Straight answers to the questions people actually search about security awareness training and phishing simulations. Each one leads with the answer and links its sources.
For most employees, a foundation security awareness course takes 20 to 45 minutes, completed once. After that, effective programmes run short refreshers of 5 to 10 minutes a month rather than repeating a long annual session. Phishing simulations take seconds unless someone clicks, which triggers a few minutes of follow-up coaching. A realistic all-in figure is one to two hours per employee per year.
Security awareness training is an administrative control, sometimes called a managerial or operational control, because it works through people and policy rather than technology. Its primary function is preventive: it reduces the chance of a successful attack before one happens. It also builds a detective capability, because trained staff who report suspicious emails become sensors for attacks already in progress.
There is no single Australian law that makes security awareness training mandatory for every business. In practice it is effectively required for many: APRA-regulated entities must maintain information security capability under CPS 234, and the Privacy Act's requirement to take reasonable steps to protect personal information is read by the OAIC as including staff training. Cyber insurers and government supply chains increasingly demand it too.
A failed phishing test should trigger coaching, not discipline. Best practice is a short lesson served immediately after the click, while the context is fresh, followed by inclusion in the next campaign to confirm the lesson landed. Punishing clickers reliably backfires: it drives down reporting of real incidents, because staff who fear consequences stop putting their hand up when they make a genuine mistake.
Yes, always. Reporting a simulated phishing email is the correct outcome, not a spoiled test. The report exercises exactly the behaviour that catches real attacks, and a rising report rate is the single healthiest metric a security awareness programme can show. Good platforms count a report as a win even when the same person clicked first, because reporting after a mistake is precisely what you want in a real incident.
The Anti-Phishing Working Group logged almost five million unique phishing attacks in 2023, its worst year on record, which averages more than 13,000 distinct attacks per day. That counts campaigns and sites, not messages: the raw volume of phishing emails sent daily is orders of magnitude higher, with industry estimates running into the billions. The direction matters more than the decimal: volume keeps climbing as AI makes convincing lures cheaper to produce.
Phishing is effective because it attacks routines rather than software. A well-made phish borrows authority from a boss or a brand, urgency from a deadline and familiarity from workflows people action every day, then arrives inside the tools they trust. It costs attackers almost nothing to send at scale, and a single click is enough. Defences that assume people will simply spot bad spelling misunderstand what modern phishing looks like.
Looking for answers about the platform itself, plans, trials and billing? Those live on the product FAQ.
Sign up and start training your team in minutes. No sales calls, no demos — just pick a plan and go. Phishing simulations, video courses, and certificates from day one.
