Required for all clients
Security Awareness Training (SAT) is the habit layer of your defence. It is short lessons and realistic phishing simulations for every person with a company mailbox or login. Not posters. Not a once-a-year slideshow nobody finishes.
Most attacks against Perth SMEs still start with a message that looks almost right. A fake invoice. A fake bank alert. A fake request from the director. SAT gives people practice before the real campaign lands.
At Stride IT, SAT is required for every client under the Continual Security Uplift Program. It sits beside Business Premium controls and the rest of the required stack. Technology reduces the blast. People still open the mail.
What SAT is
SAT has two parts that work together. Training teaches people what to look for and what to do next. Simulations send safe fake phishing messages so staff can practise reporting without risking the business.
Good training is short. Ten minutes beats a half-day workshop that gets cancelled twice. Topics stay practical: how to spot a lookalike domain, why urgent payment requests deserve a second channel check, what to do if you already clicked.
Simulations should match how attacks arrive in Australian inboxes. Tax time themes. Supplier payment changes. Shared mailbox traps. “CEO said pay this now” messages sent while the real CEO is offline. Cartoon scare tactics do not build useful habits.
Reporting matters as much as not clicking. A user who clicks and reports fast still helps. A user who clicks and stays quiet can let an attacker sit in the mailbox for days. SAT should make reporting normal, not embarrassing.
Results show up as trends: click rates, report rates, and who needs a quiet coaching chat. Shame campaigns backfire. Coaching and clear process work better for small teams where everyone knows each other.
SAT is also a feedback loop for your email protections. If sims show people falling for lookalike domains, you tighten filters and Conditional Access where you can. Training without that loop is half a program.
Why it matters for Perth SMEs
Perth businesses often run lean. The same person may handle invoices, client email, and supplier updates. One convincing message can move money or open a door into Microsoft 365.
Insurers and boards increasingly ask how you train people. “We told them once” is a weak answer. Ongoing SAT with measured results is easier to explain at renewal time.
Many local firms work with trades, professional services, and project clients across WA. Staff jump between site, home, and office. Phishing does not wait for them to be at a desk with a calm inbox.
Business Premium can filter a lot of junk. It cannot teach judgment. Attackers write for the gaps: the Friday arvo rush, the end-of-month payment batch, the new starter who has not seen a real company process yet.
SAT also protects your reputation. If a compromised mailbox starts phishing your customers, you spend the next week apologising. Prevention is cheaper than that cleanup.
Regional and FIFO-linked teams add another wrinkle. People check mail on phones between jobs. Short modules and mobile-friendly reporting beat long desktop courses that never get finished on site.
Day-to-day reality
In a healthy setup, staff get small training modules on a steady cadence. Simulations arrive without fanfare. People who report a sim get a quick thank-you and a tip. People who click get a short lesson, not a public call-out.
Managers see simple numbers each quarter: are click rates falling, are reports rising, are the same few accounts still the weak spots. That feeds the Continual Security Uplift review, not a vanity dashboard.
Finance and admin teams often see the sharpest phishing. They should get scenarios that match payment and supplier fraud. Sales teams see different bait: fake meeting links and file shares.
New starters should land in SAT in their first week. Waiting three months is asking for trouble. Contractors with mailboxes need the same standard as permanent staff.
When a real phishing campaign hits Perth, your provider should tighten sims and training around that theme. SAT is not a set playlist you ignore for twelve months.
Leaders should model the behaviour. If directors ignore training invites, staff will too. Include them in the same cadence, with scenarios that match payment approvals and wire changes.
Common failure modes
Annual compliance videos that people mute and click through. Nobody remembers the content. Attackers still win on Monday morning.
Simulations that are so obvious they teach nothing, or so rare that the first real test feels like a gotcha. Neither builds skill.
Punishing clickers in front of the team. People stop reporting. The next real incident stays quiet until money moves.
Training only “office” staff and skipping warehouse, workshop, or field roles who still have email on phones.
Buying SAT as a checkbox, then never reviewing the reports. If click rates stay flat, something in the program is not working.
Leaving executives out because they are “too busy”. Directors are prime targets for payment fraud. They need the practice too.
Running sims but never teaching what to do after a real click: who to call, how to report, and how fast to reset sessions.
Questions for your IT provider
Is SAT required for every user with a mailbox, or optional for “risk roles” only?
How often do simulations run, and how do you choose themes that match real threats?
What happens when someone clicks? Is there coaching, and how is privacy handled in a small team?
Do we see click and report trends in quarterly reviews, with clear owners for follow-up?
Are new starters enrolled automatically in the first week?
How does SAT connect to email protections in Business Premium, so training and filters work as one story?
If the same people keep failing, what changes in the next uplift cycle besides another generic video?
Fit with Continual Security Uplift and Business Premium
Business Premium gives you stronger email filtering, Conditional Access, and device compliance. Those controls cut volume. SAT trains people for what still gets through.
In Continual Security Uplift, we baseline behaviour early, then keep measuring. Stabilise and Uplift phases put training and sims in place for everyone. Continual reviews track whether habits are improving.
SAT pairs with EDR, ITDR, and SIEM. If someone clicks a real payload, detection still matters. If fewer people click, you have fewer fires. Both layers belong in the Standard.
We do not treat SAT as a soft optional. If a client will not train users, we decline. The human layer is part of the floor, same as Business Premium.
When you earn the Stride Uplift Mark path, people controls sit alongside technical proof. Boards and clients can see you take the human side seriously without claiming official government certification.
Uplift is continual on purpose. Attack themes change. Staff turnover resets habits. SAT stays on the quarterly agenda so the human layer does not decay after go-live.
SAT is practice for the inbox you already have. Short training, honest simulations, coaching without theatre, and numbers that move over time. For Perth SMEs on Continual Security Uplift, it is required because most breaches still begin with a person making a fast decision under pressure.
Further reading
What Is Security Awareness Training (SAT) for Perth Businesses?
A longer owner’s guide on the same topic, written for Perth businesses comparing providers.
Read the blogWHAT YOU GET
Lower click rates on phishing over time with numbers you can show the board.
Staff who know what to do when something looks wrong.
Human layer that matches the technical controls in the Standard.
FREQUENTLY ASKED QUESTIONS
Is SAT required for Stride IT clients?
Yes. Security Awareness Training (SAT) is required for every client under the Stride IT Security Standard. It is not an optional add-on. If you will not run it, we decline.
How does SAT fit Our One Plan?
SAT is part of the required detection and posture stack inside Our One Plan. It sits on top of Microsoft 365 Business Premium. We baseline it in the Baseline Review, implement it during Stabilise and Uplift, and review it in quarterly Continual reviews.
Do you sell this as a standalone product?
No. This stack runs as part of Our One Plan with Continual Security Uplift. We do not cherry-pick detection controls while leaving the rest of the Standard unfinished.
THE REST OF THE STACK
APPLY FOR BASELINE
We confirm Business Premium readiness and the full required stack, including SAT, before we start.
Apply for Our One Plan