The real problem with security awareness training happens before the product is chosen.
Cyber training programs are typically evaluated and purchased by IT and cybersecurity teams. Criteria is technical, shaped by vendor demos, largely disconnected from the people in the business: what shifts their behaviour and fits into busy days?
If this vital human question is skipped in selection, no feature list alone will deliver lasting change. This report shows why teams need executive sponsorship, and effective socialisation.
Without these foundations, adoption stays low regardless of which platform is selected. Teams go back to market blaming the product for what the program never delivered.
Meanwhile, attackers study supply chains and org charts, pull data from LinkedIn and public records, and use AI to produce requests near-indistinguishable from legitimate ones.
The capacity of any workforce to absorb, retain, and act on security knowledge under pressure has a ceiling. Beyond it, the responsibility shifts to the defence-in-depth layers that wrap around your people: email security, endpoint controls, identity management.
This report is produced in collaboration with Parabellum, Byte and CodeBlue New Zealand. We examined 20 platforms based on real testing across staff bases. Assessing the cyber curriculums that deliver lasting change.
This report finds that people are not the problem. They can be a solution with the right training solution.
Security awareness training is growing the skills gap
Most organisations train staff once a year1,2. A 20-minute module, a completion-rate report filed for audit. They satisfy a regulatory checkbox. But they do not change behaviour.3
It's been true since 1885. Forgetting Ebbinghaus' Curve,4 or countless studies telling us infrequent training only produces a minimal change in behaviour. Closer to home, an Adelaide study found that where training improved phishing identification, improvement had disappeared by 6 months.5
The Australian Information Commissioner recorded 1,113 notifiable data breaches in 2024 (the highest annual total since the NDB scheme began).6
Human factors, including phishing, credential theft, and social engineering, were implicated in approximately 45% of all incidents.7 The skills gap between staff and attackers is widening.
Attacker AI · 2025
24% more effective than human-crafted phishing
~80% of attacks AI-generated
SAT programmes · 2025
7.5% personalise training to individual risk
Sources: Brightside AI (2025); e-Bits (2025). Attacker adoption indexed to AI-generated phishing prevalence. SAT personalisation rate (7.5%, 2025) confirmed; 2020–2024 training trend estimated. See sat_divergence_dataset_v1.md. 2026 values projected.
Tekspace's Email Security research supports email as the dominant vector in AU breach data.8
But the attack surface grew beyond the inbox and programs do not train the gap. Voice phishing surged fourfold in the past year9, yet only one in five orgs train staff for phone-based attacks10. SMS phishing had more than doubled11, with similarly thin training coverage. And virtually no training assesses the established QR code phishing vector.
AI shifts the balance further. By early 2025, AI-generated phishing outperformed human-crafted attacks by approximately 24%12. It was estimated 80% of phishing in that period was AI-generated13 The attacks are more convincing and produced at a scale no human team could sustain.
The deepfake dimension compounds the risk. Mastercard-commissioned research found 20% of Australian businesses received deepfake threats in the prior 12 months14, but many of the trusted training software vendors have no plan to offer deepfake capability in the next 6 months.15
For organisations responsible for customer data, not training staff to identify emerging vectors indicates training does not satisfy the regulatory requirements for cyber awareness outlined by The OAIC's APP 11: Security of personal information.
In 2025, the Federal Court handed down the first civil penalty ever issued under the Privacy Act for a data breach: $5.8 million against Australian Clinical Labs16. The court specifically noted that “the IT team leader had no formal cybersecurity training and had never seen the organisation's cyber playbooks”.
In 2024, an enforceable undertaking against Oxfam Australia became the first to explicitly mandate a security awareness training program.17
For the first time ever, cybersecurity training is now a business obligation, not an IT task. When a breach happens, businesses face a greater financial cost from the government than the APTs.
Across the regulated economy, the bar for adequate training has moved from completion to demonstrated behaviour change.
Or 30% of domestic turnover. Up from $2.2M before December 2022.
Per day. 11 sectors. All approved frameworks require SAT.
Phishing test rates named as Board-level reporting.
Australian Clinical Labs — first civil penalty in Privacy Act history.
Court cited no formal cybersecurity training for key IT staff.
That position alone warrants attention. But the deeper problem is the awareness-action gap that knowledge-based training alone cannot close. It becomes clear in post-incident reviews, the users who engage in unsafe behaviour are fully aware of the risk and proceed anyway.19
Legacy training modules can only inform. They can't change what people do under pressure, under deadline, or under the authority cues that modern social engineering exploits. The psychology is well understood. The challenge is building programmes that account for it.
When the goal shifts from compliance to sustained behavioural change, the human layer moves from liability to a functioning part of an organisation's cyber strategy.
With the threat context as a backdrop, what do information technology professionals prioritise when considering a new security awareness training solution?
Delivers training effective to the intent of the organisation; in-line with regulations, effective phishing simulations, the ability to report emails when they see them, resulting in improved metrics across the organisation.
The platform can automate campaigns, content, reporting and learning, so admins are not spending hours each week to deliver cyber training programs to one or many tenants.
A single behavioural risk score that aggregates simulation data, training engagement, and incident reporting into one view.
Engaging, relevant, localised content that earns attention and delivers learning rather than demanding compliance.
Security awareness training is a well-defined category with a clear set of capabilities.
The Tekspace Cyber Continuum™ ranks 20 of the leading security awareness training vendors in one transparent, measureable spectrum.
We assessed 300+ vendor features across the field, normalising to 39 distinct capabilities. A weighted scoring model produces a single maturity score per vendor, giving a picture of feature depth rather than feature count alone.
You could just pick a leader on our Cyber Continuum™ - but a logo on a chart is not a reflection of how it truly fits your environment with your team. We help with that.
Book your sessionCompletely free. If we can't find a match, we exit your journey.
The quickest way to assess a platform's maturity is how it teaches.
Platforms built like a library hand administrators a content catalogue and hope for the best. Others work like an exam, training only on failure. Neither reliably changes behaviour.
The model that produces measurable change is a curriculum. Sequenced content that builds foundations first, repeats the basics, layers complexity, and adapts to each person's skill level and susceptibility traits. IT teams often find this approach too simple. That is their lens, not their workforce's.
With automated set ups or smart baselining the best platforms deliver value from day one, not after six months is spent setting up the curriculum.
Because a platform is only half the investment. Without executive support, without socialising why it's being done, without normalising failure, adoption will be low regardless of platform.
And it is why teams go back to market blaming the solution.
Once-off induction sessions and annual modules are not delivering the outcomes Australian organisations need.
Technical controls handle what they can. Between what technology covers and what falls through the cracks, a well-run training program is the highest-return investment most organisations have not yet made properly.
If your current program is not producing measurable behaviour change, we can help. We will map your program against the outcomes in this report, identify the gaps, and match you with the platform best suited to your people, your compliance obligations, and your risk profile.
In launching this report, the Tekspace would like to acknowledge contributions from the following teams and individuals.
This report evaluates platforms delivering phishing simulations, in-email reporting, and cybersecurity awareness education. It does not cover standalone email security gateways, broader governance/risk/compliance platforms, or physical security awareness programs.
Twenty-three vendors were researched. Three were excluded as out-of-category following technical review, leaving 20 platforms in the final evaluation.
One hundred and forty-four enriched features were normalised into 32 canonical capabilities across 20 evaluated vendors. Each capability was classified into one of three maturity bands based on how many vendors offer it.
Tablestakes capabilities (offered by 13 or more vendors) represent market baseline. Common capabilities (5-12 vendors) represent meaningful differentiation. Advanced capabilities (4 or fewer vendors) represent specialist depth.
A weighted scoring model assigns higher value to capabilities requiring greater technical depth, producing a single maturity score per vendor.
At the outset, we aimed to produce an analysis that is both strategic and practical. It needs to be useful to all IT leaders, regardless of how familiar they are with a given product domain.
In doing so, we gave consideration to how products are compared against one another.
Comparison at a superficial level is too shallow and doesn't give insight as to differentiation between products. At the same time, diving into technical minutiae can often mean losing focus of how products are meaningfully differnt.
As such, we conduct our evaluation at what we call, Level 2: The Functional Group.
In doing so, we can consistently assess whether a product's capabilities are more or less likely to help IT leaders achieve their desired outcomes.
| Domain | Level 1 The Module |
Level 2 The Functional Group |
Level 3 The Micro-Feature |
|---|---|---|---|
| Grocery | Fruit | Banana | Sold in bunches of 5 |
| Automotive | Car | Wheels | 5 spokes, 5 lug nuts |
| Education | Course | Mathematics | Weekly problem sets |
| Healthcare | Clinic | GP Consultations | 15 Minute Standard Appointment |
Where commercial relationships exist, we apply the same evaluation criteria we use for all technologies, including tools we do not resell. We recognise the importance of independence in this research, and do not let commercial relationships affect our framework.
Findings reflect our professional judgement at the time of publication, based on the data available to us. Product capabilities and roadmaps change, so organisations should treat this report as a guide to practical decision making, not as a substitute for their own due diligence.
If you have identified errors in this report, or wish to have another product assessed, please contact our team.
Contact our team