On Thursday 1 October 2026, Alert Online kicks off Cybersecurity Month at KPN in Hilversum. Across the EU, October is European Cybersecurity Month (ECSM), an annual campaign coordinated by ENISA and the European Commission. In the Netherlands the campaign is run by the Alert Online partner network, which includes the Ministry of Economic Affairs, ECP (the Dutch platform for the information society) and the NCSC, the Dutch National Cyber Security Centre. Free material is ready to use: visuals, flyers, a pub quiz and a guide to get started.
It is a good moment to draw attention to cyber-secure behaviour. It is also a moment to ask yourself an honest question: is awareness in your organisation a campaign that starts in October and fades away in November, or a demonstrable part of your management system?
Why a campaign alone is not enough
Human action plays a role in the majority of security incidents. An employee clicks a phishing link, reuses a password or leaves a setting open that should have been closed. Technology catches a lot, but not everything. Behaviour is therefore a control, just like a firewall or multi-factor authentication.
The problem with a one-off campaign is not its content but the lack of follow-up. The posters come down, the quiz is done, and six months later nobody can say who took part, what was learned and whether behaviour actually changed. That last point is exactly what an auditor or regulator wants to know.
What standards and legislation ask of you
Awareness is no longer an optional topic. Three frameworks you will probably recognise:
ISO 27001:2022
Clause 7.2 requires you to determine the necessary competences, fulfil them and retain evidence. Clause 7.3 requires employees to be aware of the information security policy, their own contribution and the consequences of non-compliance. Control 6.3 in Annex A (information security awareness, education and training) makes this concrete: periodic awareness, appropriate to the role, and kept up to date.
Dutch Cybersecurity Act
The Dutch Cybersecurity Act, the national implementation of NIS2, obliges board members of essential and important entities to follow training and keep their knowledge up to date. The Act also encourages organisations to train employees periodically. Demonstrability is central: the board must be able to show that this has been organised.
NEN 7510
For healthcare, NEN 7510, the Dutch information security standard for the health sector, asks the same. Anyone working with patient data must know what is expected of them, and the organisation must be able to substantiate that.
The common denominator: the question is not whether you do awareness, but whether you can demonstrate who learned what, when, and what effect it had.
A programme for October: four weeks, four themes
Cybersecurity Month lends itself perfectly to a compact programme you can repeat every year. A structure that works well in practice:
The Alert Online campaign material is free and ready to use. The added value lies in what you organise around it: measurement, registration and repetition.
Measuring and recording: how behaviour becomes demonstrable
Do you want to be able to show in December, or at the audit in spring, what October delivered? Then record the following for each activity:
Without these six points, awareness remains a feeling. With them, it becomes a managed control, with evidence.
How uComply helps
In uComply you record October's awareness activities as tasks with an owner and a deadline, linked to the corresponding control for control 6.3 and clause 7.2 of ISO 27001, or to the training obligation in the Cbw/NIS2 control framework. Because you link one control to multiple standard requirements, the same campaign counts directly towards ISO 27001, NEN 7510 and the Dutch Cybersecurity Act. Attendance lists, quiz results and the phishing simulation report are attached to the control as evidence, so the substantiation no longer has to be hunted down at audit time.
With Reminders and scheduled tasks you plan the annual repetition once as a series; uComply automatically reminds the owner before the deadline and tasks simply appear in Outlook. The Flightdeck dashboard shows the implementation status of the controls and progress per standard, so management and the board can see that awareness is not a loose activity but a working control. For the content, the templates for communication plans and awareness activities in the content packs help you get started.
Summary
Cybersecurity Month starts on 1 October 2026 and the Alert Online campaign material is available free of charge. Use it, but organise around it what a campaign does not provide: measurement before and after, registration per employee, evidence linked to the standard and a fixed annual repetition. That way you satisfy ISO 27001, NEN 7510 and the Dutch Cybersecurity Act with the same effort, and you can show it.
Would you like to see how to embed awareness as a demonstrable control in your management system? Book a no-obligation demo or view our pricing.



