What should a cyber security awareness program include?

A cyber security awareness program needs six parts: baseline, onboarding, regular training, phishing simulations, remediation and reporting. The 2026 checklist.

A cyber security awareness program should include six parts: a baseline assessment, automatic onboarding, regular short training, phishing simulations, automatic remediation and reporting that proves progress. Programs that stop at a once-a-year video miss the parts that change behaviour.

TL;DR

What should a cyber security awareness program include in 2026?

The six components below work for any size of organisation. The difference between a small and a large business is how much of it you automate, not which parts you need.

ComponentWhat good looks likeHow to measure it
1. BaselineA starting point for risk, before training beginsBaseline click rate and gap list
2. OnboardingNew starters enrolled automatically in their first daysShare of new starters trained on time
3. Regular trainingShort, story-based lessons on a steady cadenceCompletion and quiz scores
4. Phishing simulationVaried, realistic campaigns all yearClick rate and report rate
5. RemediationFailed simulation leads to a short follow-up courseRepeat-failure rate
6. ReportingPer-learner and trend reporting for leadershipHuman Risk Score trend

1. Start with a baseline

You cannot show progress without a starting point. KnowBe4's 2026 Phishing by Industry Benchmarking Report puts the global average baseline at 33.2% of employees likely to engage with a phishing email before training. Your own number may be higher or lower, and it is the one that matters. A security gap assessment also shows which controls beyond training need attention first.

2. Automate onboarding

Training that depends on someone remembering to enrol people will lapse. Cyber Aware's awareness training picks up new starters through Microsoft 365 or Google Workspace sync, CSV upload or signup links, sends a welcome email and removes leavers cleanly.

3. Train on a steady cadence

Short, story-based lessons on a monthly rhythm beat a long annual session. Cyber Aware's library has 120+ animated, story-driven videos that dramatise real cyber events, each followed by a quiz to check comprehension. Topics should cover phishing, credentials, data handling and how to report an incident.

4. Run phishing simulations all year

Simulations test what people do, not what they say they know. A good library has varied scenarios and difficulty levels. Cyber Aware's phishing simulations offer 100+ templates and report who clicked and who reported, with no credential harvesting.

5. Turn failures into lessons

Anyone who clicks should be enrolled in a short follow-up course automatically, with no awkward email. Anyone who does not click can get a congratulations note and the same explainer. That keeps the programme positive rather than punitive.

6. Report on results

Leadership needs a view that does not require reading raw logs. Human Risk Reporting rolls overdue courses and failed quizzes into a Human Risk Score per learner, tracks it over time and exports branded PDFs.

What mistakes make awareness programs fail?

Is a cyber security awareness program mandatory in Australia?

It depends on your sector and contracts rather than a single blanket rule. The detail is in our guide on whether cyber security awareness training is mandatory in Australia, linked below.

FAQ

What should a cyber security awareness program include? A baseline, automatic onboarding, regular short training, phishing simulations, automatic remediation and reporting. These six parts cover knowledge, behaviour and evidence.

How long does it take to set up an awareness program? The time depends on how much you automate. Directory sync for enrolment and a scheduled year of phishing campaigns remove most of the manual setup.

What topics should awareness training cover? Phishing, credential hygiene, data handling and incident reporting at a minimum, with extra scenarios for roles that handle payments.

How do you measure an awareness program? Track click rate, report rate and completion over time, plus a per-learner risk score.

Do small businesses need all six parts? Yes, but they can run them with automation rather than a dedicated security team.

One last thing

Pick the measure before you launch. Decide up front that you will report click rate, report rate and completion each quarter. Programs with a defined scorecard get funded again, while programs without one get cut.

Related guides

Ready to deploy

Same playbook.
Your brand.

Cyber Aware's Human Risk Score works the same way for every MSP partner - under your brand, on your cadence.