Yes. In Australia, businesses can require contractors to complete security awareness training as a written condition of their engagement, and in many cases they should: the Privacy Act 1988 expects organisations to take reasonable steps to protect personal information, and recent reform commentary specifically contemplates training for all staff and contractors with access to that information.
TL;DR
- Nothing stops a business from making training a contractual condition for contractors — you set the terms of engagement.
- Australian privacy law expects anyone who touches personal information, including contractors, to be trained and access-controlled.
- Contract language is what makes training enforceable: a completion condition, a deadline, and a consequence for non-completion.
- Best practice treats contractors as first-class users of the training program — same courses, same phishing simulations, same reporting.
- Frameworks clients audit against (Essential 8, SMB1001, ISO 27001) expect contractor training to be evidenced, not assumed.
Why the question matters more than it sounds
Contractors sit in an awkward spot in most security programs. They have email addresses, system logins and access to client data, but they sit outside the HR umbrella that covers employees. Many businesses run security awareness training only through their HR system — so every contractor, temp and outsourced bookkeeper quietly skips it.
That gap matters because attackers do not distinguish. Phishing remains the number one initial access vector for attacks against Australian organisations in the ASD's threat reporting — and a phishing email does not check whether the recipient is on your payroll. The contractor with a mailbox is as reachable as the employee (FOIT).
What the law actually requires
Australian law does not name a universal "mandatory security training" statute that covers every business. What it does require, broadly, is reasonable care:
- Privacy Act 1988 (Cth) — organisations must take reasonable steps to protect personal information they hold, and destroy or de-identify it when no longer needed. Commentary on Australia's recent privacy reforms notes that organisations should review and implement training for "all staff and contractors with access to personal information" as part of meeting their security obligations (Piper Alderman).
- Sector obligations — regulated sectors such as financial services, health and critical infrastructure carry additional cybersecurity requirements beyond the Privacy Act (ICLG).
- Framework expectations — the Essential Eight is not legally mandated for most private companies, but it is mandatory for Australian federal government agencies, and both it and ISO 27001 expect security awareness to be part of the control set, applied to the workforce including contractors (KM Tech).
If a contractor handles your customers' personal data, untrained access is a risk you documented but did not manage — the worst position to be in after a breach, and a serious one if penalties apply. Serious or repeated privacy breaches can now attract penalties of up to $50 million under the Privacy Act.
Can you make training a condition of engagement?
Yes, and the mechanism is contractual. A business engaging an independent contractor can include, in the services agreement or the contractor's onboarding pack:
- a requirement to complete nominated security awareness training before system access is granted;
- refresher training at a set cadence (annual is the usual rhythm);
- participation in phishing simulations run through the business's platform;
- a consequence clause — suspension of access or termination for refusal.
This is standard commercial practice, not legal overreach. You are not compelled to give system access to anyone; conditioning access on training is simply risk management expressed as a contract term. Two caveats: make the requirement proportionate (a short course plus simulations for a contractor with an email account; deeper role-based training for one with production access), and get the requirement into the written agreement before the first day, not after the first incident.
One practical caution: training records about contractors are personal information too. Collect completion data, store it, and share it only for security purposes — the same discipline you apply to employee records.
What contractors actually need trained
Contractors need the same fundamentals as employees, tuned to what they touch:
- Phishing and business email compromise — the contractor's inbox is a genuine attack surface, and attackers increasingly target outsourced roles precisely because they assume training is thin.
- Data handling — what the contractor may download, store, forward or retain, and what must stay inside your environment.
- Device and account hygiene — MFA on any account that touches your systems, no credential sharing across clients, separate personal and work accounts.
- Incident reporting — who the contractor notifies, and within what timeframe, when something looks wrong.
For contractors whose role is genuinely high-risk — outsourced finance functions, IT administrators, anyone with payment authority — add a role-specific module beyond the baseline.
How to run it without doubling your admin
The mistake most businesses make is running a separate contractor program. Don't. Run one program with two lists:
- One platform, one course library. Invite contractors into the same security awareness training program employees use, tagged as contractors so reporting separates them.
- Same phishing simulations. Include contractor mailboxes in your phishing simulation schedule — attackers target them anyway, and excluding them blinds you to half the risk.
- Completion as an access gate. Tie the onboarding checklist to course completion: no certificate, no system login. Automation makes this a rule, not a chase.
- Contractor-specific reporting. When a client or auditor asks for evidence, human risk reporting that splits employees from contractors answers the question directly.
- Framework mapping. A gap assessment against Essential 8, SMB1001 or ISO 27001 will surface contractor coverage as a control gap if it is missing — better to find it in a review than in an audit.
If you are evaluating platforms for this, check that they support external user accounts and separate reporting before you sign — compare on that feature, not just price.
The compliance payoff
Contractor training is one of those items that costs little and answers a lot:
- It evidences "reasonable steps" under the Privacy Act when regulators ask how personal information was protected.
- It satisfies the contractor-training expectation in client and insurer security reviews.
- It closes the audit finding that "security training applies to employees only" — a finding that recurs when businesses grow through contractors and temps.
Evidence beats intention: completion certificates, simulation participation records and a training policy that names contractors are what a reviewer actually wants to see.
FAQ
Can businesses legally mandate security training for contractors? Yes. Training can be set as a written condition of engagement, with access suspension or termination as the consequence for refusal.
Are contractors required to do security training by law in Australia? No standalone statute mandates it for every business, but the Privacy Act's reasonable-steps expectation and recent reform commentary put contractors with access to personal information inside the training obligation in practice.
Who pays for contractor security training? Whatever the agreement says. Most businesses either include it in the engagement terms at their own cost, or permit the contractor to complete an equivalent course and provide the certificate.
Should contractors be included in phishing simulations? Yes. They receive real phishing at the same rate as employees, and their responses are part of your risk picture.
What happens if a contractor refuses training? The contracted consequence applies — typically suspension of system access until completion, or termination of the engagement if access is essential to the role.