Most awareness efforts fail before the first module loads — not because the content is wrong, but because nobody built a programme. A course gets bought, assigned once, reported once and forgotten. A programme is different: enrolment, training, testing and reporting run as a repeating cycle with named owners, and the numbers prove whether it works. The case for building one properly is stark. Before training, roughly one in three employees interacts with a phishing email — KnowBe4's 2025 Phishing by Industry Benchmarking Report measured 33.1% globally and 36.8% across Australia and New Zealand. After twelve months of ongoing training that figure falls 86%, to 4.1%. And with the human element behind roughly 60% of breaches according to Verizon's 2025 Data Breach Investigations Report, the people layer is the one worth building first. Here is the 90-day build, step by step.
Programme versus course: the difference that matters
| One-off course | Ongoing programme | |
|---|---|---|
| Cadence | Once a year | Monthly module plus monthly simulation |
| Enrolment | Manual spreadsheet, leaks starters and leavers | Synced from your Google or Microsoft directory |
| Measurement | Attendance certificate | Click rate, report rate, completion, risk score |
| Evidence | A PDF nobody opens | Dated reports ready for audits and insurers |
| Outcome at 12 months | Little measurable change | 86% fewer phishing clicks (2025 benchmark) |
The right column is not a bigger budget — it is the same training, run as a system. The 90 days below get you there.
Week 0: baseline before you train
Measure before you change anything, or you will never be able to prove the programme paid off. Two baselines in the first week:
- Run a baseline phishing simulation to every staff member and record the click rate. Expect a number near the benchmark: roughly a third of people will interact with the lure.
- Score your controls with a structured gap assessment so the technical gaps — MFA coverage, backup testing, email authentication — sit in the same plan as the human ones.
Write both numbers down. Everything the programme does for the next two quarters is judged against them.
Days 1-30: enrol everyone and set the rhythm
Month one is about building the machine, not maximising content:
- Sync enrolment from your directory (Google Workspace or Microsoft 365) so every active account is in, and leavers drop out automatically. No spreadsheet, no gaps.
- Assign the first module — short, 5-10 minutes, due on a fixed date.
- Fix the monthly rhythm: assign on the 1st, remind on days 7 and 21, close on day 25 with a grace window for leave.
- Brief line managers on the rhythm and give them their own team's completion list, so chasing does not all land on IT.
Cyber Aware's security awareness training is built around exactly this cycle — auto-enrolment, short monthly modules and due-date reminders — which is why month one is mostly configuration rather than content work.
The success test for month one is simple: everyone enrolled, one module completed, one simulation run, one report produced.
Days 31-60: content that matches the attacks you actually face
Generic content collects completions; specific content changes behaviour. Map each month's module to the attacks that actually hit businesses like yours — invoice fraud for anyone touching payments, MFA fatigue prompts for Microsoft 365 users, QR-code scams for front-desk and operations staff.
Three rules keep the content working:
- One topic per month, tied to a realistic lure your staff could receive this week.
- Escalating simulation difficulty, so month three is harder than month one and recognition keeps improving instead of plateauing.
- Constructive failure handling: a click triggers a two-minute refresher, never public shaming. Punishing clicks teaches staff to hide clicks and destroys the reporting culture you need.
By the end of month two you should see the first real signal: the second simulation's click rate below the baseline, and — just as important — more staff reporting the simulated email instead of silently deleting it.
Days 61-90: reporting that proves the programme
By day 60 the inputs exist. The last month is about making the outputs legible to people outside IT:
- A monthly one-page report to leadership: completion percentage, click-rate trend against the baseline, report rate, and the teams that need help.
- Per-person risk signals: human risk reporting turns overdue modules, failed quizzes and simulation clicks into a per-person score, so follow-up targets people rather than the whole company.
- An evidence pack: dated completion records and simulation results — exactly what insurers, client security questionnaires and frameworks ask for. SMB1001's 2026 edition, for example, moved staff awareness training into its Bronze tier, so the evidence is now a certification requirement, not a nice-to-have.
Roles: who owns what
- Programme owner (usually the IT or security lead): owns the rhythm, the simulation calendar and the monthly report.
- Line managers: chase their own team's overdue list weekly; their ask lands harder than a system email.
- Every employee: complete the monthly module and report suspicious email — reporting is a win, not an admission of failure.
- Leadership: read the monthly report and escalate the stubborn non-completers.
What good looks like at day 90
- 95%+ completion on the current month's module, with the remainder actively escalated.
- Click rate already falling from the baseline — the benchmark data shows roughly a 40% drop within the first 90 days of ongoing training.
- Report rate rising: staff forwarding suspicious email to security instead of ignoring it.
- Next quarter's simulation calendar and module plan already scheduled.
If completion is stuck below 80% at day 90, the problem is almost always deadline mechanics or manager visibility, not the content.
FAQ
How much does a programme cost?
Most platforms price per seat per year, so the line item scales with headcount — for most small businesses it is a rounding error against the average small-business cybercrime loss of $56,000 per incident reported to ASD in FY2024-25.
How long before we see results?
Click rates usually start falling within the first quarter — roughly 40% below baseline by day 90 in the benchmark data — with the full 86% reduction appearing only after about twelve months of sustained training.
Can we run it without a dedicated security person?
Yes. A programme owner needs a few hours a month once the automation — directory sync, scheduled modules, automatic reminders — is configured.
What about contractors and part-timers?
Include them. Attackers do not check employment status, and contractors are exactly the population manual enrolment tends to miss — another reason directory sync beats spreadsheets.
How do we keep it from becoming box-ticking?
Track behaviour, not attendance: click rate, report rate and overdue counts in the monthly report. The moment the report stops changing, the programme has stalled — refresh the scenarios before the numbers flatline for good.
One last thing
Run the baseline before you buy anything. A programme's value is measured against the number you capture in week zero, and a baseline taken after training has already started is a number you can never honestly compare against.