The click that starts the week badly
Picture a Tuesday in a West Perth office. Accounts gets a PDF invoice that looks like last month’s supplier. The logo is right. The amount is close enough. Someone opens it, or follows a link to “confirm banking details”. By Thursday you are untangling a payment diversion or a compromised mailbox.
That story is common because it is ordinary. Attackers write for busy people, not for security teams. Security Awareness Training (SAT) exists to make the next ordinary Tuesday less dangerous.
SAT is not a vibe. It is scheduled practice: short lessons plus safe phishing simulations, with coaching when someone slips. If you want the program definition we run for clients, read the SAT page at /security-standard/security-stack/sat/ and how it sits inside /one-plan/.
What “good” looks like in a small team
In a fifteen-person firm, everyone knows who clicked the sim. That is why shame is a bad design. Good SAT thanks reporters, coaches quietly, and keeps scores at the trend level for leadership.
Training modules should finish in a coffee break. Topics should match Australian inbox bait: ATO themes, fake delivery notices, supplier bank-change emails, and messages that impersonate a director who is on a flight to the Pilbara.
Simulations should arrive often enough that people stay sharp, without becoming a weekly joke. When a real campaign hits WA businesses, themes should update. Static playlists go stale.
Measure three things: click rate, report rate, and time-to-report. A falling click rate with a rising report rate is the healthy pattern. Flat numbers mean the program is theatre.
Build a simple playbook for a real click: report, contain, reset sessions if needed, tell finance if payments were involved. Practice the playbook in training so it is not invented during panic.
Why filters alone are not enough
Modern Microsoft 365 plans can block a lot of junk. They will not catch every well-written lure, especially ones that use compromised partner mailboxes or lookalike domains.
People still approve payments, open attachments, and forward “urgent” requests. SAT trains judgment for the messages that survive filtering.
It also trains the recovery habit. Clicked something? Report it. Do not hide it. Speed matters more than pride. Small Perth teams recover faster when reporting is normal.
Filters and SAT should share lessons. If sims show a theme people keep missing, tighten mail rules where you can and coach the process that theme abuses. Technology and habits move together.
Roles that need tailored practice
Finance and payroll see payment fraud. Give them payment-fraud sims. Do not waste their time on generic “stranger danger” cartoons.
Directors and practice managers are prime impersonation targets. Include them. Busy is not an exemption.
Field and workshop staff with phones still get phishing. If they have a company login, they belong in SAT.
New starters should enrol in week one. The first month is when process knowledge is thinnest and attackers love that gap.
Reception and shared-inbox operators need practice too. Shared mailboxes are common entry points for business email compromise because many people touch them and ownership is fuzzy.
How to judge your current provider
Ask for last quarter’s click and report trends. If they cannot show numbers, you do not have a program. You have a licence line on an invoice.
Ask what happens after a click. Coaching and a short lesson is good. Silence or public embarrassment is not.
Ask whether executives are included. Ask whether contractors with mailboxes are included. Gaps are where incidents start.
Ask how SAT ties to email protections and incident response. Training in a vacuum does not fix a mailbox rule an attacker already created.
Ask whether content changes after real campaigns hit Australian SMEs. A playlist from two years ago is not awareness. It is nostalgia.
Where SAT sits in uplift
Continual Security Uplift treats people controls as required, not soft extras. Baseline captures behaviour risk. Stabilise and Uplift put training and sims in place. Continual reviews check whether habits improve.
Business Premium is the technical floor for identity, devices, and mail filtering. SAT is the habit floor. Stride IT requires both. Details live on /security-standard/security-stack/sat/ and the full program at /one-plan/.
If your MSP sells “security” without practising the inbox with your staff, ask why. Most breaches still begin with a human decision under time pressure. Practice is how you change that odds profile without pretending people are perfect.
Uplift also stops the common trap of “we trained everyone at go-live”. Turnover resets habits. Continual reviews keep SAT alive after the project glow fades.
A practical starter checklist
Enrol every mailbox user, including leaders and contractors.
Run short modules on a steady cadence, not an annual binge.
Simulate real payment and impersonation themes used against Australian SMEs.
Coach quietly. Celebrate reports. Track trends in quarterly reviews.
Update content when real campaigns hit your sector.
Connect SAT outcomes to uplift actions when the same people keep failing the same tests.
Write down who staff call after a real click, and rehearse that path once a year without drama.
Payment fraud deserves its own drill
Many Perth SMEs lose sleep over ransomware. Fair. Payment diversion via email still empties accounts without encrypting a single file.
Train finance on a second-channel check for any bank detail change. Phone a known number. Do not reply in the same thread. Put that rule in SAT and in your accounts process.
Simulate director impersonation during known travel weeks. Attackers time urgency. Your practice should too.
If a sim shows finance clicking “update details” links, fix process first, then technology. SAT should expose process gaps, not only individual mistakes.
What success feels like
Success is not zero clicks forever. People are human. Success is fewer dangerous clicks, faster reports, and fewer surprises for finance.
It feels like a staff member pausing on a bank-change email and ringing the supplier on a known number. That pause is the product.
It also feels like leadership asking for the quarterly SAT chart the same way they ask for Secure Score. Habits become a managed control, not a soft hope.
If you want that control as a required stack item, start with /security-standard/security-stack/sat/ and apply through /one-plan/.
Want the required-stack definition we run with clients? Read /security-standard/security-stack/sat/ and the Our One Plan.
