Staff security awareness training programme: the 90-day guide

How to build a staff security awareness training programme in 90 days: baseline testing, monthly cadence, phishing simulations and the reporting that proves it works.

Most awareness efforts fail before the first module loads — not because the content is wrong, but because nobody built a programme. A course gets bought, assigned once, reported once and forgotten. A programme is different: enrolment, training, testing and reporting run as a repeating cycle with named owners, and the numbers prove whether it works. The case for building one properly is stark. Before training, roughly one in three employees interacts with a phishing email — KnowBe4's 2025 Phishing by Industry Benchmarking Report measured 33.1% globally and 36.8% across Australia and New Zealand. After twelve months of ongoing training that figure falls 86%, to 4.1%. And with the human element behind roughly 60% of breaches according to Verizon's 2025 Data Breach Investigations Report, the people layer is the one worth building first. Here is the 90-day build, step by step.

Programme versus course: the difference that matters

One-off courseOngoing programme
CadenceOnce a yearMonthly module plus monthly simulation
EnrolmentManual spreadsheet, leaks starters and leaversSynced from your Google or Microsoft directory
MeasurementAttendance certificateClick rate, report rate, completion, risk score
EvidenceA PDF nobody opensDated reports ready for audits and insurers
Outcome at 12 monthsLittle measurable change86% fewer phishing clicks (2025 benchmark)

The right column is not a bigger budget — it is the same training, run as a system. The 90 days below get you there.

Week 0: baseline before you train

Measure before you change anything, or you will never be able to prove the programme paid off. Two baselines in the first week:

  1. Run a baseline phishing simulation to every staff member and record the click rate. Expect a number near the benchmark: roughly a third of people will interact with the lure.
  2. Score your controls with a structured gap assessment so the technical gaps — MFA coverage, backup testing, email authentication — sit in the same plan as the human ones.

Write both numbers down. Everything the programme does for the next two quarters is judged against them.

Days 1-30: enrol everyone and set the rhythm

Month one is about building the machine, not maximising content:

  1. Sync enrolment from your directory (Google Workspace or Microsoft 365) so every active account is in, and leavers drop out automatically. No spreadsheet, no gaps.
  2. Assign the first module — short, 5-10 minutes, due on a fixed date.
  3. Fix the monthly rhythm: assign on the 1st, remind on days 7 and 21, close on day 25 with a grace window for leave.
  4. Brief line managers on the rhythm and give them their own team's completion list, so chasing does not all land on IT.

Cyber Aware's security awareness training is built around exactly this cycle — auto-enrolment, short monthly modules and due-date reminders — which is why month one is mostly configuration rather than content work.

The success test for month one is simple: everyone enrolled, one module completed, one simulation run, one report produced.

Days 31-60: content that matches the attacks you actually face

Generic content collects completions; specific content changes behaviour. Map each month's module to the attacks that actually hit businesses like yours — invoice fraud for anyone touching payments, MFA fatigue prompts for Microsoft 365 users, QR-code scams for front-desk and operations staff.

Three rules keep the content working:

By the end of month two you should see the first real signal: the second simulation's click rate below the baseline, and — just as important — more staff reporting the simulated email instead of silently deleting it.

Days 61-90: reporting that proves the programme

By day 60 the inputs exist. The last month is about making the outputs legible to people outside IT:

Roles: who owns what

What good looks like at day 90

If completion is stuck below 80% at day 90, the problem is almost always deadline mechanics or manager visibility, not the content.

FAQ

How much does a programme cost?

Most platforms price per seat per year, so the line item scales with headcount — for most small businesses it is a rounding error against the average small-business cybercrime loss of $56,000 per incident reported to ASD in FY2024-25.

How long before we see results?

Click rates usually start falling within the first quarter — roughly 40% below baseline by day 90 in the benchmark data — with the full 86% reduction appearing only after about twelve months of sustained training.

Can we run it without a dedicated security person?

Yes. A programme owner needs a few hours a month once the automation — directory sync, scheduled modules, automatic reminders — is configured.

What about contractors and part-timers?

Include them. Attackers do not check employment status, and contractors are exactly the population manual enrolment tends to miss — another reason directory sync beats spreadsheets.

How do we keep it from becoming box-ticking?

Track behaviour, not attendance: click rate, report rate and overdue counts in the monthly report. The moment the report stops changing, the programme has stalled — refresh the scenarios before the numbers flatline for good.

One last thing

Run the baseline before you buy anything. A programme's value is measured against the number you capture in week zero, and a baseline taken after training has already started is a number you can never honestly compare against.

Sources

Ready to deploy

Same playbook.
Your brand.

Cyber Aware's Human Risk Score works the same way for every MSP partner - under your brand, on your cadence.