Awareness is a control. Govern it like one.
Training completion usually lives in an LMS that nobody outside HR opens. Phishing results live in a second tool. And once a year someone exports both into a spreadsheet for the auditor — a snapshot that is already out of date when it is attached.
NIS2 makes it explicit: basic cyber hygiene practices and cybersecurity training are a required risk-management measure, not a nice-to-have. TruSecure governs awareness like any other control — the training platform stays the system of record, and completion, coverage and simulation results are read continuously through connectors, mapped to every framework that requires them.
How it works
- Connect
Scoped, read-only connectors read completion rates, curriculum assignments and phishing-simulation results from your LMS, HR system and awareness tooling. The tools run the training; TruSecure reads the outcomes.
- Map
Training obligations map onto the shared control model once. One completion record answers NIS2, ISO 27001 and SOC 2 at the same time, because each cites the same control.
- Flag
When coverage slips — a department behind on the annual cycle, new joiners never assigned, a phishing click rate climbing — it surfaces as a reviewable gap with a named owner, not a line in a report nobody reads.
- Evidence
Completion snapshots are captured on a schedule and approved by a person. “Show me training coverage for the last twelve months” becomes a lookup, not a scramble.
What awareness coverage looks like
- Population
- 412 employees
- Completed
- 389 of 412 · 94%
- Phishing click rate
- 3.1% · falling
- Citations
- NIS2 21(2)(g) · ISO A.6.3
- Next cycle
- 2026-10-01
Which regulations it maps to
| Framework | What it expects | Citation |
|---|---|---|
| NIS2 | Basic cyber hygiene practices and cybersecurity training | Art. 21(2)(g) |
| ISO 27001 | Awareness, education and training provided and tracked | A.6.3 |
| NIST CSF 2.0 | Personnel aware and trained on their responsibilities | PR.AT |
| SOC 2 | Commitment to competence — training tracked and ongoing | CC1.4 |
Already running a dedicated awareness or phishing platform? The security-awareness and HR connectors read completion, assignment and simulation state directly from it — TruSecure enriches what you have rather than asking you to migrate your curriculum.
The auditor’s question is never “do you do training?” — it is “show me who was trained, on what, and when.” That answer now lives in the same control model as every other answer, cited by every framework that asks. AI does the chasing — the reminders, the rollups, the evidence assembly; your people decide what the program should achieve.
The monitoring loop
continuous · every 6 hours- 01
01
Connect
Read-only connectors into AWS, Azure, GCP, on-premise.
AWSAzureGCPon-prem - 02
02
Collect
AI pulls compliance evidence every 6 hours — not at audit time.
every 6 h - 03
03
Detect
Gaps and control drift flagged the moment they appear.
24/7 - 04
04
Remediate
Routine fixes closed automatically; the rest routed to you.
auto - 05
05
Approve
A named person decides. The approval is the record.
logged
The 80/20 advantage. AI handles the tedium — evidence, testing, gap analysis, routine fixes. Your team keeps the interesting 20%: strategic decisions, policy exceptions, risk acceptance.