Most breaches start with someone clicking something, not with a firewall failing. We run controlled phishing simulations against your team, then turn the results into short, practical training that speaks to what actually happened, rather than a generic annual video nobody remembers.
You get a clear baseline, repeat testing to show whether it is improving, and reporting you can take to your board, insurer, or auditor.
Why the annual video does not work
Nearly every business has done security awareness training. Very few have changed anybody’s behaviour with it.
The reason is structural rather than a failure of content. Training delivered once a year, covering everything, in the abstract, competes for attention with the actual job and loses. By the time a convincing invoice arrives in March, July’s module has gone. And because the training was generic, it never resembled the thing that eventually turns up.
Short, frequent, and specific works considerably better. Ten minutes, immediately after a simulation that caught you, about the exact technique that caught you, is worth more than an hour in a room in a way that is easy to demonstrate and hard to argue with.
What the simulations look like
Scenarios are built to resemble what actually targets Australian businesses: invoice and payment redirection attempts, a Microsoft 365 login prompt, a message that appears to come from a manager, a delivery notice, a shared document. We vary difficulty deliberately, because a programme where every test is obvious measures nothing and one where every test is expert-level teaches only despair.
We agree the scope with leadership first, including which techniques are off limits. Some scenarios are effective and inappropriate: we do not use fake redundancy notices, bonus announcements, or anything touching somebody’s health or family. A test that damages trust in the business costs more than it measures.
Report rate is the number to watch
Click rate is the figure everybody asks about first, and it is the less useful of the two.
An attacker only needs one person to click, so driving click rate to zero is not a realistic target. What actually changes outcomes is how fast you find out. A business where someone clicks and reports it within a minute can reset a password and end the incident. A business where somebody clicks and says nothing finds out weeks later from a customer.
So we measure and report both, and we deliberately make reporting easy and socially safe. The goal is a team where telling somebody is the reflex, not one where nobody ever fails a test.
What you can show somebody
Each cycle produces reporting designed to be handed over: participation, click rate, report rate, time to first report, and the trend across rounds.
That is the evidence an insurer asks for at renewal, the answer to the staff training question on a client security questionnaire, and something concrete to put in front of a board that has been told human risk is the biggest exposure and would like to know what is being done about it.