How to plan a 12-month security awareness training calendar

Build a practical 12-month security awareness training calendar with monthly behaviours, phishing practice, role-based learning and quarterly reviews.

A security awareness training calendar should make the safest response easier to remember, practise and measure throughout the year. It should not be twelve unrelated courses that staff complete once and forget. This guide gives Australian organisations a practical 12-month plan, with room to adjust the sequence when threat intelligence, systems or business processes change.

TL;DR

Why a 12-month calendar works

Security awareness competes with operational work. A calendar gives managers a visible cadence for assigning learning, running exercises and reviewing evidence. It also lets you avoid two common failures: overwhelming people with every topic at once and leaving long gaps between training and practice.

The calendar is a management tool, not proof of security. The Essential Eight is an Australian baseline of eight mitigation strategies that makes it harder for adversaries to compromise systems. Awareness supports the human decisions around those controls, but it cannot replace technical implementation, access management or incident response.

NIST SP 800-50 Rev. 1, Building a Cybersecurity and Privacy Learning Program, describes a lifecycle approach for awareness, training and education. It is designed for large and small organisations and includes metrics and evaluation methods. Use that principle to make the calendar adjustable rather than permanent.

What to decide before filling the months

Set five rules before selecting topics:

  1. Who must learn: employees, contractors, privileged users, executives and new starters may need different paths.
  2. What behaviour matters: define the action someone should take when faced with an unusual request, link, attachment, login prompt or data-sharing decision.
  3. How people report: name the mailbox, button, service desk route or manager escalation path before testing it.
  4. What evidence counts: completion alone is not enough; decide how you will use quizzes, simulations, reports and incident data.
  5. Who owns each month: assign a business owner, technical adviser and person responsible for publishing results.

Review the latest ACSC Annual Cyber Threat Report before finalising the year. Its national findings are a starting point; local incidents, helpdesk questions and business changes decide the final priority.

The 12-month security awareness training calendar

Month 1: establish the baseline

Start the year with a short foundation lesson covering suspicious messages, secure passphrases, MFA prompts, safe file sharing and the organisation’s reporting route. Give new starters the same baseline within their first week rather than waiting for the monthly campaign.

Set the measures you will use for the year: completion by due date, overdue rate, quiz results, simulated click rate, simulated report rate and time from delivery to report. Record definitions so that the January baseline can be compared with December.

Owner: security or IT with HR support. Evidence: baseline completion and a working report test.

Month 2: practise phishing recognition

Use a low-complexity simulation to practise checking the sender, destination, context and urgency of a message. The goal is not to catch people out; it is to make reporting normal and fast. The Cyber Aware phishing platform supports simulated campaigns and follow-up learning, so use a baseline scenario before increasing difficulty.

Tell staff what happens after they report. A report that disappears into a queue teaches people not to report next time.

Owner: security operations or the managed service provider. Evidence: report rate and median time to report.

Month 3: protect accounts and approvals

Teach passphrase habits, MFA prompt awareness and approval checks. Show the difference between approving a known sign-in and responding to an unexpected request. Finance and administrators should receive examples relevant to payment changes, privileged access and urgent approvals.

Coordinate with the identity owner so the lesson matches the actual sign-in process. Do not teach a workaround that conflicts with the organisation’s MFA configuration.

Owner: identity or IT operations. Evidence: quiz performance, service desk themes and a list of MFA questions that need technical resolution.

Month 4: handle information safely

Focus on personal information, customer records, confidential commercial information and accidental sharing. Teach people to select the correct recipient, verify external sharing and use approved storage. Include clean-desk and screen-lock habits where they fit the work environment.

Use real process examples without copying sensitive data into the lesson. A data-handling module should tell staff what to do when they are unsure, not imply that everyone can decide classification alone.

Owner: privacy, legal or information governance. Evidence: scenario decisions and recurring data-handling questions.

Month 5: train by role

Replace the general example with function-specific practice. Finance can work through supplier bank-detail changes and invoice requests. HR can handle candidate documents and payroll changes. Customer teams can verify unusual account requests. IT can practise reset requests, privileged access and suspicious administrator activity.

Keep the safe response consistent: pause, verify through a known channel and report when the request cannot be confirmed.

Owner: department leaders with security support. Evidence: completion by cohort and results for the role-based scenario.

Month 6: run a mid-year simulation

Run a second phishing campaign with a different delivery method or business context. Compare it with February using the same audience definitions and measures. If click rate falls but report rate also falls, investigate before declaring success. People may have learned to ignore the simulation rather than report it.

Give managers a short exception list for overdue assignments and high-risk follow-up. Keep remediation private and constructive.

Owner: security or the MSP. Evidence: change from the February baseline and completion of follow-up work.

Month 7: cover suppliers and shared responsibility

Teach staff how supplier impersonation, unexpected invoices, shared links and support requests can affect the organisation. The lesson should explain when to contact procurement, IT or the supplier through a known number.

Link this month to the organisation’s supplier register and escalation process. A security awareness calendar cannot assess a vendor on its own, but it can reduce unsafe responses to supplier-themed requests.

Owner: procurement and IT. Evidence: verified supplier-change process and a role-based scenario result.

Month 8: rehearse incident reporting

Give people a clear response for a suspected click, lost device, accidental disclosure, unusual payment request or suspicious login. Then run a short tabletop exercise with representatives from IT, legal, communications, HR and the affected business team.

The exercise should answer four questions: who receives the first report, what information is preserved, who decides containment and how the person who reported it is supported.

Owner: incident response lead. Evidence: time to acknowledge the report and actions closed from the exercise.

Month 9: make executives part of the program

Executives and board members need the baseline plus scenarios involving impersonation, sensitive information, payment approval and urgent decisions. Use a short briefing followed by a discussion of the controls management owns.

Do not give leaders a lower standard because they have less time. Give them a shorter, more relevant path and make their decisions visible: for example, approving a second-channel verification rule or funding an overdue control.

Owner: executive sponsor and board secretary or risk lead. Evidence: attendance, decisions recorded and open actions.

Month 10: refresh policies and remote-work habits

Review the policy language people actually use: acceptable use, remote access, personal devices, collaboration tools, removable media and reporting. Remove outdated instructions. Then teach the small number of changes that affect day-to-day decisions.

Use a policy refresh to resolve contradictions between security advice and operational practice. If staff cannot follow a policy while serving customers, the control needs a process owner, not another reminder.

Owner: policy owner with IT and operations. Evidence: policy exceptions, questions and confirmed owner for each change.

Month 11: test high-risk groups again

Repeat practice for groups that handle money, personal information, privileged access or high-value customer relationships. Use the year’s incident and simulation findings to select scenarios. Avoid giving every person the same difficult test when the risk is concentrated in a few workflows.

This is also a good month to check contractors, temporary workers and people who joined after the first baseline.

Owner: risk owner for each high-risk process. Evidence: cohort completion and behaviour trend across the year.

Month 12: measure, report and redesign

Close the year with a concise review. Compare the January baseline with the latest campaign, show the number of overdue assignments, explain changes in reporting and list the top three unresolved human-risk themes. Do not convert one metric into a claim that the organisation is safe.

The human risk reporting view can help combine learning, quiz and phishing signals into an actionable picture. Use it to decide where managers need to improve a process, where staff need support and what the next calendar should change.

Owner: security leader and executive sponsor. Evidence: approved priorities for the next 90 days.

How to keep the calendar from becoming noise

Use one main behaviour per month

A monthly theme can contain a lesson, simulation and conversation, but all three should reinforce one decision. If the month has ten unrelated outcomes, the audience will remember none of them.

Mix learning formats

Use short lessons for baseline knowledge, simulations for decision practice, discussions for process ownership and tabletop exercises for escalation. A quiz can show recall; it cannot prove that a person will report under pressure.

Schedule around work

Avoid the busiest operational period, but do not cancel a priority because the calendar is full. Split large cohorts into smaller groups and give managers a realistic due window.

Build in a quarterly reset

At the end of March, June, September and December, ask whether a threat, system, supplier, incident or regulation changes the next quarter. Keep the calendar stable enough to manage but flexible enough to remain relevant.

Troubleshooting

Staff are completing courses but behaviour is not changing

Check the reporting route, scenario realism and manager follow-up. Observe the workflow that creates risk. The issue may be a confusing approval process rather than a knowledge gap.

The same people fail every simulation

Offer targeted coaching and check whether they face unusual workload, access or process constraints. Use individual data to provide help, not public rankings.

Managers ignore overdue lists

Give each manager a small list with an action and due date. Escalate repeated non-response through the existing management path. Do not make the security team the owner of every business team’s completion.

The calendar is too ambitious

Protect the baseline, reporting practice and high-risk workflows first. Reduce the number of themes before reducing follow-up.

The report looks good but nobody can explain it

Define every measure, audience and comparison before the campaign runs. A dashboard without definitions creates confidence without evidence.

Choosing the delivery model

If a team needs a repeatable way to assign courses, run phishing practice and report on outcomes, compare the platform’s workflow with the calendar’s requirements. The Cyber Aware training page describes the platform’s training approach, while the comparison page can help procurement assess fit against alternatives.

For an MSP or consultant, start with the client’s gap assessment and risk priorities rather than deploying the same calendar everywhere. The Cyber Aware gap assessment can support that discovery conversation.

FAQ

Is annual security awareness training enough?

Usually not for a program that needs recurring behaviour practice. Use an annual baseline if it is required, then reinforce it with monthly or quarterly activities matched to risk.

How long should each monthly lesson be?

Use the shortest format that changes the target behaviour. A short lesson may be enough for a reminder; a role-based exercise or tabletop needs more time. Measure the outcome rather than a preferred duration.

Should every employee complete every month?

Everyone needs the baseline and reporting route. Other months can be targeted to the roles, systems and decisions involved, provided the scope is documented.

How do you measure a training calendar?

Track completion, overdue work, quiz results, phishing clicks, phishing reports, time to report and relevant incident patterns. Compare consistent cohorts and definitions across multiple campaigns.

When should the calendar change?

Change it when threat intelligence, incidents, systems, suppliers, legal obligations or business processes change the behaviour people need to practise. Review at least quarterly.

What is the best first month topic?

Start with the organisation’s baseline: suspicious messages, account protection, safe information handling and the route for reporting. Add a low-complexity simulation after the route is understood.

One last thing

A good calendar is not the one with the most events. It is the one that gives the right people a realistic chance to practise the right response, then gives leaders enough evidence to improve the next quarter.

Sources

Ready to deploy

Same playbook.
Your brand.

Cyber Aware's Human Risk Score works the same way for every MSP partner - under your brand, on your cadence.