Add Think Technology as a trusted source Security awareness training that changes behaviour | TTA

How to make security awareness training actually stick

Graphic about security awareness training

A Brisbane accounting firm we work with ticked the annual security training box every year for five years. Staff watched the same slideshow, clicked through the quiz, and moved on. Then a phishing email landed in a senior partner’s inbox on a Tuesday afternoon. She clicked it. The attacker was inside the network within the hour.

The training had happened. The behaviour had not changed. That gap is the real problem with most security awareness programsand it is more common than most business owners realise.

Why most security training fails to change behaviour

Verizon’s 2025 Data Breach Investigations Report found that 60% of breaches involve a human element, through error, social engineering, or credential abuse. That figure has held steady year after year. Technical controls have improved. Human behaviour has not kept pace. The reason is usually the training model itself.

Completion-based training, the annual module with a pass/fail quiz, tells you who sat through the content. It tells you almost nothing about whether behaviour changed. Programs focused on genuine behaviour change push threat-reporting rates above 20%, roughly double the rate seen in compliance-only programs, according to Hoxhunt’s 2026 Phishing Trends Report. The gap between a compliance program and a culture program shows up directly in how often people actually report suspicious activity.

The other problem is frequency. Security concepts fade fast when training is delivered once a year and then forgotten. Spaced repetition, short modules delivered regularly, produces significantly better retention than massed learning, which is exactly why the “annual awareness day” model keeps failing.

Story-based training and why it works

Huntress Managed SAT, formerly known as Curricula before Huntress acquired the platform in 2022, takes a different approach. Instead of dry slideshows, it uses short story-based episodes with recurring characters and real-world scenarios. The content is built around adult learning principles and designed to make concepts memorable, not just passable.

The storytelling format matters because people remember narratives better than facts. A staff member who watched a five-minute episode about a fictional receptionist getting socially engineered over the phone is more likely to pause and question a suspicious caller than someone who read three bullet points about vishing in a PDF. The scenario is concrete. The lesson is attached to a story. It sticks.

Huntress’s security researchers also update content based on the current threat landscape, so training reflects what is actually targeting Australian businesses right now, not what was relevant two years ago. That includes phishing, business email compromise, and increasingly, AI-generated deepfake attacks.

What Huntress Managed SAT includes

The platform is built for businesses that do not have a dedicated security team to manage training administration. Key features include:

  • Short, story-based training episodes updated by Huntress security researchers.
  • Phishing simulations to test awareness, with coaching for staff who click.
  • Role-based and group content delivery, so staff receive relevant scenarios.
  • Phishing Defence Coaching, which turns a clicked simulation into a personalised learning moment rather than a reprimand.
  • Compliance-aligned reporting for frameworks including ISO 27001, PCI DSS, and the ACSC Essential Eight.
  • Integrations with Microsoft 365, Google Workspace, and leading LMS platforms.
  • Managed Learning, where Huntress researchers assign monthly content based on current threats, so your team is always training on what matters.

For a small or mid-sized business, the managed approach means you get a running program without hiring someone to maintain it.

Where phishing simulations fit in

Simulations are the practical test of whether training is working. Huntress runs simulated phishing campaigns against your own staff, measures who clicks, and then delivers immediate, constructive coaching to those who do. The aim is not to name and shame, but to turn the moment of vulnerability into a learning opportunity.

KnowBe4’s 2025 Phishing by Industry Benchmarking Report found that twelve months of continuous training cut the global phish-prone rate by 86%, dropping organisations from a 33% baseline to around 4%. That kind of result only happens when training is ongoing, not annual. Simulations are what keep the training honest, because they measure actual behaviour, not just whether someone watched a video.

For professional services firms like law firms, accountants, and financial advisers, this matters especially. These businesses hold sensitive client data, handle large financial transactions, and are specifically targeted by business email compromise attacks. A strong phishing simulation program is one of the most cost-effective defences available.

How this fits your compliance obligations

Security awareness training is not just good practice for Australian businesses. It sits inside formal compliance frameworks. The ACSC Essential Eight includes user training as a supporting control. ISO 27001 requires documented awareness programs. Cyber insurers increasingly ask for evidence of regular staff training before offering cover or processing a claim.

Huntress Managed SAT produces the completion records and reporting your business needs to satisfy auditors and insurers. That means less scrambling at audit time, and a clearer picture of where your human risk actually sits.

TTA delivers Huntress Managed SAT as part of our managed IT service. You get the training program, the phishing simulations, and the reporting, all managed by us so your team can focus on the business. You can also read the Huntress case study on how TTA uses the platform for our own clients.

Signs your current training is not working

A quick check to see if your program is actually building a security culture:

  • Training happens once a year and staff forget it within weeks.
  • Nobody reports suspicious emails because they are not sure of the process.
  • You have no data on whether staff behaviour has improved since training started.
  • The same staff members fail phishing simulations each time, with no follow-up.
  • Your training content has not been updated to reflect AI-generated phishing and deepfakes.

If two or more of those are true, the program is running but it is not working. The fix is usually not more training hours. It is a change in how training is delivered and measured.

Frequently asked questions

How often should security awareness training run?

Security awareness training should run continuously, not annually. Short monthly episodes combined with regular phishing simulations produce significantly better behaviour change than a once-a-year module. Spaced repetition is the reason: people retain concepts better when they encounter them repeatedly over time, rather than in a single sitting they quickly forget.

What is the difference between compliance training and behaviour-change training?

Compliance training satisfies an audit requirement. It records who completed a module. Behaviour-change training measures whether staff actually respond differently to threats. Programs focused on genuine behaviour change produce phishing-report rates roughly double those of compliance-only programs, according to Hoxhunt’s 2026 data. Both matter, but compliance training alone does not reduce your breach risk.

Does security training count toward Essential Eight or ISO 27001 compliance?

Yes, in both cases. The ACSC Essential Eight includes staff awareness as a supporting control, and ISO 27001 requires documented security awareness programs. Huntress Managed SAT produces completion records and reporting you can present to auditors and cyber insurers. It does not replace other Essential Eight controls, but it supports your overall compliance posture.

What happens when a staff member clicks a simulated phishing email?

With Huntress Managed SAT, a clicked simulation triggers Phishing Defence Coaching, a personalised, just-in-time lesson delivered immediately after the click. The approach avoids shaming and instead uses the moment to teach. The staff member reviews the exact scenario they clicked, understands why it was convincing, and learns what to look for next time. This makes the lapse a learning event rather than a disciplinary one.

Is this suitable for a small Brisbane business with under 50 staff?

Yes. Huntress Managed SAT is built for small and mid-sized businesses. The Managed Learning option means Huntress researchers assign monthly content for you, removing the admin burden. TTA deploys and manages the platform on your behalf, so you do not need an internal security team to run the program. It is a practical option for businesses of 10 to 100 users across South-East Queensland.

How do we get started?

A good first step is understanding where your current security posture sits. A security assessment gives you a clear baseline before rolling out training. Or get in touch and we can walk you through how Huntress Managed SAT works for businesses like yours.

Get tech tips

Stay up-to-date with the latest in tech for small and medium business.
Subscribe to our newsletter and get tips and monthly updates.