Conveyancers and settlement agents move the largest single payments most clients will ever make — and email is still how bank details, variations, and last-minute instructions travel. That mix makes payment redirection the defining fraud risk for the profession in 2026.
TL;DR
- Security awareness training for conveyancers must centre on payment redirection and trust-account fraud, not generic phishing slides.
- Role-based micro-lessons plus scheduled BEC simulations beat a once-a-year compliance video for settlement desks.
- A verbal call-back rule on numbers already on file is the highest-value control you can train and measure.
- Cyber Aware fits small conveyancing practices that need short modules, phishing drills, and exportable completion evidence.
- Skip annual LMS courses that never simulate a fake 'updated trust account' email from a lookalike domain.
Why this matters
A conveyancing file is a fraud magnet: large one-off transfers, tight settlement windows, multiple parties (buyer, seller, broker, bank, agent), and heavy email traffic. Attackers do not need malware when a single spoofed message can redirect deposit or balance funds into an account they control.
PEXA has publicly warned that payment redirection — a form of business email compromise — is the pattern hitting buyers, sellers, and practitioners. Losses in the hundreds of thousands of dollars per matter are not theoretical; they have already hit Australian settlements when email was used to exchange bank details.
Generic security awareness training still talks about lottery scams and fake shipping notices. Conveyancing teams lose money on a different script: a familiar matter reference, a PDF that looks like every other settlement instruction, and one changed BSB.
Who this is for
This guide is for principals, practice managers, and compliance leads in conveyancing and settlement firms — including sole practitioners and multi-office groups — who need staff training that matches how money actually moves on a file. If your team handles trust money, issues settlement figures, or emails clients about account details, the criteria below apply.
What to look for in security awareness training for conveyancers
Payment redirection and trust-account scenarios
Training has to open with the fraud your desk actually sees: spoofed practitioner email, compromised client inbox, fake "updated bank details" on the morning of settlement, and urgent variation requests that skip the usual dual-check. If the catalogue only has retail phishing templates, it will not change behaviour on a live matter.
Verbal verification as a trained skill, not a poster
PEXA and the Australian Cyber Security Centre both push the same practical rule: do not treat email as a safe channel for bank details. Staff need a spoken call-back script, practice saying it under time pressure, and a logged outcome — the same discipline covered in guides on verifying supplier bank detail changes.
Short modules that fit a settlement calendar
Conveyancers do not have a quiet quarter for a 45-minute LMS course. Five- to twelve-minute story-led lessons that can be finished between settlements stick; marathon annual videos get muted.
Phishing simulation on BEC, not only brand spoofs
Clicking a fake retail login is a weak proxy for the risk on your desk. You need phishing simulations that look like matter updates, trust-account changes, and broker or bank follow-ups — then automatic short remediation when someone fails.
Evidence for PI insurance, audits, and principals
Professional indemnity renewals and internal file reviews increasingly ask for proof of ongoing cyber training, not a single induction certificate. Exportable completion rates, simulation report rates, and a simple human risk reporting view matter more than a vanity dashboard.
Coverage for every role that touches the money path
Principals, employed conveyancers, settlement clerks, reception, and bookkeepers all sit on different parts of the same attack path. Role-based paths beat one generic course forced on everyone.
Top picks for conveyancing and settlement training
The safe pick — role-based micro-training with BEC drills. Short lessons mapped to conveyancer, clerk, and accounts roles, plus scheduled payment-redirection simulations and a call-back checklist. Buy for any firm that moves trust money by email today.
The wildcard — facilitated annual workshop only. A half-day with a trainer can kick off culture change and brief a new principal. It builds little muscle memory and weak audit evidence on its own. Consider as a launch event, never as the whole program.
The one that looks right but isn't — generic annual compliance video. Ticks a box for "staff trained" but almost never rehearses settlement redirection or trust-account change requests. Staff click through during lunch and forget it by the next matter. Skip if payment fraud is your real risk.
The full stack — training + phishing simulation + risk scoring. Combines story-led security awareness training, matter-style BEC simulations, and per-learner scores principals can review monthly. Cyber Aware is built around that stack for small professional services teams. Buy when you want one system instead of three disconnected tools.
Train the desk that moves the money
See how Cyber Aware runs short BEC lessons and payment-redirection simulations for professional services teams.
What to avoid
- Emailing bank details "just this once" because settlement is today. That exception is the entire scam model. Train the no-exceptions call-back and back it with process, not hope.
- Simulations that never mention trust accounts or matter references. If every lure is a fake Netflix login, your highest-paid staff never practise the failure mode that costs six figures.
- Seat models that ignore casual clerks and bookkeepers. The person who processes the variation or updates the ledger is often not the licensed conveyancer — and still needs the drill.
Verdict comparison
| Approach | Covers payment redirection | Fits settlement calendars | Audit-ready evidence | Verdict |
|---|---|---|---|---|
| Role-based micro-training + BEC drills | Yes | Yes | Yes | Buy |
| Annual facilitated workshop | Partial | Yes | Weak | Consider |
| Generic compliance video | No | No | Checkbox only | Skip |
| Training + simulation + risk scores | Yes | Yes | Yes | Buy |
FAQ
What is the best security awareness training for conveyancers in 2026?
Programs that rehearse payment redirection, trust-account changes, and verbal call-backs outperform generic phishing videos. Pair short role-based lessons with BEC-style simulations and exportable completion records.
Why are conveyancers targeted by cybercriminals?
Settlements move large one-off sums under time pressure, and bank details still travel by email between clients, agents, banks, and practitioners. That combination makes business email compromise and payment redirection highly profitable for attackers.
Is a phone call enough to verify new bank details?
Only if you call a number already on the client or matter file — never a number inside the suspicious email. PEXA and ACSC guidance both stress verbal confirmation off-channel, not reply-to-sender checks.
How often should conveyancing firms run phishing simulations?
Quarterly as a minimum, with a tighter 30-day burst of three BEC-style sends when you first stand the program up. Annual-only testing leaves most of the year untested.
Does training help with professional indemnity and cyber insurance?
Most insurers ask for evidence of ongoing staff awareness, not a single induction slide. Platforms that export completion and simulation results make renewals faster and claims conversations clearer.
Should sole practitioners bother with a formal platform?
Yes if you still exchange bank details by email or run a trust account. A lightweight stack with short lessons and a few realistic simulations is enough; a 200-seat enterprise LMS is not required.
What should staff do if they already clicked a suspicious settlement email?
Stop further replies, preserve the message, tell the principal immediately, and contact the bank and any platform involved before funds move. Speed of escalation matters more than blame.
One last thing
The email that empties a trust account rarely looks like a scam. It looks like the twentieth message on a familiar matter, with one field changed. If your training never forces staff to pause on that exact pattern — and log a call-back — you are preparing them for someone else's threat model.