The ACSC threat report is useful to staff training only when its national findings become specific behaviours, practice scenarios and reporting habits inside your organisation. This 2026 guide shows how to turn the latest Australian threat picture into a 90-day training plan without treating a report as a checklist.
TL;DR
- The 2024–25 ACSC report recorded phishing or social engineering in 60% of reported incidents; make it the first training priority.
- Use the report to choose role-specific scenarios, not to copy a generic annual course for everyone.
- Review the plan every 90 days against clicks, reports, completion and incident patterns.
- Cyber Aware training gives MSPs a practical way to assign lessons, run phishing practice and show progress.
Why this matters
The Annual Cyber Threat Report 2024–25, published by ASD’s Australian Cyber Security Centre on 14 October 2025, gives Australian organisations a current threat baseline. It records more than 42,500 calls to the Australian Cyber Security Hotline, over 1,200 cyber security incidents responded to by ASD’s ACSC and more than 84,700 cybercrime reports during FY2024–25.
Those figures do not tell you which lesson to assign on Monday. Your job is to translate them into the decisions people make at work: whether they verify a payment change, report a suspicious message, approve an unexpected login or share a sensitive file. A report-led program makes that translation deliberate.
Cyber Aware training is designed around story-driven lessons, quizzes and completion tracking. Use it as one organisational control inside a wider security program, not as a replacement for identity controls, secure configuration or incident response.
What you will need
Before building the plan, gather:
- The latest ACSC threat report and the report date.
- A list of the systems, suppliers and payment processes each team uses.
- Recent phishing results, helpdesk tickets and security incidents.
- The people who own finance, HR, IT, customer data and incident response.
- A short route for reporting suspicious emails, calls, messages and requests.
- Thirty minutes with each department leader to test whether the scenarios sound real.
Do not begin by choosing courses. Begin with the work your people perform and the consequences of a wrong decision.
Step 1: extract the threats that change behaviour
Read the executive summary, incident breakdowns and mitigation advice. In the 2024–25 report, phishing or social engineering appeared in 60% of incidents reported to ASD’s ACSC. The same report records business cybercrime losses of $56,600 per report for small businesses, $97,200 for medium businesses and $202,700 for large businesses; those are average self-reported costs of cybercrime reports, not a promise about one phishing event.
Write each finding as a behaviour. Phishing becomes verify the sender and report the message. Credential theft becomes reject unexpected MFA prompts and use the approved sign-in route. Third-party risk becomes verify a supplier change through a known channel.
Expected outcome: a short list of behaviours that training can practise. Common mistake: turning every sentence in the report into a separate module.
Step 2: map each behaviour to a role
A finance team, service desk and warehouse crew should not receive the same examples. Finance needs supplier bank-detail changes, invoice attachments and urgent payment requests. HR needs candidate documents, payroll changes and fake benefits messages. IT needs privileged access, reset requests and suspicious administrator prompts.
Create a simple matrix with four columns: role, risky decision, safe response and evidence of learning. Keep the wording close to the team’s real workflow. If staff use a booking platform, collaboration suite or customer portal, use that context only when it is accurate.
Expected outcome: each group sees why the threat matters to its own work. Common mistake: using consumer-brand examples that do not resemble the systems people actually use.
Step 3: make phishing the practice engine
The report’s 60% phishing and social-engineering finding justifies recurring practice, not a single annual surprise. Use phishing simulations to rehearse sender checks, link inspection, attachment caution and reporting. Cyber Aware says its platform includes more than 100 templates, tracks clicks and reports, and can assign follow-up training after a simulated click.
Start with an obvious scenario so the reporting route is understood. Move to role-specific scenarios only after people know how to report. A useful 90-day sequence has one baseline message in the first 30 days, one function-specific scenario in days 31–60 and one harder scenario in days 61–90.
Expected outcome: staff can identify and report a suspicious message under time pressure. Common mistake: measuring only clicks. A rising report rate can be a positive result even when click rate has not yet moved.
Step 4: connect training to the Essential Eight
The Essential Eight is an Australian baseline of eight mitigation strategies that makes compromise harder; it is not a substitute for a learning program. Training supports several strategies by helping people use MFA correctly, avoid unsafe macros or applications, protect privileged accounts and report suspicious activity quickly.
For each training topic, name the technical owner and the human action. MFA training should point to the approved authenticator process. Application-hardening training should explain why unapproved software or risky browser behaviour creates exposure. Privileged-user training should be separate from the general workforce lesson.
Expected outcome: training is connected to a control owner and a process. Common mistake: claiming that course completion proves an Essential Eight mitigation is implemented.
Step 5: build a 90-day curriculum
In days 1–30, teach the baseline: phishing, strong passphrases, MFA prompts, safe file sharing, payment verification and incident reporting. Keep lessons short and give new starters the same baseline within their first 7 days.
In days 31–60, add role-based scenarios and a private remediation path. Give finance a payment-diversion exercise, HR a fake document request and executives an impersonation scenario. In days 61–90, run a tabletop exercise that connects a suspicious message to containment, escalation and business communication.
Repeat the cycle when the threat picture, systems or business processes change. A calendar is a delivery mechanism; it is not evidence that the content remains relevant in 2026.
Step 6: measure the change
Track five measures: completion within the due window, overdue assignments, phishing click rate, phishing report rate and time from delivery to report. Add incident and helpdesk patterns where the data is reliable. Compare the same definitions across months so that a change in reporting does not create a false trend.
Human risk reporting turns overdue courses, failed quizzes and phishing behaviour into a learner-level risk signal. Use the output to identify who needs support and which process needs repair. Do not publish individual results as a punishment.
Expected outcome: a board or client conversation can show behaviour and trend, not just attendance. Common mistake: using a 100% completion rate as proof that the organisation is safe.
Step 7: brief leaders with a decision
Give executives a one-page update every quarter. Include the threat finding that drove the program, the two behaviours that changed, the remaining high-risk cohort and one decision required from leadership. For example, ask for approval to enforce a second-channel payment check or to fund a control that training alone cannot provide.
The ACSC report is a national source, but leaders need a local answer. State what the organisation will do differently in the next 90 days and who owns the result.
Troubleshooting
The report feels too broad
Choose the two findings most connected to your systems and data. A smaller plan tied to actual decisions is stronger than a catalogue of every threat category.
Staff say the examples are unrealistic
Ask department leaders for three genuine requests they would want checked. Remove confidential details, then turn the patterns into safe practice scenarios.
Click rate rises after training
Check whether reporting also rose and whether the new campaign is harder. A short-term increase can show that the measurement became more realistic; use the next two campaigns to judge direction.
Leaders want one annual course
Show the difference between annual attendance and recurring practice. Recommend a baseline course plus a 90-day simulation cycle, with a clear owner and a small set of measures.
The training report is full of overdue users
Separate enrolment problems from behaviour problems. Reconcile active accounts, contractors and leave exceptions first, then assign managers a weekly exception list.
Tools and resources
- Cyber security gap assessment to map client posture and priorities against frameworks.
- Cyber Aware comparison guide to assess platform fit when procurement is part of the plan.
- NIST SP 800-50 Rev. 1, Building a Cybersecurity and Privacy Learning Program, published September 2024, for lifecycle planning and evaluation ideas.
- The ACSC Annual Cyber Threat Report 2024–25 for the Australian threat baseline and date scope.
FAQ
How often should staff training be updated from the ACSC threat report?
Review the program at least every 90 days and whenever a new ACSC report, advisory or material business change affects the risk picture. Keep the report date beside each curriculum decision.
What should staff learn from the ACSC threat report?
They should learn the safe response to the threats that touch their work: verify unusual requests, protect credentials, report suspicious messages and escalate incidents quickly.
Does the ACSC report replace a security awareness program?
No. It provides threat intelligence and national context; the organisation still needs role-based lessons, practice, reporting routes, technical controls and measurement.
Why prioritise phishing in 2026?
Phishing or social engineering was recorded in 60% of incidents reported to ASD’s ACSC during FY2024–25. That makes it a defensible first priority for behaviour practice, while other controls remain necessary.
How do you measure whether report-led training works?
Track completion, overdue work, clicks, reports and time to report using stable definitions across at least two or three campaign cycles. Pair those measures with incident and helpdesk evidence.
Should executives receive the same training as everyone else?
Executives need the baseline plus scenarios involving impersonation, payment approval, sensitive information and urgent decision-making. Their training should be role-specific, not exempt.
One last thing
The most useful line in an ACSC report is not the one with the largest number. It is the line that changes what a person does when an urgent request arrives in their inbox, phone or chat.
Sources
- ASD Annual Cyber Threat Report 2024–25, published 14 October 2025, covering FY2024–25.
- ASD Essential Eight, accessed for the 2026 baseline.
- NIST SP 800-50 Rev. 1, published September 2024, covering learning-program lifecycle and evaluation.