Public sectorEvidence an auditor can verify. Not a completion rate.

Public administration is the most targeted sector in the European Union, carries the highest human-element share of any sector we compare, and is the only one where internal actors account for nearly half of breaches. It is also the sector where a fine may never arrive — and the inspection certainly will.

ENISA Threat Landscape 2025 · Verizon DBIR 2026, Public Administration (92) · 3,634 incidents
NIS2 · GDPR · ISO 27001 · ISO 27701 · EU data residency (Frankfurt) · No endpoint agents
Evidence chain
Every step independently checkable
Policy acknowledged — v3.214 Mar 09:12
Module completed — 94% coverage18 Mar 16:41
Certificate issued18 Mar 16:42
Public verification URLcheckable by a third party
Exported to SIEM — NDJSON19 Mar 02:00
Nothing here is self-reported by the browser.
Illustrative record. Timestamps and version numbers are examples.
Evidence chain
Every step independently checkable
Policy acknowledged — v3.214 Mar 09:12
Module completed — 94% coverage18 Mar 16:41
Certificate issued18 Mar 16:42
Public verification URLcheckable by a third party
Exported to SIEM — NDJSON19 Mar 02:00
Nothing here is self-reported by the browser.
Illustrative record. Timestamps and version numbers are examples.
Human risk in the public sector

NOUSEC is used by public bodies that must demonstrate a cyber-hygiene and training programme rather than merely run one. Under NIS2, central-government entities are in scope regardless of size, and Article 21(2)(g) makes cyber hygiene and cybersecurity training a minimum mandatory measure — while Article 34(7) leaves it to each member state to decide whether fines apply to public bodies at all. NOUSEC produces the artefacts an inspection asks for: policy acknowledgement with version tracking, a compliance scorecard showing raw and audit-adjusted completion, certificates with a public verification page, an audit log, and SIEM export in CSV, NDJSON or JSON — with no endpoint agents and data resident in Frankfurt.

What the data says

The most targeted sector in the Union.

38.2%[2]
of identified EU incidents targeted public administration — the most targeted sector
69%[1]
of breaches in Public Administration (92) involve the human element — the highest of the four sectors
44%[1]
of actors in the sector are internal; espionage is the motive in 33% of breaches
20%[1]
phishing as an initial access vector in the sector, second to vulnerability exploitation at 40%

Verizon's dataset is contributed casework, not a representative sample of all breaches; industry figures are for prioritisation.

The argument

In this sector the fine is optional. The inspection is not.

Most vendors sell public bodies a penalty they may never face. Here is the accurate position, and the artefact list that actually matters.

NIS2 puts central-government public administration entities in scope regardless of size, and lets member states extend it to regional and local bodies. But the enforcement chapter is not symmetrical: the temporary ban on managerial functions under Article 32(5) applies to essential entities and expressly not to public administration, and under Article 34(7) each member state decides whether and to what extent administrative fines apply to public bodies at all.[3]

So the pressure on a public-sector security team is evidentiary rather than financial. You will be asked to show that a programme exists, that people completed it, that the record is defensible, and that it can be handed to an auditor without a spreadsheet reconciliation exercise.

That is a product problem, and it is the one we built for.

Each evidence artefact, what it proves, how a third party can check it, and the tier it starts at
ArtefactWhat it provesHow it is checkableTier
Policy acknowledgement with version trackingWho accepted which version, whenPer-user record, exportableProfessional
Compliance scorecard — raw and audit-adjustedCompletion, and completion that survives a quality thresholdBoth figures shown; the discount is triggered by a quiz score below 40%Essentials
Completion evidenceTraining taken, not training assigned≥ 90% unique-second watch coverage, computed server-side; a forged completion returns 403Essentials
Certificate with public verification pageThe certificate is genuineA third party can verify it without access to your tenantProfessional
Audit logWho changed what in the programmeImmutable recordEnterprise
SIEM exportThe record leaves the platformCSV, NDJSON or JSONEnterprise
Who we have to reach

Nearly half the actors are already inside.

This is the finding that makes the public-sector page different, and it is also where we have to be careful about what we sell.

In Public Administration the DBIR records internal actors in 44% of breaches and Privilege Misuse as a top-three pattern — the only sector of the four where that is true. Espionage is the motive in a third of cases.[1]

Some of that is malice and some is error, and a security awareness platform is honest about which half it can touch. NOUSEC does not do user behaviour analytics, data loss prevention or insider-threat detection, and the components that would imply otherwise are not shipped. What it does is train and measure the behaviours that sit upstream of both: handling of sensitive records, policy acknowledgement, credential hygiene, and a reporting culture where flagging something raises your Human Risk Score rather than exposing you.

Reporting is subtractive by design. An employee who reports a suspicious message improves their own score. Exposure from a third-party breach is counted as exposure, not blame — a user in a 2017 credential dump did not choose to be there.

What you have to evidence

Scope, liability, and what an inspection asks for.

Instruments, articles, what each requires, and the NOUSEC mechanism that evidences it
InstrumentArticleWhat it requiresHow NOUSEC evidences it
NIS2[3]Art. 2(2)(f)(i)Central-government public administration entities are in scope regardless of size.
NIS2Art. 2(2)(f)(ii), 2(5)Regional entities in scope following a risk-based assessment; local bodies and education institutions at member-state discretion.
NIS2Art. 21(2)(g)Cyber hygiene and cybersecurity training as a minimum mandatory measure.Server-side completion gate; audit-adjusted scorecard.
NIS2Art. 20(1), 32(5), 34(7)Management bodies approve, oversee and can be held liable — but the managerial ban does not reach public administration, and fines are at member-state discretion.Board cohort evidence; audit log.
GDPRArt. 39(1)(b)Awareness-raising and training in the DPO's monitoring remit.Policy acknowledgement with version tracking.
ISO/IEC 27001:2022[5]Cl. 7.2 / 7.3, A 6.3Competence, awareness, training.Certificate public verification page.

Regulatory summaries are for orientation, not legal advice. Scope and classification depend on your member state's transposition.

Procurement answers

The four questions a tender always asks.

No endpoint agents

Nothing is installed on any device. The report button is an optional mail-client add-in.

EU data residency

Frankfurt, with tenant-level export and erasure.

Full white-label

Your branding, in 30 languages — nine fully localised today, twenty-one more on request.

Published methodology

The 0–100 score shows its component breakdown. No black box.

Evidence that is not self-reported

A video is complete at ≥ 90% unique-second watch coverage, computed server-side. A forged completion request returns 403.
Security awareness training

A score that shows its working

0–100 with the component breakdown published, and visible to the person being scored. Reporting subtracts.
Human Risk Score

Related reading: the Human Risk Score methodology, why NOUSEC, and the glossary entries for insider threat and pretexting. If your authority also runs plant or grid infrastructure, the same evidence chain has to satisfy two different NIS2 annexes at once. Our own posture is on Trust and Security.

What this will not do.
NOUSEC will not detect an insider exfiltrating records, and no awareness platform should claim to. We train and measure human behaviour; we do not monitor it. If your requirement is detection, that is a different control and we will say so on the call.

Questions

What a public-body security team and its procurement office ask first.

Does NIS2 apply to our authority?

Central-government entities are in scope regardless of size under Article 2(2)(f)(i). Regional entities come in following a risk-based assessment, and member states may extend the directive to local bodies and education institutions.

Can we be fined?

Article 34(7) leaves that to each member state — several have chosen not to apply administrative fines to public administration entities. The obligations under Article 21 apply either way, and so does the inspection.

What exactly can we hand an auditor?

Policy acknowledgements with versions, raw and audit-adjusted completion figures, certificates with a public verification URL, an audit log, and a SIEM export in CSV, NDJSON or JSON.

Do you monitor employees?

No. There are no endpoint agents, no behaviour analytics and no data loss prevention. The Human Risk Score is built from simulation results, training activity, credential hygiene signals and breach exposure — and every component is visible to the person being scored.

Can the platform carry our own branding?

Yes — full white-label, in 30 languages: nine fully localised today, twenty-one more on request.

Receipts

Every figure on this page, and where it came from

Last reviewed: 11 August 2026. Regulatory citations are checked against the consolidated text at EUR-Lex on each review.

  1. 2026 Data Breach Investigations Report
    Verizon Business — industry section, p. 84 for Financial and Insurance (NAICS 52). Corpus: 31,000+ incidents, 22,000+ confirmed breaches, 145 countries, Oct 2024 – Nov 2025 · 2026
    Used for: Public Administration (92) — 3,634 incidents; 69% human element; 44% internal actors; 33% espionage motive; 20% phishing against 40% vulnerability exploitation; Privilege Misuse in the top three patterns.
  2. Threat Landscape 2025
    ENISA — 13th edition, v1.2, 4,875 incidents, 1 Jul 2024 – 30 Jun 2025 · 2025
    Used for: 38.2% of identified EU incidents targeting public administration. 4,875 incidents, 1 Jul 2024 – 30 Jun 2025.
  3. Directive (EU) 2022/2555 (NIS2)
    Official Journal of the European Union, OJ L 333, 27.12.2022 · 2022
    Used for: Articles 2(2)(f), 2(5), 20(1), 21(2)(g), 32(5) and 34(7).
  4. ISO/IEC 27001:2022 and ISO/IEC 27002:2022
    International Organization for Standardization — 3rd edition · 2022
    Used for: Clauses 7.2 and 7.3; the title of Annex A control 6.3.

Bring your last audit finding.

We will show you which artefact answers it, and which one we cannot produce.

GDPR native · EU data residency (Frankfurt) · No endpoint agents · Pricing