The Email That Nearly Cost Everything
A finance officer at a mid-sized Melbourne logistics company received what appeared to be an urgent message from her CEO. The email requested an immediate bank transfer to finalise a vendor contract. The branding looked right. The language sounded right. The sender's name was right.
She processed the transfer within the hour. The $85,000 never came back.
What happened wasn't a sophisticated hack. There was no malware, no system breach, no stolen password. A cybercriminal simply crafted a convincing email and waited. This type of attack — known as Business Email Compromise (BEC) — is now one of the most financially damaging cyber threats facing Australian businesses, and it works almost entirely through human psychology rather than technical exploits.
The uncomfortable truth is that most Australian organisations are still not doing enough to train their people to recognise these threats. That needs to change, and in many cases, the law is starting to demand it.
Why Phishing Is Australia's Most Persistent Cyber Threat
Cybercriminals are not random opportunists anymore. They are methodical, patient, and increasingly well-resourced. In 2025, phishing attacks have become one of the most persistent threats faced by Australian businesses — well-crafted and convincing attacks designed to steal login credentials, access sensitive data, and compromise entire systems.
The numbers are sobering. Companies with 1,000 or more employees in Australia and New Zealand recorded a Phish-prone Percentage (PPP) of 44.6%, the highest globally according to the 2025 Phishing Benchmarking Report. That figure means nearly half of staff at large organisations are likely to click a malicious link before training kicks in.
Human error is attributed to nearly two-thirds of reported phishing incidents in Australia, and 95% of reported data breaches worldwide begin with a phishing attempt.
There is also a well-documented local example that underscores the global scale of this threat. In 2024, engineering firm Arup forwarded $25 million to a deepfake video call impersonating its CFO — an attack that bypassed every technical control on the network. Arup is a global firm with significant resources, and they still fell victim. No business is immune when the weakest link is human behaviour.
The Australian Regulatory Landscape: What Employers Are Required to Do
The Privacy Act 1988 and the Notifiable Data Breaches Scheme
For most Australian organisations, the foundation of their privacy and data security obligations sits inside the Privacy Act 1988. Overseen by the Office of the Australian Information Commissioner (OAIC), this legislation requires organisations to take "reasonable steps" to protect the personal information they hold.
The Notifiable Data Breaches (NDB) Scheme, which operates under the Privacy Act, requires organisations to notify affected individuals and the OAIC when a data breach is likely to result in serious harm. Phishing attacks are among the most common triggers for these notifications.
In 2025, Australian cybersecurity regulations are more stringent than ever, with laws requiring businesses to report breaches and take proactive steps to secure sensitive data. The NDB Scheme continues to guide businesses on best practices for cybersecurity, and failure to comply can result in fines and long-lasting reputational damage.
The Privacy Act 1988 was also significantly strengthened through reforms legislated in November 2024, covering enhanced regulator powers and penalties, a statutory tort for privacy, and new transparency requirements around the use of automated decision-making tools. These changes mean the OAIC now has sharper tools to investigate organisations that fail to protect personal data — and employees who have not been trained to recognise phishing are a foreseeable vulnerability.
The Cyber Security Act 2024
Australia now has standalone cyber security legislation for the first time in the form of the Cyber Security Act 2024. One key component is a requirement to report to the Department of Home Affairs and the Australian Signals Directorate any ransomware payments made in connection with a cyber security incident, applying to all entities above a set revenue threshold.
This matters for phishing training because ransomware is most commonly delivered via phishing emails. An untrained team is not just a security risk — it is now a compliance and reporting risk at the executive level.
The Essential Eight Framework
The Australian Signals Directorate (ASD) developed the Essential Eight as a baseline set of mitigation strategies to reduce the risk of cyber incidents. The Essential Eight Maturity Level 2 is a mandatory requirement for all Australian non-corporate Commonwealth entities subject to the Public Governance, Performance and Accountability (PGPA) Act.
While some sectors are required to meet a specified maturity level under the Security of Critical Infrastructure Act 2018 (SOCI Act), the Essential Eight is also recommended as a voluntary baseline for all organisations. Even where it is not legally compulsory, regulators and insurers increasingly expect private organisations to demonstrate they have followed these guidelines.
Phishing awareness training aligns with the Essential Eight's emphasis on user education, application controls, and multi-factor authentication — all of which reduce the risk of a successful phishing attack gaining a foothold.
Board-Level Accountability
The Australian Institute of Company Directors (AICD) emphasises that cyber security is a board-level governance responsibility, and the joint ASD–AICD Cyber Security Priorities for Boards in 2025–26 identifies four priority areas boards should actively oversee. Under the Corporations Act 2001, directors have a duty of care and diligence. Failing to ensure adequate cyber awareness training for staff could be considered a breach of that duty.
In 2026, regulators and insurers increasingly expect organisations to prove that employees have completed a cyber security awareness training course. If there is no evidence of training, from a governance perspective, it effectively never happened.
What Does Effective Phishing Training Actually Look Like?
Understanding that training is required is one thing. Knowing what good training looks like is another. Many organisations still rely on annual slideshow presentations or one-off email warnings — approaches that research consistently shows have little lasting impact.
Move Away from Annual, One-Off Training
Traditional workshops or annual webinars often overwhelm employees with too much information in a single session. After an hour of slides and statistics, most of the content is forgotten within days. Effective phishing training is not an annual event. It is an ongoing habit.
Industry guidance suggests that for the best and most consistent results, employees should be given security awareness training every four months.
Use Simulated Phishing Campaigns
One of the most effective approaches is sending realistic but harmless fake phishing emails to employees and measuring who clicks. This is not about tricking people into feeling embarrassed — it is about giving them a low-risk opportunity to experience what a phishing attempt looks like and learn from it in real time.
When an employee clicks a simulated phishing link, the best programs redirect them immediately to a short, constructive learning moment rather than a disciplinary outcome. The goal is behaviour change, not blame.
Localise the Content for Australian Contexts
Some platforms deliver cyber security awareness training designed for global audiences. These courses frequently reference US-specific terminology or regulatory frameworks that feel irrelevant to Australian employees. When staff cannot relate to the content, engagement and retention drop dramatically.
Training that references myGov impersonation scams, Australian Taxation Office phishing emails, or fake superannuation communications — the types of attacks Australian workers actually encounter — will land far more effectively than generic overseas content.
Adopt a Micro-Learning Model
The most effective programs in 2026 follow a micro-learning model designed for busy employees. Short modules of five to ten minutes, delivered regularly and tied to current threats, are far more effective than lengthy annual sessions. This approach works particularly well in workplaces with older staff, shift workers, or teams who spend most of their time away from a desk.
Cover the Full Spectrum of Phishing Threats
Modern phishing has expanded well beyond suspicious emails. Common phishing techniques in 2025 targeting Australian businesses include Business Email Compromise (BEC), spear phishing using personal details to build trust, smishing and vishing through SMS and voice calls, credential harvesting pages, and multi-platform campaigns that begin on email and move to platforms like LinkedIn or messaging apps.
Good training should cover all of these attack vectors, not just email. If a team member does not know that an unexpected call from the "IT help desk" asking for their login credentials is a vishing attempt, then half the training gap remains unfilled.
A Snapshot: What Phishing Training Needs to Cover
|
Training Area |
Why It Matters |
|
Recognising suspicious emails |
The starting point for any phishing defence |
|
BEC and CEO fraud |
High financial impact; heavily used in Australia |
|
SMS and voice phishing |
Increasingly common with AI voice cloning |
|
Safe reporting procedures |
Employees must know what to do when they suspect a threat |
|
Password hygiene and MFA |
Reduces damage when credentials are compromised |
|
Incident response basics |
Every staff member should know who to contact |
Sector-Specific Considerations
Healthcare and Aged Care
Patient records are among the most valuable data types on the dark web. Healthcare providers must comply with both the Privacy Act and sector-specific obligations under the My Health Records Act 2012. Staff often work under high pressure and may be more vulnerable to urgent-sounding messages. Training in this sector needs to address that specific emotional context.
Financial Services
APRA-regulated entities must comply with CPS 234, which sets out specific requirements around information security, including the capability to detect, respond to, and recover from information security incidents. Phishing awareness training is considered a key element of an organisation's defensive capability under this standard.
Government and Critical Infrastructure
The NSW Cyber Security Policy establishes mandatory requirements for all NSW Government agencies to effectively manage cyber security risks, and the Essential Eight is mandated for government agencies under this policy. Culture and awareness through training and awareness programs is an explicit priority area. Similar frameworks apply in other states and territories.
The Real Cost of Not Training Your People
The direct financial impact of a successful phishing attack is only part of the story. There are also the costs of incident investigation, legal advice, regulator notifications, potential fines, and the reputational damage that follows a publicised breach.
Cyber insurers increasingly expect evidence of baseline controls — including Essential Eight compliance and staff training — before offering coverage at competitive premiums. In practice, organisations without documented phishing training may find their insurance claims disputed if a breach occurs.
In May 2025, the Australian Government introduced a mandatory ransomware reporting regime for businesses with annual turnovers of $3 million or more. For these organisations, a phishing-enabled ransomware attack now comes with mandatory government notification attached.
There is also a simpler human cost. When staff are not equipped to recognise phishing, they carry the anxiety of making an irreversible mistake. Training gives people confidence and clarity — that is worth something independent of the regulatory requirements.
Where to Start: Building a Training Program That Actually Works
Getting a phishing training program off the ground does not require a large budget or a dedicated security team. It does require a structured, consistent approach.
Begin with a baseline assessment — either a simulated phishing exercise or a short knowledge quiz — to understand where your team currently stands. Use the results to tailor the content, not to shame individuals.
Establish a regular training schedule and stick to it. Quarterly modules combined with periodic simulated phishing campaigns creates the kind of repeated exposure that actually builds lasting habits.
Make reporting easy. If an employee suspects a phishing email, they need a simple, low-friction way to flag it — ideally a single button in their email client. The faster suspicious emails are reported, the faster your security team can respond.
Document everything. Completion rates, simulation results, and refresher training records are what a regulator, insurer, or client will ask for when they want to verify your security posture.
Take the Next Step with Purpose-Built Australian Training
If you're looking for a training solution built specifically for the Australian context, the Phishing Prevention and Email Security Training course from Australian Compliance Training is designed to give your team practical, immediately applicable skills to recognise and respond to phishing threats.
The course covers the full range of modern phishing tactics — from email-based BEC attacks to SMS and voice phishing — and is structured around Australian workplace scenarios and regulatory context. It's suitable for all staff regardless of their technical background, and completion is fully trackable for compliance purposes.
Ready to protect your people and meet your legal obligations? Enrol your team in Phishing Prevention and Email Security Training today.
