A security awareness training program is a recurring, measured cycle of training and phishing tests that changes how staff behave — not a once-a-year compliance video with a quiz bolted on the end. The difference between a program and a course is measurement: a baseline phishing test before training starts, a monthly cadence that actually sticks, and one number that shows movement month over month.
Key takeaways
- A program has four properties a course does not: it recurs, it measures, it remediates and it evidences.
- Before any training, 33.2% of employees click a simulated phishing email; a sustained year of training and simulation takes that to 4.2%, according to KnowBe4's 2026 Phishing by Industry Benchmarking Report.
- The largest gains land between months 3 and 12 of sustained training, so plan for a year, not a quarter.
- Australian small businesses reported an average cybercrime cost of $56,600 in FY2024–25, up 14% on the prior year (ASD's ACSC Annual Cyber Threat Report) — the budget line this program defends.
What a security awareness training program is
A program has four properties a course does not:
- It recurs — monthly, not annually. Recognition of a phishing email is a reflex, and reflexes need short, frequent rehearsal.
- It measures — a baseline before the first course, then a trend line every month.
- It remediates — repeat clickers get targeted follow-up, not just another all-staff email.
- It evidences — records you can hand to an auditor, a client contract or a cyber insurer.
A course gets you a completion certificate. A program gets you a workforce that reports suspicious email instead of clicking it.
Why it matters in 2026
ASD's ACSC received more than 84,700 cybercrime reports in FY2024–25 — one every 6 minutes — and the average self-reported cost to small business rose 14% to $56,600. Business email compromise fraud, an attack that starts with nothing more than a convincing email, was 15% of business cybercrime reports that year. Globally, IBM's 2026 Cost of a Data Breach Report puts the average breach at USD 4.99 million, up 12% year over year, with phishing the most common initial attack vector for the fourth year running.
None of those attacks starts with a zero-day. Most start with an email a person chose to trust.
Step 1: Baseline with a phishing simulation
You cannot show improvement without a starting number. Send one simulated phishing email before any training begins and record the click rate, the report rate and time-to-report. That number is your argument for the budget and your yardstick for every month after — industry benchmarking puts the untrained baseline near one in three employees, so a first click rate in the 20–30% range is normal, not a crisis.
Cyber Aware's phishing simulations can run that first campaign in a day, with anyone who clicks auto-enrolled into a short follow-up module immediately.
Step 2: Set a monthly cadence
Short monthly modules beat annual marathons on every measure: retention, completion and relevance. A 5–10 minute module each month, with a due date and a grace period, is the 2026 standard. The benchmark data is blunt about timing: global phishing susceptibility falls 40% within the first 90 days of training, but the full reduction — from 33.2% to 4.2% — only lands with twelve months of continuous training and testing.
- One module per month, due within two weeks of release.
- A 7-day grace period so a bad week does not become a disciplinary matter.
- A fixed release day, so staff learn the rhythm.
Step 3: Pick content your staff will recognise
Training lands when the examples look like the staff member's own inbox. For Australian teams that means:
- ATO and myGov lures, seasonal and otherwise.
- Invoice and payment-detail-change fraud — the business email compromise pattern behind 15% of business reports.
- Impersonation via messaging apps — the "Hi Mum" pattern, now also a workplace payment-fraud variant.
- Fake Microsoft 365 login pages, the most common credential-harvesting lure in business.
Generic global content still teaches the reflexes. Local content teaches them faster.
Step 4: Automate enrolment and reminders
Manual spreadsheets die the first time the person maintaining them goes on leave. Automate three things on day one:
- New hires enrol the day they start, not when someone remembers.
- Reminders go out on schedule, escalating after the grace period.
- Clickers auto-enrol into follow-up training without anyone pressing a button.
Step 5: Measure with a single number
Track one number per learner, not five dashboards. A human risk score built from overdue courses, failed quizzes and phishing results tells you who needs help; a bare completion percentage tells you almost nothing. Cyber Aware's human risk reporting produces that score per learner per month, banded low, moderate and high.
Watch three trend lines monthly: click rate down, report rate up, high-risk band shrinking.
Step 6: Report monthly, remediate the top band
Publish a one-page summary every month: completion, click rate, report rate, and the risk trend. Then act on the top band — the small group of repeat clickers drives most of your residual risk. A phone call and a follow-up module beats an all-staff email, every time. And keep it no-blame: the moment staff believe a click means trouble, they stop reporting real attacks, and reporting is the habit that saves you.
Step 7: Evidence the frameworks you answer to
If your clients or contracts ask for Essential Eight or SMB1001, the training records and phishing evidence you have been generating since step 1 are the answers. Cyber Aware's gap assessment maps against both frameworks out of the box, so the program's output doubles as audit evidence.
Choosing a platform
| Option | Best for | Notes |
|---|---|---|
| Cyber Aware | Australian SMBs and MSPs | Essential Eight and SMB1001 mapping, per-seat pricing with no minimums |
| KnowBe4 | Enterprises wanting the deepest content library | Published bands from $2.40/user/mo on 3-year terms |
| Huntress SAT | MSPs wanting fully managed delivery | $2.08/learner/mo published, tiers from the 50–99 learner band |
| In-house (LMS plus templates) | Very small teams with spare admin time | No phishing automation or risk scoring |
The full feature-by-feature breakdown is on our platform comparison page.
Common mistakes
- Training once a year and calling it a program.
- Naming clickers publicly — it kills reporting, and reporting is the metric that saves you.
- Buying a platform nobody administers.
- Running the first simulation before the report button exists.
- Measuring completion percentage instead of behaviour.
FAQ
How long does a security awareness training program take to show results? The first movement shows in the click rate within a few months — global susceptibility drops 40% in the first 90 days — but the largest gains land between months 3 and 12 of sustained training.
How much does a security awareness training program cost? Per-seat platforms publish rates around $2.08–$2.40 per user per month at the low end in 2026; the total depends on seats and add-ons.
What should be in the first month? A baseline phishing simulation, one core module with a due date, and a report-phishing button.
Who owns the program? A named owner. "IT eventually" is how programs die in month two.
How do you prove the program works? Trend lines: phishing click rate down, report rate up, high-risk band shrinking month over month.
Do we need phishing simulations to have a program? You need a baseline and measurement. Simulations are the cheapest, most honest way to get both.
One last thing
Build the program to run without a champion. Automated cadence, automated enrolment, automated reporting. The program that survives is the one that keeps running the month you are on leave — because that is usually when the real phishing email arrives.