Is cyber security training mandatory in Australia? What the law actually requires

No single law mandates cyber training for all Australian businesses - but the Privacy Act, APRA CPS 234, SOCI and government contracts make it mandatory in practice. Here's what each regime requires.

No single Australian law says 'every employee must complete cyber security training'. But if you sit under the Privacy Act, APRA CPS 234, the Security of Critical Infrastructure Act, or you answer government tenders, your regulators already expect you to prove your staff are trained and tested - and several of these regimes changed materially in 2024-2026. Here is what each one actually asks of you, and how to evidence it.

TL;DR

Why this matters

Business owners ask this question because they are deciding whether to fund training or defer it. The honest answer is that Australia regulates the outcome, not the activity: every regime below holds you accountable for human-driven breaches, and training is the standard control the sector recognises for the human layer. Verizon's 2025 Data Breach Investigations Report found around 60% of breaches involve a human element - error, misuse or social engineering - which is precisely why auditors keep asking about training.

The Privacy Act and the 2024-2025 reforms

The Privacy Act 1988 requires organisations covered by the Australian Privacy Principles to take reasonable steps to protect personal information from misuse, interference, loss and unauthorised access. The Privacy and Other Legislation Amendment Act 2024 added a statutory tort for serious invasions of privacy and significantly higher penalties for serious or repeated privacy breaches, with further privacy reform continuing to roll out.

None of this text says 'train your staff'. But when the OAIC investigates a breach caused by an employee clicking a phishing link, the absence of any staff awareness program is exactly the kind of gap it treats as evidence that reasonable steps were not taken. A documented security awareness training program with completion records is your evidence.

APRA CPS 234

If you are an APRA-regulated entity - a bank, insurer or large superannuation trustee, or a service provider to one - CPS 234 requires you to maintain information security capability commensurate with the size of your business, and to test your incident response. APRA's compliance expectations explicitly discuss keeping personnel skills and awareness current. For APRA entities and their suppliers, training is not optional in any practical sense.

The Security of Critical Infrastructure Act (SOCI)

Entities captured by SOCI's enhanced cybersecurity obligations - across energy, transport, water, health, food and grocery and other critical sectors - must maintain risk management programs covering governance, personnel and cybersecurity. Staff who do not know what a suspicious payment request looks like are a gap in any of those programs, and boards of these entities carry personal accountability. Assessors examining a SOCI program consistently start with whether people were trained and whether the training register matches reality.

Government contracts and the Essential Eight

If you sell to federal or state government, your contract almost certainly references the Australian Cyber Security Centre's Essential Eight mitigation strategies. Several of the eight - restricting Microsoft Office macros, user application hardening, multi-factor authentication - assume users who understand why a control exists and do not try to work around it. The ACSC's small business guidance names staff awareness training as a foundational control, and tender evaluators increasingly ask for a training register rather than a policy document alone.

Cyber insurance

Insurers now routinely ask about phishing simulations and security awareness training as a condition of cover. The KnowBe4 2025 Phishing by Industry Benchmarking Report measured the global average phish-prone rate - the share of employees who click a simulated phishing link - at 33.1% before training, falling to 4.1% after twelve months of consistent training and simulation. Insurers read those numbers: an organisation that cannot show a program pays more premium, or walks away without cover at all.

What 'mandatory in practice' means for your business

Work through this checklist:

  1. Do you hold personal information? The Privacy Act applies - training is your evidence of reasonable steps.
  2. Are you APRA-regulated, or a supplier to an APRA entity? CPS 234 - documented, current training.
  3. Are you in a critical infrastructure sector? SOCI - trained, exercised staff.
  4. Do you bid for government work? Essential Eight alignment - a training register.
  5. Do you carry cyber insurance? Training and simulation history - a condition of cover.

If none of the five apply, training is still the cheapest control you will ever buy: IBM's 2025 Cost of a Data Breach report puts the Australian average breach at USD 2.55 million, and the human element is involved in roughly 60% of incidents.

How to evidence a training program

Regulators and auditors want three artifacts:

FAQ

Is cyber security training legally required in Australia? Not for all businesses as a standalone statute. Sector regimes - Privacy Act reasonable steps, APRA CPS 234, SOCI and government contracts - make it mandatory in practice, and insurers increasingly treat it as a condition of cover.

Which businesses must do cyber security training under the Privacy Act? Any organisation covered by the Australian Privacy Principles that collects personal information. The OAIC expects reasonable security steps, and staff awareness is considered one of them.

How often should Australian staff complete cyber training? At least annually for core modules, with monthly micro-training and quarterly phishing simulations. Benchmark data shows 90 days of consistent training cuts phish-prone rates by about 40%.

Does the OAIC ask for training records after a breach? Training records, simulation history and policies are among the first artifacts an OAIC investigation or a cyber insurance claim will request.

Related guides

Ready to deploy

Same playbook.
Your brand.

Cyber Aware's Human Risk Score works the same way for every MSP partner - under your brand, on your cadence.