What should security awareness training include?

Security awareness training should include phishing, MFA, invoice fraud, device hygiene and reporting — six modules, monthly cadence. The 2026 checklist inside.

Security awareness training should include phishing and social engineering, passwords and multi-factor authentication (MFA), business email compromise and invoice fraud, safe browsing and device hygiene, and a clear incident-reporting routine — delivered as short monthly lessons with phishing simulations in between, not one annual course. Those six modules are the 2026 baseline for Australian small businesses; the sections below cover what each one teaches and how often to run it.

What should security awareness training include?

Six modules appear in virtually every effective programme:

ModuleWhat staff learnWhat it protects
Phishing and social engineeringSpotting fraudulent emails, texts and calls; verifying sendersThe entry point for most breaches
Business email compromiseInvoice and payment-redirection fraud, executive impersonationMoney leaving the business
Passwords and MFAPassphrases, password managers, careful MFA approvalsAccount takeover
Safe browsing and downloadsFake login pages, malicious attachments, risky software sourcesMalware and credential theft
Device and remote-work hygieneLocking screens, home Wi-Fi, public networks, lost devicesData on laptops and phones
Incident reportingHow and when to report, and why speed beats certaintyDamage limitation

A programme built from these six modules answers the question insurers, auditors and the Essential Eight's user-education strategy all ask: can staff recognise an attack and report it? Cyber Aware's security awareness training maps its modules to that standard, which matters when you need evidence rather than attendance sheets.

Phishing and social engineering: the module that comes first

Phishing is where attacks start, so the module comes first and returns every month. Industry benchmark studies report roughly one in three untrained staff clicking a simulated phishing email, falling below 5% after a year of monthly training. The lesson should teach:

Pair the lesson with phishing simulations a few days later. The click is the rehearsal; the report is the skill you are actually building.

Business email compromise and invoice fraud

BEC is where awareness training pays for itself, because the attack needs no malware — just a convincing email. Staff should learn:

Passwords, MFA and account security

Reused passwords turn one breach into ten. The module covers passphrases over complexity, a password manager for work accounts, and MFA approvals treated like signatures: never approve a prompt you did not trigger. A two-minute exercise that makes the risk personal is checking your own email address at Have I Been Pwned, which shows whether it has appeared in a known data breach.

Reporting: the habit that limits the damage

Every module ends the same way: report it. A false alarm costs minutes; a silent click can cost the average Australian small business $56,600 (2024-25 figures used across Cyber Aware's breach-cost guidance). The routine to teach is short — report anything odd, immediately, even when you are not sure, and never worry about being wrong. Speed beats certainty every time.

How the modules should be delivered

How often should each module run?

ModuleCadence
PhishingMonthly lesson plus monthly simulation
Business email compromiseQuarterly, with a payment-fraud simulation each quarter
Passwords and MFATwice-yearly refresher
Browsing and device hygieneTwice-yearly refresher
Incident reportingRehearsed in every simulation

FAQ

How long should security awareness training take per employee? About five to ten minutes a month, which keeps a 20-person team under two hours of training per person per year — small enough to complete, frequent enough to stick.

Is a single annual training session enough? No. Memory decays within weeks and attack tactics change monthly; an annual course produces a compliance record, not a change in behaviour.

What topics matter most for small businesses? Phishing and invoice fraud. Most small-business incidents start with an email someone clicked or a payment redirected on convincing instructions.

Should training be different for different roles? Yes. Finance staff face payment redirection, reception faces phone scams, executives face impersonation — the generic course misses all three.

Does training need to cover privacy and compliance? A short data-handling module aligned to the Privacy Act rounds out the programme, but it should not crowd out the phishing and fraud content where the actual risk sits.

How do you prove the training worked? Click rate falling and report rate rising over 90 days, per person. That pair of numbers is the evidence pack insurers and auditors ask to see.

Can training replace technical controls? No. MFA, tested backups and patching do the heavy lifting; training covers the attacks that arrive despite them.

Related guides

Ready to deploy

Same playbook.
Your brand.

Cyber Aware's Human Risk Score works the same way for every MSP partner - under your brand, on your cadence.