How do you know that training produced a real effect?

Michał Rutkowski • for senior management and data protection officers • published 19 August 2026 • updated 19 August 2026 • 8 min read

Legal status

August 2026. The GDPR in its consolidated version and the Polish Act on the National Cybersecurity System (KSC) as amended by the act of 23 January 2026 (Journal of Laws 2026, item 252). Assessing the effectiveness of measures: Article 32(1)(d) GDPR and Article 8(1)(2)(h) of the act; obligation of the head of the entity: Article 8d(4) and Article 8e.

Last substantive update: 19 August 2026.

Short answer

By the fact that people’s behaviour changed in specific situations and the change is visible in data the organisation collects independently of the training. Attendance, the final test score and the course rating describe how the training went, not its effect. Assessing effectiveness is not purely a management matter either. The GDPR requires regularly testing, assessing and evaluating the effectiveness of technical and organisational measures (Article 32(1)(d)) and the Polish Act on the National Cybersecurity System (KSC) lists policies and procedures for assessing the effectiveness of measures as a separate element of the information security management system (Article 8(1)(2)(h)).

Why the question comes up at all

The question usually comes up at two moments. The first is the budget conversation, when the board wants to know what the organisation got for the money spent on training. The second is harder. After an incident it turns out that the people who made the mistake had been trained and their attendance documented. In both situations the organisation has a full set of evidence that the training took place and nothing that would show what changed after it.

The source of the doubt is the way the rules frame the obligation. Neither the GDPR nor the KSC act requires you to “deliver training” as an event with its own deadline. The obligation is framed as a result. The head of an essential or important entity ensures that staff are aware of their cybersecurity obligations and know the entity’s internal rules in that area (Article 8d(4) of the KSC act). A controller implements measures appropriate to the risk and must be able to demonstrate this (Article 24(1) GDPR). Training is one of the tools leading to that state and not the state itself.

The NIS2 Directive names outright the capability the training is meant to give. Members of the management body are to follow regular training “to gain sufficient knowledge and skills in order to identify risks and assess cybersecurity risk-management practices and their impact on the services provided by the entity” (Article 20(2)). That is a ready-made assessment criterion. If after the training a board member still cannot judge whether the measures adopted match the organisation’s risk then the objective set out in the directive has not been achieved, however duly signed the certificate.

A certificate of attendance is evidence of presence, not evidence of competence. Telling those two things apart is the whole substance of the question in the title.

What to establish before deciding

What exactly was supposed to change

The effect cannot be measured if nobody wrote down before the training what was supposed to be different. “Raising awareness” is not a verifiable objective, because it identifies neither a person, nor a situation, nor a behaviour.

A verifiable objective describes behaviour in a specific process. In an organisation with distributed customer service that may be verifying the recipient before sending a document containing personal data. In a finance team — confirming a change of bank account number through a channel other than the one the request arrived on. Among process owners — submitting new processing for assessment before it goes live and not after the first complaint.

That record also settles the format of the session. Behaviour changes through an exercise carried out in conditions close to the real ones, less often after a lecture on general principles.

What the state was before the training

Without a baseline every later result is a number without meaning. The share of suspicious messages reported is a good or a bad result only against what the same organisation recorded earlier.

The organisation usually already has the data needed to build a baseline. The record of breaches kept under Article 33(5) GDPR covers all breaches, including those not reported to the authority, so it shows how often errors of a given type recur. To that are added internal reports to the security team and matters referred to the data protection officer. If the organisation is only now putting in order how such events are recognised and classified, putting the assessment of incidents and breaches in order is a step that comes before measuring training effectiveness — without a reliable record you measure the quality of the register and not people’s behaviour.

Which data show the effect and which only the activity

The table below is a practical assessment based on the typical arrangement of a medium or large organisation. It does not follow from any provision and needs adapting to the processes and risks of the particular entity.

AreaActivity indicatorEffect indicator
Email and phishingShare of people who completed the training moduleShare of suspicious messages reported by employees and the time from delivery to the first report
Errors in correspondenceScore in a knowledge test on dispatch rulesNumber of events of the same type in the breach record in successive periods
Recognising breachesNumber of training hoursShare of events detected by employees rather than by IT or by the data subject
New processes and systemsAttendance of process owners at the workshopNumber of processing operations submitted for assessment before go-live
Management under the KSC regimeDocumented attendance at training (Article 8e(3))Decisions taken after the training. Approval of measures, allocation of tasks and oversight of their performance (Article 8d)

The indicators in the second column are needed, because without them you do not know who has not taken the training. The decisive ones, however, are those in the third column, because only they speak about behaviour. The last row shows this most sharply. The act requires the attendance of the head of the entity at training to be documented but the point of that training is the performance of the tasks under Article 8d and it is there that its effect is visible.

A useful reference when building such a set is AR-in-a-Box, the toolkit of the European Union Agency for Cybersecurity (ENISA) for awareness-raising programmes. Its annual programme template has separate fields for the indicator, the measure and the means of measurement, filled in together with the topic of the session and the audience. The proposed indicators are grouped into four categories and behavioural change and the reach of the training are two different things in that split. It is good practice rather than a legal requirement, and its value lies in forcing the measures to be set before the programme starts, not after it.

When to measure

Measuring immediately after the session measures recall of the content. Measuring several months later measures the change in behaviour, which is what the training was about. A programme settled solely on a final test therefore gives a picture systematically better than the facts.

The second caveat concerns a single result. One measurement does not tell the effect of the training apart from seasonality, a change in mail traffic or a campaign that happened to hit the organisation. A conclusion emerges only from a series of measurements taken at the same rhythm, and that requires deciding in advance who runs them and where the data come from.

What to do when no effect is visible

The absence of change does not automatically mean the training was poor. There are three explanations to check, in this order.

  1. The measure is measuring something else. A rise in the number of reports is often read as deterioration, although it usually means people have started reporting instead of hiding.
  2. The process forces a workaround. If the correct behaviour takes more time than the incorrect one or requires permissions the employee does not have, training will not reverse that.
  3. The training did not match the situation. Generic material prepared without knowledge of the organisation’s processes changes behaviour in none of them.

The order matters in practice. Repeating the training is the most common response to a lack of effect and the least often the right one, because the first two explanations lie outside the training room.

How to evidence the effect rather than mere attendance

The accountability principle (Article 5(2) GDPR) places the burden of proof on the controller and in the cybersecurity regime the counterpart is the requirement to have policies and procedures for assessing the effectiveness of measures (Article 8(1)(2)(h) of the KSC act). In both cases the document is not the result itself but the trace of the decision the result triggered.

What has evidential value is a set that allows the reasoning to be reconstructed: the training objective written down as a behaviour, the measurement before and after the session, the conclusion drawn from the comparison and the decision taken on that basis together with its date. The attendance list remains necessary, because in entities covered by the KSC act documenting the attendance of the head of the entity at training is a standalone obligation (Article 8e(3)). It answers a different question, though, whether the training took place and not whether anything changed.

In organisations covered by the GDPR this area has a designated addressee. Monitoring compliance by the data protection officer expressly covers awareness-raising, training of staff involved in processing operations “and the related audits” (Article 39(1)(b) GDPR). Checking whether the training programme works is therefore a task arising from the regulation and not an extra initiative of the officer.

Supervisory practice shows what the absence looks like from the outside. In non-final decision DKN.5131.34.2023 of 13 June 2026 the President of UODO established that the effectiveness of the measures intended to ensure the security of processing had not been regularly tested or assessed by the controller, and that training for staff was delivered only after the breach. Evidence created after the event does not replace evidence from the period the proceedings concern.

The transitional layer matters here for planning. Entities that on the day the amendment to the KSC act entered into force met the criteria for being treated as an essential or important entity implement the obligations under Chapter 3 — including implementing an information security management system — within 12 months of its entry into force, that is by 3 April 2027. An organisation that starts measuring effectiveness only at the end of that period will enter it without a baseline from before.

Most common mistakes

  • Confusing the rating of the training with the assessment of its effect. A satisfaction survey tells you how participants rated the trainer. It says nothing about behaviour once they are back at work.
  • Measuring only on the day of the training. A test right after the session checks short-term memory and systematically flatters the programme.
  • Treating a rise in the number of reports as a bad result. In most organisations it is the first visible sign that the training works, not that security has deteriorated.
  • Measuring the whole organisation with a single indicator. An averaged result hides the team where nothing changed, and it is that team that sets the risk.
  • Closing the matter by repeating the training. Without checking whether the problem lies in the process, further sessions add evidence of activity and do not change the result.

Conclusions and next steps

The question “did the training work” is secondary to the question “what was supposed to change and where will we see it”. An organisation that asks it before commissioning a session gets two things at once: a programme matched to its own processes and evidence of the effectiveness of an organisational measure that the rules require of it anyway.

A sequence that works when putting this area in order:

  1. Write down the objective of each training as a behaviour in a specific process, not as a session topic.
  2. Set the baseline from data you already have: the breach record, internal reports and matters referred to the officer.
  3. Choose one effect indicator and one activity indicator for each group — the first for conclusions, the second to demonstrate reach.
  4. Plan a second measurement several months later and name the person who will carry it out.
  5. Before you order a repeat session, check whether the correct behaviour is feasible in the process concerned.
  6. Write down the decision taken on the basis of the result together with its date — that, and not the number itself, is the substance of accountability.

Once that sequence is in place, the answer to the question in the title no longer depends on the impression left by the session. The organisation shows what changed, where it is visible and what it decided to do next.

Related materials

Sources

  • Regulation (EU) 2016/679 of the European Parliament and of the Council (GDPR), Article 5(2), Article 24(1), Article 32(1)(d) and Article 39(1)(b), consolidated text — EUR-Lex: eur-lex.europa.eu (accessed 19 August 2026)
  • Act of 5 July 2018 on the National Cybersecurity System, Article 8(1)(2), Articles 8d and 8e and Annex 4, consolidated text — Chancellery of the Sejm, ISAP: isap.sejm.gov.pl (in Polish; accessed 19 August 2026)
  • Act of 23 January 2026 amending the Act on the National Cybersecurity System and certain other acts (Journal of Laws 2026, item 252), Article 33(1) — Journal of Laws: dziennikustaw.gov.pl (in Polish; accessed 19 August 2026)
  • Directive (EU) 2022/2555 of the European Parliament and of the Council (NIS2), Article 20(2) and Article 21(2) — EUR-Lex: eur-lex.europa.eu (accessed 19 August 2026)
  • Decision of the President of UODO DKN.5131.34.2023 of 13 June 2026 (non-final) — case-law database of the Personal Data Protection Office: orzeczenia.uodo.gov.pl (in Polish; accessed 19 August 2026)
  • AR-in-a-Box — a toolkit for building awareness-raising programmes together with proposed indicators for assessing their effectiveness, version 3 (2024) — European Union Agency for Cybersecurity (ENISA): enisa.europa.eu (accessed 19 August 2026)

Author

Michał Rutkowski — LabLogic. Combines legal, organisational and technological perspectives in work with the boards of medium and large organisations: support for and performance of the DPO role, NIS2 and KSC readiness, incident response, audits and training. Contact: M.Rutkowski@LabLogic.pl

Let us agree how you will recognise the effect of the next training

If the training programme in your organisation ends today with an attendance list, the first step is to name the behaviours that are to change and the data in which the change will be visible. We design training and workshops from that decision, not from the topic of the session.

This material is general and educational. It is not individual legal advice or a recommendation for any specific organisation. The scope of obligations should be assessed in the light of that organisation’s circumstances.

Legal status: August 2026.

Scroll to Top