Ongoing security awareness training and phishing simulation — short monthly modules on current Australian attack patterns, measured by improvement rather than blame.
The last control in the chain
Every technical control has a residue. Filtering will not catch a well-written message sent from a genuinely compromised supplier mailbox, because there is nothing technically wrong with it. MFA will not help if someone approves the prompt. At that point the control is a person deciding whether something looks right.
Which is why “the human is the weakest link” is an unhelpful framing. The human is the last control, and controls can be improved.
What is wrong with how it is usually done
Annual training. Ninety minutes once a year, clicked through at speed while doing something else, retained for approximately a fortnight. It exists to satisfy a compliance requirement rather than to change behaviour, and it does exactly that.
Generic content. American examples about wire transfers and gift cards. The attacks actually reaching Australian businesses are ATO and myGov impersonation, invoice redirection against real supplier relationships, Microsoft 365 credential harvesting pages, and text messages about undelivered parcels.
Punitive simulation. Deliberately difficult tests designed to produce a high click rate, followed by naming and shaming. The lesson staff learn is that engaging with IT about security goes badly, so they stop reporting — and losing your reporting channel costs far more than the click rate gains.
What we do instead
Short modules, monthly, on things currently happening. A few minutes each, tracked for completion.
Simulated phishing at realistic difficulty, run periodically. Anyone who clicks lands on a brief page explaining what the tells were. No manager notification, no list circulated.
Role-specific content for the groups actually targeted: finance staff on invoice and payment redirection, executives on impersonation, administrators on credential attacks.
The metric that matters
Click rate is the number everyone asks for and it is the less useful one. The number that predicts how an incident goes is report rate and report speed.
An organisation where someone forwards a suspicious email within four minutes has a chance to invalidate sessions, reset credentials and warn everyone else before the payment is made. An organisation with a low click rate and no reporting culture finds out three weeks later from the bank.
So we make reporting trivially easy, and we make sure it has never gone badly for anyone who did it — including the people who report something after clicking it, which is the single most valuable report there is.
Where it fits
Training does not substitute for email security or MFA — it covers what those cannot. A business relying primarily on staff vigilance has the layers in the wrong order.
Sitting behind properly configured technical controls, though, awareness training is what turns the small number of attacks that get through from incidents into reports.