Short answer: security awareness training works as an ongoing monthly habit, not a once-a-year compliance event. The largest published dataset in the category — KnowBe4's 2025 benchmark of 67.7 million simulations across 14.5 million users in 62,400 organisations — shows why frequency matters: 33.1% of employees interact with a phishing simulation before any training, and only 4.1% after twelve months of ongoing training. Staff forget, attackers change tactics, and a single annual session does neither job.
Key takeaways
- Monthly is the practical minimum: one short lesson plus one phishing simulation, all year round.
- The benchmark curve — 33.1% of staff interacting before training, roughly 5% after 90 days, 4.1% after twelve months — only holds under ongoing training.
- Train on triggers as well as a calendar: new starters in their first week, repeat clickers after every simulation, everyone when a new scam pattern spreads.
- Track the evidence monthly in human risk reporting so you can show click, report and repeat-click trends — not just completion certificates.
Why once a year is not a schedule
Annual training made sense when threats changed slowly. In 2026 they do not: AI-written lures, QR code phishing and deepfake voice calls now reach Australian inboxes between annual sessions. An employee trained in March faces attacks in November that did not exist when the course was written.
The decay is measurable. KnowBe4's 2025 data shows the share of staff who interact with a phishing simulation falls from 33.1% to roughly 5% within the first 90 days of ongoing training, then settles at 4.1% after a full year. The steep early fall comes from cadence: people see simulations repeatedly, click, receive a short lesson immediately, and stop clicking. Remove the cadence and the number climbs back toward one in three.
A monthly cadence that fits around real work
A workable rhythm for a small team looks like this:
- Monthly: one 5-10 minute lesson on a single topic — invoice fraud, password reuse, payment diversion — and one phishing simulation across the whole team.
- On click: an immediate short refresher for whoever clicked. Coaching, not blame, or people hide their clicks.
- Quarterly: a look at the numbers with whoever owns risk — click rate, report rate, repeat clickers.
- Annually: a compliance refresh that satisfies auditors and insurers, layered on top of the monthly rhythm rather than instead of it.
The annual refresh still matters: insurers, auditors and frameworks such as the Essential Eight expect evidence of regular training. The mistake is treating it as the whole program.
Train on triggers as well as the calendar
Some of the most valuable training is not scheduled at all:
- New starters. Staff in their first weeks click phishing at the highest rates, and scammers know it — payroll change and payment diversion scams target new employees before they know the process. Train them before their first email access, not at the next annual cycle.
- Repeat clickers. Anyone who clicks in two consecutive simulations needs a targeted follow-up, not the same all-staff lesson repeated.
- New threats. When a scam wave hits — a tax-time ATO impersonation, a fake invoice run targeting finance teams — a short 'this is what it looks like' alert within days beats a generic lesson next quarter.
An automated platform handles all three. Cyber Aware's training enrols new starters automatically, delivers click-triggered refreshers after each phishing simulation, and rotates lessons monthly without anyone chasing spreadsheets.
How to tell your cadence is working
Frequency without measurement is a promise, not a control. Three numbers tell the truth:
- Click rate on simulations, trending month over month toward the 4.1% benchmark.
- Report rate — the share of staff who flag a suspicious email — which should climb as click rate falls.
- Repeat clickers — the same staff clicking again — which should shrink toward zero.
If click rate is flat after six months of monthly training, the content or the follow-up needs changing, not the calendar.
FAQ
Is annual security awareness training enough? It is the minimum many insurers and auditors ask for, but it is not enough to change behaviour. The benchmark data shows results decay without ongoing reinforcement, and 2026 scams evolve faster than an annual cycle.
How long should each session be? Short and regular beats long and rare: 5 to 10 minutes per month plus a simulation keeps training inside the working day instead of eating an afternoon.
When should new starters be trained? In their first week, before they rely on email for real work. New starters click at higher rates and are favourite targets for payroll and payment diversion scams.
What cadence do frameworks like the Essential Eight expect? Regular training with evidence. Monthly lessons and simulations with recorded results satisfy the intent; a single annual session does not.