Security awareness training should include phishing and social engineering, passwords and multi-factor authentication (MFA), business email compromise and invoice fraud, safe browsing and device hygiene, and a clear incident-reporting routine — delivered as short monthly lessons with phishing simulations in between, not one annual course. Those six modules are the 2026 baseline for Australian small businesses; the sections below cover what each one teaches and how often to run it.
What should security awareness training include?
Six modules appear in virtually every effective programme:
| Module | What staff learn | What it protects |
|---|---|---|
| Phishing and social engineering | Spotting fraudulent emails, texts and calls; verifying senders | The entry point for most breaches |
| Business email compromise | Invoice and payment-redirection fraud, executive impersonation | Money leaving the business |
| Passwords and MFA | Passphrases, password managers, careful MFA approvals | Account takeover |
| Safe browsing and downloads | Fake login pages, malicious attachments, risky software sources | Malware and credential theft |
| Device and remote-work hygiene | Locking screens, home Wi-Fi, public networks, lost devices | Data on laptops and phones |
| Incident reporting | How and when to report, and why speed beats certainty | Damage limitation |
A programme built from these six modules answers the question insurers, auditors and the Essential Eight's user-education strategy all ask: can staff recognise an attack and report it? Cyber Aware's security awareness training maps its modules to that standard, which matters when you need evidence rather than attendance sheets.
Phishing and social engineering: the module that comes first
Phishing is where attacks start, so the module comes first and returns every month. Industry benchmark studies report roughly one in three untrained staff clicking a simulated phishing email, falling below 5% after a year of monthly training. The lesson should teach:
- The sender check. Does the domain match the real one, character by character? Most spoofed senders fail a three-second look.
- The lures that work in 2026. Fake shared documents, unexpected MFA prompts, invoice reminders and urgent messages that appear to come from a manager.
- The same psychology by other channels. Smishing (text) and vishing (voice) attacks reuse the identical urgency tricks.
- The right response. Report through the reporting button or the agreed channel — never forward the suspicious email on.
Pair the lesson with phishing simulations a few days later. The click is the rehearsal; the report is the skill you are actually building.
Business email compromise and invoice fraud
BEC is where awareness training pays for itself, because the attack needs no malware — just a convincing email. Staff should learn:
- Payment details never change over email alone. A supplier's new bank details are verified by phone, using a number you already had, not one from the email.
- Urgency plus secrecy is the pattern. Every payment-fraud email presses both buttons: act now, tell no one.
- Executive impersonation exploits deference. A text from the boss at 6pm on a Friday asking for a quick payment is a test, not a request.
Passwords, MFA and account security
Reused passwords turn one breach into ten. The module covers passphrases over complexity, a password manager for work accounts, and MFA approvals treated like signatures: never approve a prompt you did not trigger. A two-minute exercise that makes the risk personal is checking your own email address at Have I Been Pwned, which shows whether it has appeared in a known data breach.
Reporting: the habit that limits the damage
Every module ends the same way: report it. A false alarm costs minutes; a silent click can cost the average Australian small business $56,600 (2024-25 figures used across Cyber Aware's breach-cost guidance). The routine to teach is short — report anything odd, immediately, even when you are not sure, and never worry about being wrong. Speed beats certainty every time.
How the modules should be delivered
- Short monthly lessons. Five to ten minutes a month beats one long annual course; attention, not content, is the constraint.
- Monthly simulations, varied by lure and difficulty, so recognition is practised rather than recalled.
- Role-based extras. Finance teams get invoice-fraud deep dives, front desk staff get phone-scam scripts, executives get impersonation drills.
- Measure what matters. Click rate trending down and report rate trending up, tracked through human risk reporting — that is the evidence insurers and clients ask for.
How often should each module run?
| Module | Cadence |
|---|---|
| Phishing | Monthly lesson plus monthly simulation |
| Business email compromise | Quarterly, with a payment-fraud simulation each quarter |
| Passwords and MFA | Twice-yearly refresher |
| Browsing and device hygiene | Twice-yearly refresher |
| Incident reporting | Rehearsed in every simulation |
FAQ
How long should security awareness training take per employee? About five to ten minutes a month, which keeps a 20-person team under two hours of training per person per year — small enough to complete, frequent enough to stick.
Is a single annual training session enough? No. Memory decays within weeks and attack tactics change monthly; an annual course produces a compliance record, not a change in behaviour.
What topics matter most for small businesses? Phishing and invoice fraud. Most small-business incidents start with an email someone clicked or a payment redirected on convincing instructions.
Should training be different for different roles? Yes. Finance staff face payment redirection, reception faces phone scams, executives face impersonation — the generic course misses all three.
Does training need to cover privacy and compliance? A short data-handling module aligned to the Privacy Act rounds out the programme, but it should not crowd out the phishing and fraud content where the actual risk sits.
How do you prove the training worked? Click rate falling and report rate rising over 90 days, per person. That pair of numbers is the evidence pack insurers and auditors ask to see.
Can training replace technical controls? No. MFA, tested backups and patching do the heavy lifting; training covers the attacks that arrive despite them.