Conveyancers and settlement agents work in a deadline-driven environment where email instructions, identity documents, property records and large payments meet. Security awareness training for conveyancers must therefore rehearse the moments when a trusted request can quietly change a bank account, redirect settlement funds or expose a client’s personal information.
TL;DR
- Security awareness training for conveyancers and settlement agents should prioritise payment redirection, business email compromise, identity verification and secure document handling.
- A changed trust-account detail or settlement instruction is a verification event, not an ordinary email task.
- Different roles need different practice: reception, conveyancing staff, settlement agents, trust accounting, principals and contractors face different decisions.
- The safest workflow uses independent verification, separation of duties, a clear reporting route and a documented pause before high-value changes.
- Measure reporting, time to report, unsafe actions and repeat risk; course completion alone does not show whether settlement work became safer.
Why conveyancing teams are targeted
Property transactions create the exact conditions that social engineers look for: a known deadline, multiple parties, sensitive documents and a payment that cannot be casually delayed. Staff may be coordinating with a buyer, seller, lender, broker, agent, solicitor, financial institution and settlement platform while also answering urgent client questions.
An attacker does not need to understand every detail of a transaction. They only need to make one request look credible at the right time. A message may appear to come from a client asking to change account details, a lender requesting a new document, a colleague asking for a settlement file or a principal demanding an immediate transfer.
Scamwatch describes payment redirection scams as situations where scammers impersonate a business or its employees and request that an upcoming payment be sent to a fraudulent account. Its payment redirection scam guidance is a useful reminder that email instructions must not be treated as proof of identity or authority.
The Australian Signals Directorate’s Australian Cyber Security Centre also identifies business email compromise as a targeted form of phishing that can seek money, goods or important business information. Read its business email compromise guidance alongside the firm’s trust-account, client-verification and incident-response procedures.
Who this guide is for
This guide is for conveyancing practices, settlement agencies, property law teams and principals responsible for staff, contractors or outsourced support. It is also for managed service providers and compliance leaders helping a property-services business design practical security awareness training for conveyancers.
The Cyber Aware training platform is relevant when the programme needs to combine short learning, realistic phishing practice and human-risk reporting. The platform should reinforce the firm’s financial controls, approved communication channels and client-verification process; training cannot replace those controls.
The human risks to prioritise
1. Changed bank details and settlement instructions
Any request to change a trust-account detail, deposit destination, refund account or settlement instruction should trigger a controlled verification process. Teach staff to pause the change, use a trusted phone number or contact method already held in the file, confirm the details with the authorised party and record who performed the check.
Do not use the phone number, link or reply address supplied in the new request as the only verification route. A familiar email thread can still be compromised, and a real sender address does not prove that the new instruction is genuine.
2. Client and professional impersonation
Conveyancers routinely communicate with people who may be under pressure. An attacker can impersonate a client, agent, lender, broker, colleague or opposing firm and ask for a fast exception. Staff need a script for requests that are urgent, unusual or inconsistent with the file.
The safe response is to follow the approved identity and authority check, disclose only the minimum necessary information and escalate a request that tries to bypass the normal process. Training should reward a well-timed pause, not speed at any cost.
3. Credential phishing and fake portals
Property teams use email, document portals, settlement platforms, accounting systems and identity services. A fake sign-in page can look like a routine document-share notification or settlement update. Teach staff to access important systems through a known bookmark or the normal application, inspect unexpected links and report suspicious messages without entering credentials.
The Cyber Aware phishing programme should test scenarios that resemble real property work: an urgent contract upload, a lender document request, a settlement-room invitation or a client identity-verification message. Never use real client information or collect real passwords in a controlled exercise.
4. Sensitive documents and misdirected email
Contracts, identity documents, banking details, property records and correspondence should be sent only through approved channels and to verified recipients. A training module should cover autocomplete mistakes, reply-all, personal email, shared links, downloads to unmanaged devices and requests for a complete client file.
The correct behaviour is to check the recipient, use the approved secure channel and report a suspected misdirection immediately. Staff should know that a message sent to the wrong person is an incident to escalate, not a mistake to hide until the transaction is finished.
5. Trust accounting and financial authority
Trust accounting and finance staff face a different risk profile from front-office staff. They need practice with new payees, altered invoices, refund requests, dual approval and urgent payment exceptions. A person who can receive a request, update account details and release funds should not be the only control in the process.
Training should point to the exact separation of duties: who checks the instruction, who verifies the account, who approves the payment and who records the evidence. If the firm has no clear answer, the gap is operational and needs an owner beyond the training programme.
6. Contractors, agents and outsourced providers
A practice may rely on virtual assistants, IT providers, document services, offshore support or external settlement partners. Each relationship introduces people who may handle access, documents or payment information.
Make onboarding, access reviews and offboarding part of the awareness programme. Contractors should know which systems they may use, how they verify an unusual request, where they report a suspected compromise and what happens when their engagement ends. The ACSC’s managing cyber supply chains guidance provides a useful external reference for assigning ownership across supplier relationships.
What effective security awareness training for conveyancers includes
A role map that follows the transaction
Start by mapping who can see, change, approve or pay each important item. The map does not need to be complicated:
- Reception and administration: client contact details, identity documents and incoming requests.
- Conveyancing staff: contracts, authorities, client instructions and document sharing.
- Settlement agents: settlement schedules, lender communication and completion steps.
- Trust accounting and finance: payees, refunds, deposits and payment release.
- Principals and managers: exceptions, approvals, incident decisions and client communication.
- Contractors and suppliers: system access, shared files and service requests.
Assign training to the decisions each role can make. A generic module about phishing will not teach a trust accountant how to verify a new bank detail or a receptionist how to handle a request for a client’s full file.
Short learning followed by realistic practice
Use a short lesson to explain the safe action, then practise it in a controlled scenario. A conveyancer might receive a request to send a document to a new address. A settlement agent might receive an urgent account change. A principal might receive a message asking for an exception to the normal approval chain.
The exercise should make reporting easy and should not punish a person for asking for a second check. The aim is to make the safe response habitual under deadline pressure.
Payment controls that the training can explain
Training is most useful when it matches the firm’s actual payment process. Document the trusted contact method, the minimum information required to verify a change, the second approver and the person who can pause a payment. Then use that process in the learning and simulation.
If the safe process is too slow, improve it rather than telling staff to be more careful. A clear verification route is a control that makes good judgement possible.
A visible reporting route
Staff should be able to report a suspicious email, unexpected login prompt, misdirected document or unusual payment request in under a minute. The route should be visible in the tools they use and should identify who responds after the report.
Managers need a simple response script: acknowledge the report, preserve the message and relevant details, stop the affected process where appropriate and escalate to the security, finance or practice owner. Blame makes the next report slower.
Programme picks for conveyancers and settlement agents
Role-based learning — Buy
Role-based learning is the right buy for a practice with separate administration, conveyancing, settlement, trust-accounting and leadership responsibilities. It makes the difference between a person knowing that phishing exists and knowing exactly how to verify a settlement instruction.
Choose a platform that can assign relevant content, refresh it when processes change and show risk by team or workflow. Cyber Aware should be judged on whether the programme supports those decisions, not just on the number of courses listed in its catalogue.
Payment-redirection drills — Buy
Payment-redirection practice is a high-priority buy because one believable request can affect a large transaction. Use a controlled scenario that tests the pause, independent verification, second approval and evidence record. A successful exercise ends with safe verification, not with the learner merely identifying a suspicious logo.
Human-risk reporting — Buy
Human-risk reporting is a buy when principals need to see whether staff are reporting, escalating and repeating risky actions. Use the human-risk reporting view to compare trends by team, role and workflow, then decide whether the answer is coaching, a process change or a technical control.
Do not use the data to create a public leaderboard. The goal is to identify where the safe action is unclear or difficult and remove that friction.
Annual generic training only — Skip
Skip a programme that records attendance but never tests changed bank details, document sharing, client impersonation or portal phishing. Annual training can provide baseline coverage, but it is not enough evidence that settlement work is safer under time pressure.
A 90-day rollout
Days 1–30: map the money and information
List the workflows that can change payment details, release funds, disclose identity documents, upload contracts, grant access or communicate a client instruction. For each workflow, document the trusted verification route, the second approver and the incident-reporting owner.
Run a low-risk baseline exercise. Record reporting rate, time to report, unsafe actions and the workflow where the decision failed. Complete a gap assessment and rank the gaps by financial and client impact.
Days 31–60: train the high-consequence roles
Deliver short, role-specific modules to administration, conveyancing, settlement, trust accounting, principals and contractors. Pair each lesson with the written procedure the learner must follow.
Run a second exercise with a different lure. A new payee request, fake settlement-room invitation and misdirected-document scenario will reveal different weaknesses. Give managers a response checklist and reinforce people who report quickly.
Days 61–90: test the response
Hold a tabletop exercise with security, finance, practice management, conveyancing leads and leadership. Test who can pause a payment, freeze a change, contact a client through a trusted route, revoke access and preserve evidence.
Review the change from the baseline. More reports can be positive if staff are using the route earlier. Look for faster escalation, fewer unsafe actions and fewer repeat failures. Where the same problem persists, redesign the process rather than repeating the same course.
Measure behaviour, not just completion
A useful dashboard for security awareness training for conveyancers includes:
- Reporting rate: the share of participants who use the approved route for a suspicious message or request.
- Time to report: the elapsed time between receiving or discovering a concern and escalating it.
- Unsafe action rate: clicks, credential submissions, unauthorised disclosure or attempted payment-process bypasses in a controlled exercise.
- Repeat-risk rate: the share of people or teams repeating the same unsafe action after coaching.
- Workflow concentration: whether risk clusters around trust accounting, document sharing, client verification, settlement communication or supplier access.
Completion belongs in the record, but it should not be the headline result. The operating question is whether people can make and report a safe decision when a transaction is moving quickly.
Choosing a platform
Before selecting a platform, check whether it can support role-based assignments, realistic simulations, simple reporting and trend analysis. Confirm that it can include contractors and remote staff without losing ownership of results.
Ask how the programme handles sensitive information. A training provider should not need genuine client documents, account numbers or passwords to demonstrate whether a process works.
Use the security awareness platform comparison to structure the buying review, then confirm the shortlisted product’s current capabilities, integrations and pricing in the proposal. A feature list is not evidence of behaviour change.
FAQ
What is the best security awareness training for conveyancers?
The best security awareness training for conveyancers is role-based practice that covers payment redirection, business email compromise, identity verification, secure document handling and rapid reporting. It should match the firm’s real approval routes and measure behaviour, not only course completion.
How can a conveyancing firm prevent payment redirection?
Use independent verification for every changed bank detail or settlement instruction, a trusted contact method already held in the file, separation of duties and a documented second approval. Train staff to pause the request and report it when the normal process cannot be followed.
What should settlement agents practise?
Settlement agents should practise urgent payment requests, changed account details, fake settlement-room invitations, lender impersonation and requests to bypass a client or authority check. Exercises should use fictional data and an obvious reporting route.
How should staff handle a suspicious client email?
Staff should stop the requested action, avoid replying with sensitive information, verify the request through a trusted contact method and report the message to the designated owner. If a payment or document has already been sent, escalate immediately rather than waiting for more evidence.
Should every employee receive the same training?
No. Everyone needs a common baseline, but reception, conveyancing, settlement, trust accounting, principals and contractors make different decisions and need different practice.
How often should conveyancing teams run phishing simulations?
Run controlled practice throughout the year and change the scenario when roles, systems, suppliers or procedures change. Use the results to improve the process and target coaching, not to shame individuals.
What metrics should a principal review?
Review reporting rate, time to report, unsafe action rate, repeat risk and workflow concentration, alongside completion. These measures show whether staff can protect client information and payment processes under pressure.
One last thing
The most dangerous request in a conveyancing practice often looks ordinary: a familiar name, a real transaction and one changed detail. Make that detail trigger an independent check, a second approval and a fast report. The safer process should be easier to follow than the urgent shortcut.