Skip to content
Business Services

Cyber Security Awareness Training

Your staff are the control that fails first, and a report saying so changes nothing on its own. GravIT phishes your team to get an honest baseline, trains them, tests them again, and chases the people who do not do it. Anyone still clicking gets a teacher in the room. That accountability is the difference between a box ticked and a defence that works.

Why most of it fails

Everybody runs phishing tests now. The results are still bad.

The monthly ritual is familiar. Results go to management, everyone agrees it needs to improve, a reminder email goes round, it gets a mention in a meeting, and next month the numbers look the same.

Then the report softens it by showing you the industry average, and everyone relaxes. That average deserves no comfort at all: it is low because most businesses do this badly. Measuring yourself against a room full of people who are also failing is not a benchmark, it is company.

Meanwhile the attacks got better. Scammers use AI now, and between that and what your team has quietly published on social media, they can build a profile of a real person and write a message tailored to them. “Spot the typo” stopped being useful advice some time ago.

How we run it

The difference is what happens to the people who keep failing.

Everything up to that point is ordinary and we do it properly. It is the branch below the line that turns a report into a defence.

Runs on a loop, and again, and again. A habit is not a certificate.

  1. Phish first

    Before anyone is trained, so the starting number is the real one.

  2. Assign training

    Short modules, assigned automatically, new starters included.

  3. Phish again

    Another campaign. The score either moves or it does not.

  4. Keep going

    Monthly, not annually. March is forgotten by June.

… and when the same people keep clicking

  1. Escalating reminders, four weeks. Each one says plainly what happens next.
  2. Still ignored? Management and HR are told. It stops being optional.

In person. With a teacher.

On site, one to one or in a small group. Not another video, because another video has already not worked.

Then straight back into the cycle. Nobody is written off.

A real baseline, before anyone is trained

We phish your staff first, before a single module is assigned. Train people first and you never learn what your actual starting position was. You just get a number that was always going to look better. The first campaign is the honest one, and nobody is named for it.

Then training, then testing, forever

Short modules assigned automatically, including to new starters, so nobody has to remember to enrol anyone. Then another simulated campaign, and the score either moves or it does not. Monthly rather than annually, because a session in March is forgotten by June.

The platform behind it handles the mechanics: realistic simulations, courses matched to what each person got wrong, a risk score per user rather than one number for the business, policy acknowledgements, and a check on whether staff addresses are turning up in breach data. Useful plumbing, but plumbing is all it is.

Accountability, which is the actual product

Software can tell you who failed. It cannot make anything happen about it. So we do:

  • Someone reads the report. Completions, non-starters, failures and high-risk users, every cycle, by a person rather than a dashboard nobody opens.
  • Non-completers get chased. Escalating weekly reminders across four weeks, each one saying plainly what happens next if it keeps being ignored.
  • It stops being optional. Continued non-compliance is reported to management and HR, and repeat failures are assigned to high-risk training.
  • Training keeps up with the scams. Sessions cover what is actually arriving now: AI-written phishing with no clumsy tells, voice-clone phone calls, and how much of what your team shares publicly is being harvested to tailor the next attempt.
  • Management gets the trend. Completion, risk and direction of travel, with recommendations, in language a board or an insurer can read.

And for the people who still keep clicking

They get a teacher. On site, one to one or in a small group, with someone walking through the material with them, using real examples and roleplay, until it lands. It is deliberately not another video, because another video has already not worked.

This is also where we can help people the online-only approach quietly leaves behind: staff for whom English is a second language, staff who find the technology itself hard, and staff who have been nodding along in meetings for two years without wanting to say so. It is done without embarrassment. The aim is a colleague who now reports suspicious email confidently, not a colleague who has been told off.

Where it fits

Training is the control that covers what the other controls miss, and it is the cheapest one on the list. It sits alongside cyber security and email protection. Filtering catches what it can, multi-factor authentication catches most of the rest, and this covers the convincing message that still lands on a busy Tuesday. It also supports several Essential Eight controls in practice, and gives you the evidence insurers increasingly ask for.

What's included

  • Baseline phishing campaign first
  • Short modules, assigned automatically
  • Ongoing simulations, monthly
  • Per-user risk scoring
  • New starters enrolled for you
  • Four-week escalation on non-completers
  • Reporting to management and HR
  • In-person sessions for repeat failures
  • Board and insurer-ready evidence
FAQ

Frequently asked questions

Isn't security awareness training just an annual video?

One session a year is forgotten by February. Ours runs continuously in short pieces, with simulated phishing in between, because the point is a changed habit rather than a completion certificate.

What happens to someone who keeps failing?

They get a teacher. After escalating reminders and a report to management, anyone still failing gets an in-person session on site, one to one or in a small group, walking through real examples until it lands. That is the part most providers do not do, and it is the part that changes the number.

Will it embarrass staff who click?

No, and it would not work if it did. Results target training rather than name anybody, the first baseline campaign is nobody's fault by definition, and the in-person sessions are run as help rather than a telling-off. We want people who report a suspicious email confidently, and that only happens when they are not afraid of getting it wrong.

Why phish us before training anyone?

Because otherwise you never learn your real starting position. Train first and the first score was always going to look respectable, which tells you nothing about the day before you started.

Our results are around the industry average. Is that fine?

It is worth less comfort than it appears. The average is low because most businesses run this as a box-ticking exercise, so matching it means keeping company with a lot of organisations that are also failing. The number worth watching is your own, moving.

Does the training cover AI scams and deepfakes?

Yes, because the scams now do. AI writes phishing without the clumsy tells people were taught to look for, and voice cloning makes “the boss on the phone” something to verify rather than trust. Training covers both, along with the quiet one: how much staff share publicly that scammers harvest to make an attempt convincing.

Does it help with the Essential Eight or our cyber insurance?

It supports both. Staff awareness underpins several Essential Eight controls in practice, and insurers increasingly ask whether you run training and can evidence it. The reporting gives you that evidence, including who did not complete and what was done about it.

How much staff time does it take?

Minutes at a time, not half-days. Short modules people can finish between jobs, which is the only way training actually gets done in a busy business. The in-person sessions are scheduled around your shifts.

What does it cost?

It is priced per user alongside your other licensing, with the in-person work quoted to scope. Call 03 5280 8088 and we will size it to your headcount.

Find out how your team would go

That is exactly what the first campaign tells you. No judgement and no training beforehand to flatter the number, just an honest baseline.