"We do a security training session every year" is one of the most common answers we hear from business owners - and it's also one of the clearest signs that a training program isn't actually changing behaviour. Once-a-year training tends to be forgotten within weeks. Here's what works better.
Why Annual Training Isn't Enough
A single annual session - often a long video or slide deck staff click through once a year - tends to produce a short-term bump in awareness that fades quickly. Attackers, meanwhile, don't operate on an annual cycle. Phishing tactics evolve constantly, and new staff join throughout the year without any security grounding until the next scheduled session.
The result is a gap between "technically completed training" and staff actually recognising and responding correctly to a suspicious email when it lands in their inbox.
A More Effective Cadence
Rather than one big annual event, an effective program layers training across the year:
- At onboarding - every new starter gets a security briefing in their first week, covering the basics: recognising phishing, reporting suspicious activity, and password/MFA hygiene.
- Monthly or quarterly micro-training - short, focused sessions (5–10 minutes) on a single topic, rather than a long annual session covering everything at once.
- Ongoing phishing simulations - realistic test emails sent periodically throughout the year, with immediate feedback for anyone who clicks.
- An annual refresh - a broader session covering the fundamentals plus anything that's changed over the past year.
This kind of cadence keeps security "front of mind" without becoming a burden - most micro-training sessions take less time than a single annual session, just spread out.
What Should Be Covered
Topics worth rotating through over the course of a year typically include:
- Recognising phishing and business email compromise attempts
- Safe handling of attachments and links
- Password and MFA best practice
- Recognising and reporting unusual account activity
- Handling requests for payments, gift cards, or sensitive information - especially those that seem to come from management
- Safe use of personal devices and remote working practices
Measuring Whether It's Working
The most useful measure isn't whether staff completed a training module - it's whether their behaviour changes over time. Phishing simulation results are a good proxy: a declining click-through rate and an increasing report rate over successive simulations is a strong signal that training is having a real effect.
For businesses tracking compliance against frameworks like the Essential Eight or preparing for cyber insurance renewals, this kind of reporting also provides useful evidence that staff training is an ongoing, managed process - not a one-off tick-box exercise.
Building a Sustainable Program
The key to making any of this stick is sustainability. A program that requires significant manual effort each month tends to fall away once things get busy. The most effective programs are largely automated - scheduled simulations, short training modules delivered automatically, and reporting that surfaces who needs follow-up - so the cadence keeps running even when nobody's actively thinking about it.
Frequently Asked Questions
Is once-a-year security training really not enough?
On its own, generally not. A single annual session tends to produce a short-term bump in awareness that fades within weeks, while attackers and their tactics keep changing all year round. Layering in short, regular sessions and periodic phishing simulations tends to keep staff genuinely alert rather than just ticking a box once a year.
How long should ongoing training sessions actually take?
Short is the point, most effective micro-training sessions run five to ten minutes and focus on a single topic, rather than trying to cover everything at once. Spread across the year, this usually adds up to less total time than one long annual session, while keeping security front of mind more consistently.
What's a phishing simulation and is it worth doing?
It's a realistic but harmless test email sent to staff to see how they respond, with immediate feedback for anyone who clicks. It's a genuinely useful way to measure whether training is actually changing behaviour, since a falling click-through rate and a rising report rate over time is a much stronger signal than simply confirming people watched a training video.
Do new starters need security training before their official onboarding session?
Ideally yes, a basic security briefing covering phishing, reporting suspicious activity, and password or MFA habits should happen in a new starter's first week rather than waiting for the next scheduled companywide session. New staff without any security grounding are a common gap attackers can exploit in the meantime.
We run ongoing security awareness training and phishing simulations for Perth businesses - built to run year-round, not just once a year.
Security Awareness Training →Still running annual-only training?
Call 0433 087 091 for a free, no-obligation conversation about building a year-round training program for your team.
Book a Free ConsultationFor related reading, see our guides to Phishing & Staff Security Training for Perth Businesses and What an IT Security Audit Covers.