Dimitris Koupatsiaris, Cybersafe
Walk into almost any small or medium enterprise (SME) in Athens or any of the major cities in Greece, and you will find an office utilizing digital technologies, investing heavily in antivirus software, firewalls, and cloud storage backup solutions. But if you look closely at the workstation where those security licenses are active, you will find the real wildcard: the employee sitting at the keyboard.
In our first blog post for the SOC4SME project, we explored how an outsourced Security Operations Center acts as a community guardian for e-businesses. In our second post, we warned against the outdated “big sky, small bullet” mentality and detailed the essential components of a strong corporate defense posture. Now, as the SOC4SME initiative is in its implementation phase, we confront the most critical diagnostic vulnerability facing Greek business owners: failing to measure personnel behavior before deploying advanced technical defenses.
Knowledge is Not Behavior: The Core Diagnostic Problem
Many executives confuse cybersecurity awareness with cybersecurity behavior. Sending your staff a yearly PDF of safety rules or hosting a single presentation on password hygiene is a good start, but it does not tell you how an employee will act under pressure.
A true personnel behavioral assessment is a deliberate, measured diagnostic of the workforce’s real-world reactions to threat indicators. Without establishing this human baseline, you are essentially installing an expensive security system on a building while leaving the back windows unmonitored and hoping the keys are never dropped.
A rigorous behavioral assessment checks for several critical operational patterns:
- Controlled Phishing Simulations: Do employees spot sophisticated social engineering indicators, or do they inadvertently hand over credentials?
- Active Reporting Rates: When an employee identifies a suspicious email, do they simply delete it, or do they immediately alert the internal IT contact point?
- Credential Handling Under Pressure: Are employees bypassing corporate access policies to complete tasks faster on their mobile devices?
Integrating Human Baselines into the SOC4SME Platform
As a specialized partner in the SOC4SME consortium, Cybersafe focuses on turning these diagnostic insights into actionable security resilience. Within the project structure, our work directly interfaces with WP4 (Baseline Analysis) and WP3 (Tool Harmonization and Endpoint Enablers).
The Technical Reality: A Security Operations Center (SOC) is incredibly efficient at monitoring network anomalies and pushing endpoint alerts. However, if an enterprise has not evaluated its internal behavioral baseline, the SOC is left to sort through excessive false positives generated by preventable human errors.
Furthermore, as the Lead Beneficiary for WP5 (Evaluation), Cybersafe tracks the operational impact of the pilot deployments across Greek businesses. The data collected from our pilot evaluations demonstrate that technical tools deliver a significantly higher return on investment when paired with an initial human risk assessment.
The NIS2 Regulatory Mandate: Compliance Demands Proof
For businesses operating within critical sectors, ranging from courier services and manufacturing to food distribution, regulatory compliance is no longer a checklist of suggestions. The NIS2 Directive (EU 2022/2555) and its Commission Implementing Regulation (EU) 2024/2690 carry strict, enforceable legal obligations.
Specifically, Group 8 Requirements (of NIS2) dictate that cybersecurity training cannot simply be an unchecked administrative item. The European Commission explicitly mandates the following structural rules:
| Regulatory Focal Points | Legal Operational Requirements |
| Section 2.1: Effectiveness Testing | The corporate awareness-raising program shall, where appropriate, be tested in terms of effectiveness based on the current threat landscape. |
| Section 2.4: Behavioral Training | Training must cover explicit technical instructions regarding secure mobile operations and behavior when security-relevant events occur. |
According to the guidelines outlined by the Greek National Cybersecurity Authority (NCSA) in their Cybersecurity Handbook, proving this compliance requires verifiable tracking records. You cannot legally satisfy an auditor by pointing to generic training videos; you must present data demonstrating that your personnel’s security behavior has been actively tested, evaluated, and improved over time.
Conclusion: Establish Your Baseline First
Digital transformation requires a parallel commitment to human security diagnosis. Before purchasing additional technical tools, take the time to run a dedicated behavioral baseline analysis on your workforce. Understanding exactly where your team stands is the only reliable way to close your business’s hidden structural vulnerabilities.
- Track the Progress: Visit the official SOC4SME portal to monitor the ongoing pilot evaluation results and discover how holistic SOC integrations protect evolving Greek enterprises.
- Assess Your Risk: If you want to identify your team’s behavioral blind spots, contact Cybersafe today for a comprehensive, localized personnel diagnostic tailored to your business footprint.
Fun fact: The value of realistic training (train as you fight)
General George S. Patton is widely known for his colorful personality and hard-driving leadership style. Through his charisma, exemplified by a flamboyant and well-publicized image, he personified the offensive spirit, the ruthless drive, and the will for victory in battle.
He is less known, however, for being an advocate of operational training as a central component of combat effectiveness. As a matter of fact, many of the incidents that made him known for his intolerance for complacency and laxity took place during operational training. Although the motto “train as you fight, fight as you train” is not attributed to Patton, he was a strong advocate of harsh, realistic combat training that ultimately saved lives during actual combat.
Obviously, no one is suggesting that office employees should enter a boot camp of some sort. However, just as production personnel became accustomed to safety procedures, such as fire safety, by conducting drills among other activities, cybersecurity training cannot be effective unless it is exercised under pressure, in order for the personnel to respond adequately under the exerted pressure of the actual cyber attacks.


