A cyber security awareness program should include six parts: a baseline assessment, automatic onboarding, regular short training, phishing simulations, automatic remediation and reporting that proves progress. Programs that stop at a once-a-year video miss the parts that change behaviour.
TL;DR
- Start with a baseline so you can show improvement later.
- Enrol new starters automatically and train on a monthly rhythm.
- Run phishing simulations and send anyone who fails straight into a short remediation course.
- Make reporting easy for staff and make the results visible to leadership.
- Keep the evidence: completion logs and click and report trends are what auditors, insurers and clients ask for.
What should a cyber security awareness program include in 2026?
The six components below work for any size of organisation. The difference between a small and a large business is how much of it you automate, not which parts you need.
| Component | What good looks like | How to measure it |
|---|---|---|
| 1. Baseline | A starting point for risk, before training begins | Baseline click rate and gap list |
| 2. Onboarding | New starters enrolled automatically in their first days | Share of new starters trained on time |
| 3. Regular training | Short, story-based lessons on a steady cadence | Completion and quiz scores |
| 4. Phishing simulation | Varied, realistic campaigns all year | Click rate and report rate |
| 5. Remediation | Failed simulation leads to a short follow-up course | Repeat-failure rate |
| 6. Reporting | Per-learner and trend reporting for leadership | Human Risk Score trend |
1. Start with a baseline
You cannot show progress without a starting point. KnowBe4's 2026 Phishing by Industry Benchmarking Report puts the global average baseline at 33.2% of employees likely to engage with a phishing email before training. Your own number may be higher or lower, and it is the one that matters. A security gap assessment also shows which controls beyond training need attention first.
2. Automate onboarding
Training that depends on someone remembering to enrol people will lapse. Cyber Aware's awareness training picks up new starters through Microsoft 365 or Google Workspace sync, CSV upload or signup links, sends a welcome email and removes leavers cleanly.
3. Train on a steady cadence
Short, story-based lessons on a monthly rhythm beat a long annual session. Cyber Aware's library has 120+ animated, story-driven videos that dramatise real cyber events, each followed by a quiz to check comprehension. Topics should cover phishing, credentials, data handling and how to report an incident.
4. Run phishing simulations all year
Simulations test what people do, not what they say they know. A good library has varied scenarios and difficulty levels. Cyber Aware's phishing simulations offer 100+ templates and report who clicked and who reported, with no credential harvesting.
5. Turn failures into lessons
Anyone who clicks should be enrolled in a short follow-up course automatically, with no awkward email. Anyone who does not click can get a congratulations note and the same explainer. That keeps the programme positive rather than punitive.
6. Report on results
Leadership needs a view that does not require reading raw logs. Human Risk Reporting rolls overdue courses and failed quizzes into a Human Risk Score per learner, tracks it over time and exports branded PDFs.
What mistakes make awareness programs fail?
- Training once a year. The Verizon 2025 DBIR still finds the human element in about 60% of breaches (Verizon 2025 DBIR).
- No remediation. A failed simulation with no follow-up teaches nothing.
- Manual enrolment. New starters slip through the cracks.
- No evidence trail. Without logs you cannot answer an insurer or auditor.
- Punishing clicks. Staff stop reporting if mistakes are punished.
Is a cyber security awareness program mandatory in Australia?
It depends on your sector and contracts rather than a single blanket rule. The detail is in our guide on whether cyber security awareness training is mandatory in Australia, linked below.
FAQ
What should a cyber security awareness program include? A baseline, automatic onboarding, regular short training, phishing simulations, automatic remediation and reporting. These six parts cover knowledge, behaviour and evidence.
How long does it take to set up an awareness program? The time depends on how much you automate. Directory sync for enrolment and a scheduled year of phishing campaigns remove most of the manual setup.
What topics should awareness training cover? Phishing, credential hygiene, data handling and incident reporting at a minimum, with extra scenarios for roles that handle payments.
How do you measure an awareness program? Track click rate, report rate and completion over time, plus a per-learner risk score.
Do small businesses need all six parts? Yes, but they can run them with automation rather than a dedicated security team.
One last thing
Pick the measure before you launch. Decide up front that you will report click rate, report rate and completion each quarter. Programs with a defined scorecard get funded again, while programs without one get cut.