The five building blocks
Programme structure
- Baseline annual module. Phishing, passwords/MFA, data classification, incident reporting, AI acceptable use — under 30 minutes total.
- Role-targeted modules. Finance (BEC), developers (secure code), executive assistants (impersonation), customer support (social engineering).
- Phishing simulations. Monthly with realistic scenarios, immediate just-in-time coaching for clickers, recognition for reporters.
- Tabletop exercises. Annual for execs, quarterly for the CIRT, ad-hoc after material industry incidents.
- Communications cadence. Monthly security newsletter, post-incident learnings published internally, recognition for security-positive behaviour.
Metrics that move the needle
- Report rate — proportion of simulated phishing emails reported (target: rising quarter on quarter).
- Click rate — proportion clicked (target: declining; treat this as a quality, not quantity metric).
- Repeat clickers — staff who click in three consecutive months get targeted coaching.
- Time-to-report — median minutes from inbox arrival to security reporting.
- Policy violation incidents — declining trend in shadow IT, data exfil, AI policy breaches.
Australian-specific content to include
- Notifiable Data Breach scheme and what employees should do if they suspect a breach
- SOCI / APRA / ASIC obligations as relevant to your sector
- Privacy Act reform — particularly the new doxxing offences and statutory tort
- AI acceptable use including the prohibited and high-risk use cases for your organisation
FOR SECURITY LEADS
Generate your security awareness programme charter in one mission.
FORTE/CYBERx produces a defensible 12-month security awareness programme — modules, cadence, metrics and board reporting — anchored to ISO 27001 and CPS 234.
Start a free missionFAQ
Is security awareness training mandatory in Australia?
It is required by ISO 27001:2022 (clause 7.3 and Annex A 6.3), APRA CPS 234, the SOCI CIRMP rules and most cyber insurance policies. The detail of what counts as "adequate" is yours to define and defend.
How often should we train staff?
Annual baseline plus role-targeted micro-modules quarterly for high-risk groups (finance, executive assistants, developers, customer support). Phishing simulations monthly with declining frequency as performance improves.
How do we measure effectiveness?
Beyond completion rates: phishing click rates by team, report rates (more important than click rates), policy-violation incident rates, and a survey-based culture index. Trend over time matters more than point-in-time.
Do we have to buy a platform?
No, but most mid-market organisations do because content production and reporting are the real cost. Whether you build or buy, the programme is more important than the platform.