Employees should do security awareness training monthly — one 10-to-15-minute lesson plus a phishing simulation — with a deeper role-based course each year for high-risk teams and a refresher whenever someone changes jobs. An annual compliance video leaves ten and a half months of drift between lessons, and phishing lures change faster than that in 2026.
Key takeaways
- Monthly is the working standard in 2026: a 10–15 minute micro-lesson plus one phishing simulation, for every staff member.
- New starters complete baseline training in their first 10 days and face their first phishing test by day 60.
- Finance, executives and IT need quarterly role-specific deep-dives on top of the monthly rhythm.
- Cyber Aware's security awareness training runs the monthly cadence automatically and keeps per-learner evidence for audits.
- Track completion monthly — one data point a year steers nothing.
How often should employees do security awareness training?
Monthly is the practical answer for 2026, and the cadence most awareness platforms now build for. Here is how it distributes across a business:
| Audience | Cadence | What it looks like |
|---|---|---|
| All staff | Monthly | 10–15 minute micro-lesson plus one phishing simulation |
| New starters | First 10 days | Baseline course, then join the monthly rhythm |
| Finance and executives | Monthly plus quarterly deep-dive | Payment fraud, invoice verification, CEO impersonation |
| Remote and field staff | Monthly | Home network, device and channel-specific lures |
| IT and administrators | Quarterly | Privileged-access abuse and insider-threat indicators |
| Every employee | Annually | One longer course with a knowledge check, kept as evidence |
Why monthly beats annual
The case is behavioural, not contractual. Skills decay when unused, and attackers iterate weekly: the lure that catches staff in February is not the one that catches them in July. In FY2024–25 the Australian Signals Directorate received more than 84,700 cybercrime reports — one every six minutes — and small businesses reported an average cost of $56,600 per incident (ASD Annual Cyber Threat Report 2024-25). A control that runs once a year does not move those numbers.
The human element sits behind roughly 60% of breaches. Verizon's 2025 Data Breach Investigations Report analysed 12,195 confirmed breaches and again attributed a majority to people — clicks, misdelivery, stolen credentials (full report PDF). Training is the only control that acts directly on that share of the problem, which is why its frequency matters more than its production values.
Monthly also creates a measurement rhythm. This month's click rate tells you whether last month's lesson landed; annual training produces a single data point per year, which is useless for steering anything.
What a monthly session should look like
- 10–15 minutes, one theme. Invoice fraud one month, tax-impersonation scams the next. Depth comes from repetition across the year, not from a two-hour marathon.
- Local content. Fake ATO notices, toll-payment texts and bank-portal clones outperform generic imported templates for Australian staff in 2026.
- A simulation in the same month. The lesson and the test reinforce each other; clickers get auto-enrolled into a follow-up lesson the same day.
- Recorded completion. Per-learner evidence matters as much as the lesson itself — it is what auditors, insurers and enterprise clients ask to see.
Why annual training fails on its own
- Drift. By month ten, most of last year's course is forgotten.
- One-size content. The finance lead and the warehouse casual face opposite exposures; a single annual course treats them identically.
- No feedback loop. Without a cadence you cannot tell whether the training worked, so you cannot improve it.
- Coverage blind spots. A hire who starts in March waits months for their first exposure — and new starters are among the most-attacked group in their first weeks.
The fix is not a longer annual course. It is a shorter, steadier cadence with the annual deep-dive layered on top for the roles that handle money and privileged access.
How to keep a monthly cadence running
Automation is the difference between a programme that exists in the policy document and one that actually runs. Directory-sync enrolment puts new starters in on day one, scheduled simulation campaigns fire without anyone remembering, and a report button gives staff something to do with suspicious mail instead of ignoring it. Cyber Aware's phishing simulations handle the scheduling and same-day coaching, and the platform comparison shows which vendors automate which parts — the ones that need a human to remember will stop within a quarter.
Can you train employees too often?
Yes, and the symptom is fatigue: open rates drop and simulation emails get waved off as obvious tests. Monthly lessons plus one or two simulations a month is the ceiling that works for most teams. Beyond it, vary the format — a two-minute video, a one-question quiz, a real example from last month's reports — rather than adding sessions.
What if staff stop completing training?
Track completion, not intention. Chase individuals at week two, escalate to their manager at week four, and record non-completion in the risk report. Around 90% trained and 100% enrolled are different claims, and auditors read the difference.
FAQ
How often should employees do security awareness training? Monthly: a 10–15 minute lesson plus a phishing simulation for all staff. High-risk roles add quarterly deep-dives, and everyone completes one longer annual course.
Is annual security training enough for compliance? Rarely. Frameworks such as the Essential Eight expect evidence of ongoing awareness, not a single annual event. Monthly sessions with recorded completion are the safer position in 2026.
How long should each session be? 10–15 minutes. Attention on security topics collapses past that in a normal workday, and shorter sessions let you cover more themes across a year.
Should contractors follow the same cadence? Yes. Attackers do not distinguish payroll status, and contractors with mailbox access are targeted exactly like employees.
What is the best time for a bigger training push? The month before your busiest financial period, or immediately after a real incident. Relevance is the strongest retention aid available.
How do you prove training actually happened? Export per-learner completion and simulation results each month. Cyber Aware's human risk reporting keeps that evidence current without manual reporting.
One last thing
The cadence that matters most never appears on a calendar: the same-day follow-up. When someone clicks a simulation, a short lesson within hours — not weeks — is when the lesson attaches to the memory of the mistake. That single automation does more for retention than doubling your monthly content.