Trade businesses work from vans, workshops, building sites, home offices and supplier portals. Cyber security awareness training for trade businesses and tradies has to protect payment approvals, customer details and email accounts without assuming everyone sits at a desk all day.
TL;DR
- Train tradies on invoice redirection, lookalike domains, fake login pages and urgent supplier requests.
- Verify every bank-detail change through an established phone number or face-to-face contact before paying.
- Use strong passphrases and multi-factor authentication on business email, accounting and cloud systems.
- Run short, role-specific lessons for owners, office staff, site supervisors, apprentices and contractors.
- Rehearse one reporting route and retest within 30 days so the rule survives the next busy work period.
Why this matters
The Australian Cyber Security Centre has warned that criminals are targeting construction companies with business email compromise. The observed pattern is simple: an attacker impersonates a legitimate business, asks a customer to change bank details, and diverts an invoice payment to an account controlled by the scammer. Lookalike domains and hacked email accounts make the message feel familiar at a glance.
That risk applies beyond large builders. A plumbing business, electrical contractor, landscaper, roofing company or HVAC firm may send invoices, approve subcontractors and share plans through the same email account. One compromised mailbox can expose customer conversations, supplier details, tax documents and payment instructions at the exact moment a job is under pressure.
The ACSC recommends verifying payment-related requests, securing email with strong passphrases and multi-factor authentication, and training staff to recognise suspicious bank-detail changes and login requests. Those controls are practical for a trade business because they reinforce the decisions people already make every day.
Cyber Aware’s security awareness training is relevant when a business needs recurring lessons, quizzes and completion reporting rather than a once-a-year reminder. The aim is not to turn a tradie into a security analyst. It is to make the safe action the fastest action when a message arrives between two jobs.
Who this is for
This guide is for trade business owners, office managers, bookkeepers, project administrators, site supervisors and MSPs supporting construction and field-service clients. It also covers apprentices, casual workers and subcontractors who may use a personal phone, shared tablet or customer-provided portal.
If one person can approve a payment, reset an account, open a job document, update a supplier record or access customer information, that person belongs in the programme. Job title is less useful than access and decision power.
What to look for in training for trade businesses
1. Lessons that fit the workday
A desk-based course that assumes uninterrupted time is a poor fit for a mobile workforce. Look for short modules that can be completed on a phone or laptop, with a clear explanation of the decision being practised. A toolbox meeting, office handover or end-of-day admin block is a better delivery point than a long annual session.
The content should use trade situations: a supplier asking to change a BSB, a customer sending a new portal link, a project manager requesting plans from a personal address, or a courier message asking someone to scan a QR code. Familiar context is what makes the warning memorable.
2. Business email compromise and invoice fraud
Generic phishing examples are not enough. Trade businesses need practice with payment diversion, fake progress claims, altered invoices and messages that appear to come from a builder, supplier, customer or site manager. The core rule is direct: do not action a payment or bank-detail change from an email alone.
The verification route must be independent. Call the established number already held in the supplier record, or confirm face to face. Do not use the new number in the message, reply to the email, or trust a familiar signature as proof.
3. Role-based coverage
Owners and finance staff need payment and account-takeover scenarios. Site supervisors need fake delivery, document-share and urgent access requests. Apprentices need mobile phishing, QR-code and social-media examples. Subcontractors need a simple reporting rule and clarity about which customer data they can access.
A good programme assigns different examples without creating separate administration for every person. The owner should be able to see who is overdue, who needs coaching and which scenario produced a report or a click.
4. Account protection that supports the lesson
Training should point to the control people must use. Secure business email with a strong, unique passphrase and multi-factor authentication. Keep accounting, cloud storage, password managers, payroll and customer portals on named accounts rather than a shared password.
The ACSC’s Essential Eight lists eight mitigation strategies, including multi-factor authentication, restricting administrative privileges, application control, macro restrictions, user application hardening, patching applications and operating systems, and regular backups. A trade business does not need to implement every technical change through the training platform, but training should make the human part clear: approve MFA prompts carefully, do not share credentials, and report an unexpected reset or sign-in alert.
5. A reporting route people will actually use
If a suspicious email should go to an inbox nobody checks, the policy has failed before the first simulation. Give staff one route: a reporting button, a service desk ticket, a phone call to the office or a named manager. Tell them what to include and what not to do.
The first response should be supportive. A worker who reports a suspicious invoice before paying it has helped the business, even if the message turns out to be legitimate. Measure reports and verification behaviour alongside clicks.
6. Contractor and leaver coverage
Subcontractors, temporary administrators and bookkeepers may have access to job folders, invoices, customer records or accounting systems. Assign their training before access is granted, record the end date, and remove access when the work ends.
Do not rely on a shared mailbox as a substitute for ownership. Named access makes it possible to see who acted, revoke one person without disrupting the whole team, and reset credentials after a worker leaves.
Top picks for trade businesses
The safe pick: recurring training plus realistic phishing practice
An ongoing programme combines short lessons, quizzes, safe simulated messages and a report that an owner or MSP can review. Cyber Aware describes 120+ story-driven training videos, quizzes, branded completion certificates and reporting on learner progress. Its phishing programme describes 100+ templates, recurring campaigns, automatic follow-up training for people who click and reporting on clicks and reports.
That combination is a strong fit when the business wants more than a policy document. Owners can train office staff on invoice fraud, send site supervisors a document-share scenario and use the results to decide who needs another lesson. Buy this approach when payment and customer-data risk is material.
The best low-friction starting point: a toolbox rule card
A one-page rule card is useful when a business is starting from zero. Put five rules where payment and job administration happen: stop urgent requests, do not change bank details from email alone, use a known number to verify, never share a passphrase or MFA code, and report suspicious messages immediately.
A card is not a complete programme because it does not test behaviour or produce evidence. Consider it as the first week’s intervention, then add short lessons and simulations.
The MSP-delivered option: a managed client programme
A trade business that already relies on an MSP can add awareness training to the same service relationship. The MSP can configure enrolment, schedule reminders, run a payment-fraud simulation, review results and bring the open actions to a regular service meeting.
This works when the MSP has a clear owner and does not treat training as a generic email blast. Buy it when the business has several sites, rotating workers or limited internal administration.
The approach that looks right but is not: a generic annual video
A long compliance video can show that a course was assigned, but it may not teach anyone how to verify a supplier bank-detail change or report a suspicious customer portal. It also leaves a long gap between the lesson and the next real message. Skip it as the only control.
What to avoid
- Payment rules that live only in a policy folder. The person approving an invoice needs a short instruction at the point of action.
- Simulations that only use fake password resets. Include supplier, customer, delivery, document-share and payment scenarios.
- Training only permanent office staff. Include owners, site teams, apprentices, bookkeepers and subcontractors with access.
- Shared credentials for convenience. Shared access removes accountability and makes offboarding harder.
- Punitive debriefs. A gotcha exercise teaches people to hide mistakes; a coaching loop teaches them to stop and report.
- Assuming email security replaces human checks. The ACSC’s construction alert specifically recommends verification, MFA and staff awareness together.
A practical 30-day rollout
Days 1–5: map the decisions
List the accounts and workflows that can move money, expose customer data or grant access. Identify who approves supplier changes, who can reset email, who manages job folders and who handles new subcontractors. Write the independent verification method beside each workflow.
Days 6–10: set the non-negotiable rules
Turn the map into a short rule card and manager script. Require a known-channel check for bank-detail changes and unusual payment requests. Turn on MFA for business email and the systems that hold customer or financial information.
Days 11–20: train by role
Give owners and accounts staff an invoice-fraud lesson. Give site supervisors a document-share and delivery-message lesson. Give apprentices and mobile workers a QR-code and phone-based phishing lesson. Give contractors the reporting route and access boundary before they start work.
Days 21–25: run a safe simulation
Send one controlled scenario to the relevant group. Do not collect passwords, imitate a real customer, or use a live payment instruction. Measure who reported, who clicked, how quickly the report reached the owner, and whether the recipient used the approved verification route.
Days 26–30: coach and retest
Explain the red flags immediately, close any account or process gap, and schedule a different scenario within 30 days. If the first exercise used an invoice, use a document-share or fake portal message next. The goal is recall across situations, not memorising one template.
Verdict comparison
| Approach | Payment-fraud practice | Mobile fit | Reporting evidence | Verdict |
|---|---|---|---|---|
| Recurring lessons plus simulations | Yes | Strong | Strong | Buy |
| Rule card only | Partial | Strong | None | Consider as a starting point |
| MSP-managed programme | Yes | Depends on delivery | Strong | Buy for lean teams |
| Generic annual video | Usually weak | Variable | Basic | Skip as the only control |
FAQ
What should cyber security awareness training for tradies cover?
It should cover invoice redirection, supplier bank-detail changes, fake login pages, document-share invitations, QR-code scams, MFA prompts, passphrases, reporting and contractor access. Examples should reflect the accounts and payment decisions the business actually makes.
How do trade businesses stop invoice redirection scams?
Require an independent phone or face-to-face check for every new bank detail or unusual payment request. Use the established supplier contact already held by the business, not the number or link in the message.
Do apprentices and subcontractors need the same training as office staff?
They need the same core reporting and account-protection rules but different scenarios. Office staff need payment-fraud practice, while apprentices and subcontractors may need mobile phishing, QR codes, document sharing and access boundaries.
Is MFA enough to protect a small trade business?
No. MFA reduces the damage from stolen passwords, but it does not replace payment verification, safe document handling, backups or reporting. The ACSC recommends using several controls together.
How often should tradies receive cyber security training?
Use recurring short lessons and role-specific simulations instead of one annual session. Retest a different scenario within 30 days of the first exercise, then keep a regular cadence that fits the business.
What should a worker do after clicking a suspicious link?
Stop entering information, disconnect if malware is suspected, tell the designated contact immediately and preserve the message. The business can then secure the account, reset credentials and assess whether other systems need attention.
Can an MSP run the programme for a trade business?
Yes. An MSP can manage enrolment, reminders, simulations, reporting and follow-up, provided the client has a named owner and the scenarios match its payment, customer and site workflows.
One last thing
The most convincing invoice scam may not contain an obvious spelling error. It may arrive from a compromised legitimate mailbox or a lookalike domain during a real project deadline. In 2026, the safer habit is not better proofreading; it is an independent verification step that no urgent message can bypass.
Related guides
- Phishing simulations
- Cyber security gap assessment
- Human risk reporting
- Security awareness platform comparison
Sources
- Cybercriminals targeting construction companies to conduct email scams, Australian Signals Directorate’s Australian Cyber Security Centre, construction-sector business email compromise alert.
- Business email compromise, Australian Signals Directorate’s Australian Cyber Security Centre, threat definition and prevention guidance.
- Essential Eight maturity model FAQ, Australian Signals Directorate’s Australian Cyber Security Centre, eight mitigation strategies and maturity guidance.
- Phishing, Australian Signals Directorate’s Australian Cyber Security Centre, reporting and recovery guidance.