How to build a security awareness training program

Build a security awareness training program in 7 steps: baseline phishing test, monthly cadence, Australian-relevant content, automation, risk scoring and monthly reporting.

A security awareness training program is a recurring, measured cycle of training and phishing tests that changes how staff behave — not a once-a-year compliance video with a quiz bolted on the end. The difference between a program and a course is measurement: a baseline phishing test before training starts, a monthly cadence that actually sticks, and one number that shows movement month over month.

Key takeaways

What a security awareness training program is

A program has four properties a course does not:

A course gets you a completion certificate. A program gets you a workforce that reports suspicious email instead of clicking it.

Why it matters in 2026

ASD's ACSC received more than 84,700 cybercrime reports in FY2024–25 — one every 6 minutes — and the average self-reported cost to small business rose 14% to $56,600. Business email compromise fraud, an attack that starts with nothing more than a convincing email, was 15% of business cybercrime reports that year. Globally, IBM's 2026 Cost of a Data Breach Report puts the average breach at USD 4.99 million, up 12% year over year, with phishing the most common initial attack vector for the fourth year running.

None of those attacks starts with a zero-day. Most start with an email a person chose to trust.

Step 1: Baseline with a phishing simulation

You cannot show improvement without a starting number. Send one simulated phishing email before any training begins and record the click rate, the report rate and time-to-report. That number is your argument for the budget and your yardstick for every month after — industry benchmarking puts the untrained baseline near one in three employees, so a first click rate in the 20–30% range is normal, not a crisis.

Cyber Aware's phishing simulations can run that first campaign in a day, with anyone who clicks auto-enrolled into a short follow-up module immediately.

Step 2: Set a monthly cadence

Short monthly modules beat annual marathons on every measure: retention, completion and relevance. A 5–10 minute module each month, with a due date and a grace period, is the 2026 standard. The benchmark data is blunt about timing: global phishing susceptibility falls 40% within the first 90 days of training, but the full reduction — from 33.2% to 4.2% — only lands with twelve months of continuous training and testing.

Step 3: Pick content your staff will recognise

Training lands when the examples look like the staff member's own inbox. For Australian teams that means:

Generic global content still teaches the reflexes. Local content teaches them faster.

Step 4: Automate enrolment and reminders

Manual spreadsheets die the first time the person maintaining them goes on leave. Automate three things on day one:

Step 5: Measure with a single number

Track one number per learner, not five dashboards. A human risk score built from overdue courses, failed quizzes and phishing results tells you who needs help; a bare completion percentage tells you almost nothing. Cyber Aware's human risk reporting produces that score per learner per month, banded low, moderate and high.

Watch three trend lines monthly: click rate down, report rate up, high-risk band shrinking.

Step 6: Report monthly, remediate the top band

Publish a one-page summary every month: completion, click rate, report rate, and the risk trend. Then act on the top band — the small group of repeat clickers drives most of your residual risk. A phone call and a follow-up module beats an all-staff email, every time. And keep it no-blame: the moment staff believe a click means trouble, they stop reporting real attacks, and reporting is the habit that saves you.

Step 7: Evidence the frameworks you answer to

If your clients or contracts ask for Essential Eight or SMB1001, the training records and phishing evidence you have been generating since step 1 are the answers. Cyber Aware's gap assessment maps against both frameworks out of the box, so the program's output doubles as audit evidence.

Choosing a platform

OptionBest forNotes
Cyber AwareAustralian SMBs and MSPsEssential Eight and SMB1001 mapping, per-seat pricing with no minimums
KnowBe4Enterprises wanting the deepest content libraryPublished bands from $2.40/user/mo on 3-year terms
Huntress SATMSPs wanting fully managed delivery$2.08/learner/mo published, tiers from the 50–99 learner band
In-house (LMS plus templates)Very small teams with spare admin timeNo phishing automation or risk scoring

The full feature-by-feature breakdown is on our platform comparison page.

Common mistakes

FAQ

How long does a security awareness training program take to show results? The first movement shows in the click rate within a few months — global susceptibility drops 40% in the first 90 days — but the largest gains land between months 3 and 12 of sustained training.

How much does a security awareness training program cost? Per-seat platforms publish rates around $2.08–$2.40 per user per month at the low end in 2026; the total depends on seats and add-ons.

What should be in the first month? A baseline phishing simulation, one core module with a due date, and a report-phishing button.

Who owns the program? A named owner. "IT eventually" is how programs die in month two.

How do you prove the program works? Trend lines: phishing click rate down, report rate up, high-risk band shrinking month over month.

Do we need phishing simulations to have a program? You need a baseline and measurement. Simulations are the cheapest, most honest way to get both.

One last thing

Build the program to run without a champion. Automated cadence, automated enrolment, automated reporting. The program that survives is the one that keeps running the month you are on leave — because that is usually when the real phishing email arrives.

Related guides

Ready to deploy

Same playbook.
Your brand.

Cyber Aware's Human Risk Score works the same way for every MSP partner - under your brand, on your cadence.