How often should you do cyber security awareness training?

Monthly micro-training plus monthly phishing simulations is the 2026 default. What the 33.1% to 4.1% benchmark data says about training cadence for your team.

Monthly is the right cadence for security awareness training in 2026: one short module per month plus a monthly phishing simulation, with completion tracked on a dashboard instead of filed away as a once-a-year certificate. The benchmark data explains why. Before any training, roughly one in three employees interacts with a phishing email — KnowBe4's 2025 Phishing by Industry Benchmarking Report measured a global baseline phish-prone rate of 33.1%, and 36.8% across Australia and New Zealand. That rate drops by about 40% within 90 days of ongoing training and by 86% — to 4.1% — after a full year of it. The 12-month figure is the point: the improvement comes from sustained, repeated exposure, not from a single annual session.

How often should you do cyber security awareness training?

CadenceWhat it looks likeWho it suits
MonthlyOne 5-10 minute module plus one phishing simulation, every monthMost businesses; anyone handling client data, payments or personal information
QuarterlyOne module and one simulation every three monthsSmall, low-risk teams that already have strong technical controls
AnnualOne long course once a yearA compliance checkbox on its own — no longer sufficient as the only training

For most Australian businesses, the monthly rhythm is the honest answer in 2026. It matches how attacks arrive (continuously), how memory decays (quickly) and how evidence requirements now work (point-in-time snapshots at audit and insurance renewal).

Why the once-a-year model stopped working

An annual session still has value as formal, dated compliance evidence. It just cannot be the only mechanism, because it trains for a moment, not for the 365 days of real email in between.

Monthly: the 2026 default

Monthly training works because it is short by design. A module of 5-10 minutes fits between meetings, which is why completion rates hold up where a three-hour annual course does not. The monthly rhythm also gives you a natural place to hang everything else:

Platforms built for this cadence, including Cyber Aware's security awareness training, deliver the module, the simulation and the completion evidence as one monthly cycle rather than three separate admin jobs.

Quarterly: the minimum for a low-risk team

If your team is small, technical controls are strong (MFA everywhere, email filtering, tested backups) and nobody handles regulated data, quarterly training is a defensible floor. Four modules a year still refresh recognition four times more often than the annual model.

The trade-off is simulation fatigue management: when training runs quarterly, each phishing simulation carries more weight, so keep the difficulty ramped and the tone constructive. A failed test should trigger a two-minute micro-module, never a lecture.

Annual: what it still counts for

Keep the annual course if a contract, insurer or framework requires dated completion evidence. It documents that formal training happened, and for gap assessments mapped to frameworks like Essential 8 and SMB1001, that document matters.

But treat it as the certificate layer on top of monthly training, not the training itself. The pattern that fails is the one where the annual course is the only thing staff ever complete.

How to set your cadence in 2026

  1. Enrol everyone automatically from your directory (Google or Microsoft), so new starters enter the cycle on day one instead of waiting for the next annual intake.
  2. Assign one short module per month on a fixed due date, with a grace period for leave.
  3. Run one phishing simulation per month on varied, escalating templates.
  4. Track behaviour, not attendance — clicks, reports, overdue courses and quiz fails in one place.
  5. Report monthly to whoever owns the risk, so the trend line is visible before an audit or insurance renewal demands it.

What to pair with the rhythm

Cadence only pays off when the output is measurable. Monthly phishing simulations prove recognition is improving between courses, and human risk reporting turns overdue courses, failed quizzes and phishing clicks into a per-person risk signal you can actually act on — who needs help, not just who is enrolled.

FAQ

How long should each training session be?

5-10 minutes per module. Completion holds up at that length; it collapses on hour-long annual courses. Short and repeated beats long and rare.

Is annual security awareness training enough for compliance?

It satisfies a dated-evidence requirement, but it does not change behaviour on its own — the 86% click-rate reduction in KnowBe4's 2025 data required 12 months of ongoing training, not one session.

How often should phishing simulations run?

Monthly for most teams. Monthly simulations keep recognition fresh and give you a per-month trend line; annual surprise tests measure memory, not habit.

Does frequent training actually reduce phishing clicks?

Yes — the 2025 benchmark data shows roughly a 40% reduction within 90 days and an 86% reduction (from 33.1% to 4.1% phish-prone) after 12 months of ongoing training.

What if staff complain about monthly training?

Keep modules under 10 minutes, make deadlines predictable, and share team progress publicly. Complaints usually track with course length and surprise, not with frequency itself.

One last thing

Before choosing a cadence, run a baseline phishing test on your own team. If more than a third of staff click — the 2026 Australian and New Zealand average is 36.8% — monthly is not optional; it is the only cadence the evidence supports.

Sources

Ready to deploy

Same playbook.
Your brand.

Cyber Aware's Human Risk Score works the same way for every MSP partner - under your brand, on your cadence.