Skip to main content
Service

Security awareness training that treats staff as a control, not a liability

Short, frequent, and about attacks actually reaching Australian businesses — with simulated phishing used to find gaps rather than to embarrass people.

16+ years

Brisbane-based since 2010

1,500+

Employees supported across SEQ

Named engineers

The same team every time

Essential Eight aligned

Microsoft Partner

Ongoing security awareness training and phishing simulation — short monthly modules on current Australian attack patterns, measured by improvement rather than blame.

The last control in the chain

Every technical control has a residue. Filtering will not catch a well-written message sent from a genuinely compromised supplier mailbox, because there is nothing technically wrong with it. MFA will not help if someone approves the prompt. At that point the control is a person deciding whether something looks right.

Which is why “the human is the weakest link” is an unhelpful framing. The human is the last control, and controls can be improved.

What is wrong with how it is usually done

Annual training. Ninety minutes once a year, clicked through at speed while doing something else, retained for approximately a fortnight. It exists to satisfy a compliance requirement rather than to change behaviour, and it does exactly that.

Generic content. American examples about wire transfers and gift cards. The attacks actually reaching Australian businesses are ATO and myGov impersonation, invoice redirection against real supplier relationships, Microsoft 365 credential harvesting pages, and text messages about undelivered parcels.

Punitive simulation. Deliberately difficult tests designed to produce a high click rate, followed by naming and shaming. The lesson staff learn is that engaging with IT about security goes badly, so they stop reporting — and losing your reporting channel costs far more than the click rate gains.

What we do instead

Short modules, monthly, on things currently happening. A few minutes each, tracked for completion.

Simulated phishing at realistic difficulty, run periodically. Anyone who clicks lands on a brief page explaining what the tells were. No manager notification, no list circulated.

Role-specific content for the groups actually targeted: finance staff on invoice and payment redirection, executives on impersonation, administrators on credential attacks.

The metric that matters

Click rate is the number everyone asks for and it is the less useful one. The number that predicts how an incident goes is report rate and report speed.

An organisation where someone forwards a suspicious email within four minutes has a chance to invalidate sessions, reset credentials and warn everyone else before the payment is made. An organisation with a low click rate and no reporting culture finds out three weeks later from the bank.

So we make reporting trivially easy, and we make sure it has never gone badly for anyone who did it — including the people who report something after clicking it, which is the single most valuable report there is.

Where it fits

Training does not substitute for email security or MFA — it covers what those cannot. A business relying primarily on staff vigilance has the layers in the wrong order.

Sitting behind properly configured technical controls, though, awareness training is what turns the small number of attacks that get through from incidents into reports.

What you get with JTIT

Concrete deliverables, not vague promises.

Short and frequent beats annual

A few minutes monthly retains far better than a ninety-minute session once a year that everyone clicks through while doing something else.

Australian attacks, not generic examples

Content covering what is actually landing here — myGov and ATO impersonation, invoice redirection, Microsoft 365 credential pages, supplier compromise.

Simulation used diagnostically

Phishing tests identify where training is needed. People who click get a short lesson, not a disciplinary conversation. Punishment stops reporting.

Reporting made easy and safe

The measure that matters most is how quickly a real phish gets reported. Staff report readily when doing so has never gone badly for anyone.

Finance and executives get extra

The people who can authorise payments face targeted attacks that general training does not cover. They get specific content on invoice fraud and impersonation.

Evidence for insurers and tenders

Completion rates, simulation results and improvement over time, documented — which is increasingly asked for on insurance applications.

How it works

A predictable, no-surprises process.

  1. 01

    Baseline

    An initial simulation to establish where you actually are. Almost every organisation is surprised, in both directions.

  2. 02

    Enrol and run monthly

    Short modules delivered on a monthly cadence, tracked for completion, with content matched to the roles being targeted.

  3. 03

    Simulate and coach

    Periodic simulated phishing at realistic difficulty. Anyone who clicks gets immediate, brief, non-punitive coaching on what the tells were.

  4. 04

    Measure what matters

    Click rate matters less than report rate and report speed. Both tracked and reported, so you can see the trend rather than one month's number.

Frequently asked questions

Does security awareness training actually work?

Measurably, yes, provided it is continuous and the measurement is right. Click rates fall with sustained training. But the more important metric is reporting: an organisation where staff report suspicious email within minutes detects real incidents dramatically faster than one where nobody says anything. That behaviour is trainable and it is what we optimise for. Annual compliance training, on the other hand, has very little evidence behind it.

Isn't phishing simulation just entrapment?

It can be, and done that way it is counterproductive. If simulations are designed to maximise click rate and results are used to shame people, staff learn to distrust IT and stop reporting real incidents — which makes you less safe. We run simulations at realistic difficulty and use the results diagnostically. Anyone who clicks gets a two-minute explanation of the tells, not a meeting with their manager.

How much staff time does it take?

A few minutes a month per person. That is deliberate: retention from short frequent exposure is substantially better than from a long annual session, and it is much easier to get genuine engagement with something that takes less time than making a coffee.

Our staff are not technical. Will they cope?

The content is not technical, because the attacks are not technical. Recognising urgency pressure, checking whether a request to change bank details arrived through the usual channel, and noticing that a familiar display name is attached to an unfamiliar address are judgement skills, not IT skills. Non-technical staff generally do well at this once they know what to look for.

Who should be trained?

Everyone with an email address, and then extra for the people who are actually targeted. Finance and accounts staff face invoice redirection attempts specifically. Executives face impersonation, both as targets and as the impersonated party. Anyone with administrative access is a high-value target. General training plus role-specific content for those three groups covers the realistic threat.

Related services

Most clients combine a few of these — we'll help you decide what's right for your size and risk profile.

Ready to talk?

A 30-minute consultation with an engineer, not a salesperson. You'll get an honest read on whether we're a fit.

Call Get a quote