    Used for: Articles 5(4) and 13(6).
  5. ISO/IEC 27001:2022 and ISO/IEC 27002:2022
    International Organization for Standardization — 3rd edition · 2022
    Used for: Clauses 7.2 and 7.3; the title of Annex A control 6.3.
  6. Annual Report to Congress on Breaches of Unsecured Protected Health Information, CY2024
    US Department of Health and Human Services, Office for Civil Rights — pp. 8–14 · 2024
    Used for: The healthcare sector card — 663 large breaches, of which 164 occurred in email.

Bring your sector's audit finding. We will show you the mechanism.

A live demo against your own regulator and your own workforce, not a slide deck.

GDPR native · EU data residency (Frankfurt) · No endpoint agents