A Cyber Security Awareness Month campaign at work works when you run four things across October 2026: one kick-off activity in week 1, a phishing simulation in weeks 2 and 4, a 3-5 minute training module each week, and a completion report to leadership in week 5. Cyber Aware delivers the training and simulation pieces, so your job as the organiser is scheduling, communications and the executive readout - not building content from scratch.
TL;DR
- Awareness Month works as a four-week programme: kick-off, training, simulation, report.
- Weekly security awareness training beats one long October webinar for retention.
- A phishing simulation in week 2 and week 4 measures whether the campaign changed behaviour.
- Close with a human risk reporting readout so leadership sees a number, not anecdotes.
Why this matters
Cyber Security Awareness Month runs every October. The Australian Cyber Security Centre publishes themes each year, and businesses use the month as a socially accepted excuse to ask every employee for 20 minutes of attention they would not otherwise get. The failure mode is the one-off event: a single lunch-and-learn in week 1, applause, then nothing until next October. Click rates on phishing tests do not move from a single event.
The comparison worth making is cadence, not content. Evidence from security awareness platforms consistently shows steady monthly training and testing reducing phishing click rates far more than a single annual session - Cyber Aware's own programme data points to an average 80% reduction in clicked links within the first eight months of monthly campaigns. October is the month to start that cadence, not to replace it.
Week 1: kick-off activity and baseline
Pick one activity that takes under 30 minutes of employee time and creates a shared reference point for the month:
- Run the ACSC's Act, Check and Secure checklist as a team exercise - employees check their own settings against a published government baseline
- Send a short quiz on the three scams most relevant to your industry (invoice fraud, fake login pages, delivery texts)
- Announce the month's schedule in one email: what happens each week, how long it takes, and what the phishing simulation is for
State plainly that a phishing test is coming, that clicking it triggers coaching rather than blame, and that reporting the email is the win. A simulation announced in advance measures your reporting culture honestly and avoids the trust damage of an ambush.
Week 2: first training module and first phishing simulation
- Send one security awareness training module of 3-5 minutes, tied to the scam type most common in your industry
- Launch the first phishing simulation mid-week, using a template that matches a current local threat
- Auto-enrol anyone who clicks into the failed-phishing course - the click becomes a coaching moment, not a disciplinary event
- Publish the click and report rates to the whole team within 48 hours, celebrating reporters by name where culture allows
Week 3: role-based depth
Week 3 is where generic content stops working. Finance staff need payment-verification drills; reception needs visitor and call-handling scripts; executives need whaling awareness. Assign one module per role rather than one module for all - shorter, more relevant, more likely to be finished.
Week 4: second simulation and measurement
- Run the second phishing simulation with a different template and difficulty level
- Compare click rate against week 2 - the delta is your campaign's headline result
- Pull completion rates per team from your human risk reporting dashboard
Week 5: executive readout
Close the month with a one-page report: completion rate by team, phishing click rate week 2 versus week 4, reports per 100 employees, and the two scam types to drill next quarter. A gap assessment gives the same story from a controls perspective if leadership also wants a posture view.
Common mistakes
- One event, no cadence. A single webinar in week 1 changes nothing measurable by December.
- Ambush simulations. Announce the test; ambushes destroy the reporting culture you are trying to build.
- Public shaming of clickers. Coaching-first response keeps report rates up; shame drives clicks underground.
- No executive artifact. Without a one-page readout, the budget question in January has no answer.
FAQ
When is Cyber Security Awareness Month in 2026? October 2026, as it is every year. Week 1 starts Thursday 1 October 2026, so plan the kick-off for the first full working week.
How long should a Cyber Security Awareness Month campaign run? Four to five weeks, one short activity per week. A single-day event produces no measurable behaviour change; the weekly cadence through October is what moves click rates.
What does Cyber Aware contribute to an Awareness Month campaign? Cyber Aware supplies the training modules, the phishing simulations and the reporting - you supply the schedule and the communications.
Is Cyber Security Awareness Month worth running for a small team? Yes - the four-week format costs a small team roughly two hours of employee time across the month, and the week-2 versus week-4 simulation delta gives you a real number to report.