
PCI DSS 4.0 Security Awareness Training Requirements
PCI DSS v4.0 raised the bar for security awareness, naming phishing and social engineering explicitly. Here is what the standard now requires if you handle card data.
Security awareness tips, industry news, and product updates.

PCI DSS v4.0 raised the bar for security awareness, naming phishing and social engineering explicitly. Here is what the standard now requires if you handle card data.

The EU AI Act is no longer theoretical. From the AI-literacy duty to deepfake transparency rules, here is what security and awareness teams need to act on now.

empowsec reporting dashboards consolidate training completion, phishing simulation results, and risk scores into a single view - filterable by user, department, or company - with the same data available via API for your existing BI tools.

empowsec issues verifiable completion certificates every time a learner finishes an assignment or course, giving compliance teams clean, downloadable PDF evidence they can present to auditors without any extra effort.

empowsec lets you bundle modules into courses, assign them to users or departments with due dates, automate reminders and manager escalations, and set up annual renewals - so compliance training runs itself rather than requiring manual follow-up.

empowsec delivers training in each employee's own language: modules, courses, interactive lessons, and phishing templates all support per-language translations, with bulk import tooling and hreflang SEO for public pages.

The NIS2 Directive requires organizations to implement cybersecurity awareness training. Here's exactly what the regulation demands, who it applies to, and how to build a compliant program.