Security Awareness Training
A Cyber SaaS Analysis 2026Foreword
The real problem with security awareness training happens before the product is chosen.
Cyber training programs are typically evaluated and purchased by IT and cybersecurity teams. Criteria is technical, shaped by vendor demos, largely disconnected from the people in the business: what shifts their behaviour and fits into busy days?
If this vital human question is skipped in selection, no feature list alone will deliver lasting change. This report shows why teams need executive sponsorship, and effective socialisation.
Without these foundations, adoption stays low regardless of which platform is selected. Teams go back to market blaming the product for what the program never delivered.
Meanwhile, attackers study supply chains and org charts, pull data from LinkedIn and public records, and use AI to produce requests near-indistinguishable from legitimate ones.
The capacity of any workforce to absorb, retain, and act on security knowledge under pressure has a ceiling. Beyond it, the responsibility shifts to the defence-in-depth layers that wrap around your people: email security, endpoint controls, identity management.
This report is produced in collaboration with Parabellum, Byte and CodeBlue New Zealand. We examined 20 platforms based on real testing across staff bases. Assessing the cyber curriculums that deliver lasting change.
This report finds that people are not the problem. They can be a solution with the right training solution.
Security awareness training is growing the skills gap
Most organisations train staff once a year1,2. A 20-minute module, a completion-rate report filed for audit. They satisfy a regulatory checkbox. But they do not change behaviour.3
It's been true since 1885. Forgetting Ebbinghaus' Curve,4 or countless studies telling us infrequent training only produces a minimal change in behaviour. Closer to home, an Adelaide study found that where training improved phishing identification, improvement had disappeared by 6 months.5
The Australian Information Commissioner recorded 1,113 notifiable data breaches in 2024 (the highest annual total since the NDB scheme began).6
Human factors, including phishing, credential theft, and social engineering, were implicated in approximately 45% of all incidents.7 The skills gap between staff and attackers is widening.
The adoption gap
Attacker AI · 2025
24% more effective than human-crafted phishing
~80% of attacks AI-generated
SAT programmes · 2025
7.5% personalise training to individual risk
Sources: Brightside AI (2025); e-Bits (2025). Attacker adoption indexed to AI-generated phishing prevalence. SAT personalisation rate (7.5%, 2025) confirmed; 2020–2024 training trend estimated. See sat_divergence_dataset_v1.md. 2026 values projected.
Training can't teach beyond the inbox
Tekspace's Email Security research supports email as the dominant vector in AU breach data.8
But the attack surface grew beyond the inbox and programs do not train the gap. Voice phishing surged fourfold in the past year9, yet only one in five orgs train staff for phone-based attacks10. SMS phishing had more than doubled11, with similarly thin training coverage. And virtually no training assesses the established QR code phishing vector.
AI shifts the balance further. By early 2025, AI-generated phishing outperformed human-crafted attacks by approximately 24%12. It was estimated 80% of phishing in that period was AI-generated13 The attacks are more convincing and produced at a scale no human team could sustain.
The deepfake dimension compounds the risk. Mastercard-commissioned research found 20% of Australian businesses received deepfake threats in the prior 12 months14, but many of the trusted training software vendors have no plan to offer deepfake capability in the next 6 months.15
For organisations responsible for customer data, not training staff to identify emerging vectors indicates training does not satisfy the regulatory requirements for cyber awareness outlined by The OAIC's APP 11: Security of personal information.
The regulatory cost of inadequate training
In 2025, the Federal Court handed down the first civil penalty ever issued under the Privacy Act for a data breach: $5.8 million against Australian Clinical Labs16. The court specifically noted that “the IT team leader had no formal cybersecurity training and had never seen the organisation's cyber playbooks”.
In 2024, an enforceable undertaking against Oxfam Australia became the first to explicitly mandate a security awareness training program.17
For the first time ever, cybersecurity training is now a business obligation, not an IT task. When a breach happens, businesses face a greater financial cost from the government than the APTs.
Across the regulated economy, the bar for adequate training has moved from completion to demonstrated behaviour change.
Regulatory penalties · Australia 2025
Or 30% of domestic turnover. Up from $2.2M before December 2022.
Per day. 11 sectors. All approved frameworks require SAT.
metric
Phishing test rates named as Board-level reporting.
Australian Clinical Labs — first civil penalty in Privacy Act history.
Court cited no formal cybersecurity training for key IT staff.
Australian and New Zealand staff record the second highest phish-prone rate in the world.18
That position alone warrants attention. But the deeper problem is the awareness-action gap that knowledge-based training alone cannot close. It becomes clear in post-incident reviews, the users who engage in unsafe behaviour are fully aware of the risk and proceed anyway.19
Legacy training modules can only inform. They can't change what people do under pressure, under deadline, or under the authority cues that modern social engineering exploits. The psychology is well understood. The challenge is building programmes that account for it.
When the goal shifts from compliance to sustained behavioural change, the human layer moves from liability to a functioning part of an organisation's cyber strategy.
Security Outcomes
With the threat context as a backdrop, what do information technology professionals prioritise when considering a new security awareness training solution?
Efficacy
Delivers training effective to the intent of the organisation; in-line with regulations, effective phishing simulations, the ability to report emails when they see them, resulting in improved metrics across the organisation.
Operational Efficiency
The platform can automate campaigns, content, reporting and learning, so admins are not spending hours each week to deliver cyber training programs to one or many tenants.
Reporting and Analytics
A single behavioural risk score that aggregates simulation data, training engagement, and incident reporting into one view.
User Experience
Engaging, relevant, localised content that earns attention and delivers learning rather than demanding compliance.
Product Landscape
Security awareness training is a well-defined category with a clear set of capabilities.
The Tekspace Cyber Continuum™ ranks 20 of the leading security awareness training vendors in one transparent, measureable spectrum.
We assessed 300+ vendor features across the field, normalising to 39 distinct capabilities. A weighted scoring model produces a single maturity score per vendor, giving a picture of feature depth rather than feature count alone.
Focused
See Vendors and FeaturesFocused
- Hacker Rangers
- ID Agent
- CyberHoot
- Boxphish
- Riot
- Mimecast
Features
- Phishing Simulations
- Training Content Library
- Interactive Training Modules
- Continuous Assessment
- Performance Reporting
- Platform Customisation
- Security Baselining
- AI-Generated Simulation Content
- Gamification
- White-Label Branding
- Behavioural Risk Scoring
- In-Email Report Button
Broad
See Vendors and FeaturesBroad
- Huntress
- usecure
- MetaCompliance
- SANS Institute
- Ninjio
- Infosec IQ
- Barracuda
- Immersive Labs
- SoSafe
- Proofpoint
Features
- Advanced Analytics & Dashboards
- Adaptive Learning Engine
- Smishing Simulation
- Single Sign-On
- LMS & Third-Party Integration
- Multilingual Content
- Policy & Compliance Management
- Multi-Tenant Management
- REST API
- SIEM Integration
Comprehensive
See Vendors and FeaturesComprehensive
- Hoxhunt
- Adaptive Security
- Phished
- KnowBe4
Features
- Vishing Simulation
- QR Code Phishing (Quishing)
- Dark Web & Breach Monitoring
- AI-Powered Spear Phishing Personalisation
- Automated Risk-Based Simulations
- Custom Scenario Builder
- Threat Intelligence Reporting
- Role & Industry-Specific Content
- Autonomous Training Orchestration
- Autonomous Phishing Simulation Orchestration
- Geo-Contextual Simulation Targeting
- Content Authoring Tools
- Hands-On Labs & Skills Assessment
- Structured Learning Paths
- Deepfake Simulations
- Data Sovereignty
Get matched with your best-fit
You could just pick a leader on our Cyber Continuum™ - but a logo on a chart is not a reflection of how it truly fits your environment with your team. We help with that.
Book your sessionCompletely free. If we can't find a match, we exit your journey.
Conclusion
Start with the learning model, not the feature list.
The quickest way to assess a platform's maturity is how it teaches.
Platforms built like a library hand administrators a content catalogue and hope for the best. Others work like an exam, training only on failure. Neither reliably changes behaviour.
The model that produces measurable change is a curriculum. Sequenced content that builds foundations first, repeats the basics, layers complexity, and adapts to each person's skill level and susceptibility traits. IT teams often find this approach too simple. That is their lens, not their workforce's.
With automated set ups or smart baselining the best platforms deliver value from day one, not after six months is spent setting up the curriculum.
Because a platform is only half the investment. Without executive support, without socialising why it's being done, without normalising failure, adoption will be low regardless of platform.
And it is why teams go back to market blaming the solution.
An opportunity to reimagine your training
Once-off induction sessions and annual modules are not delivering the outcomes Australian organisations need.
Technical controls handle what they can. Between what technology covers and what falls through the cracks, a well-run training program is the highest-return investment most organisations have not yet made properly.
If your current program is not producing measurable behaviour change, we can help. We will map your program against the outcomes in this report, identify the gaps, and match you with the platform best suited to your people, your compliance obligations, and your risk profile.
Addendum
Credits
In launching this report, the Tekspace would like to acknowledge contributions from the following teams and individuals.
Prepared by
- Frank De Pasquale, CEO at Tekspace
- George Hagivassilis, CCO at Tekspace
- Mike Ross, Service Director at Tekspace
- Finn Astle, Marketing Specialist at Tekspace
Contributions from
- Martin Dybalski, Director, Parabellum
- Stuart Shanahan, Director of Technical Services, Parabellum
- Kris Bowen, Senior Offensive Security Consultant, Parabellum
- Mathew Jose, Chief Information Security Officer at CodeBlue New Zealand
- Stacy Gurrie, Cheif Executive Officer at Byte
- Alison Bourke, Fractional CMO at The Launch Project
- Romain Pondard, Founder at Klippable
References
- Australian Signals Directorate (2025), ASD Annual Report 2024-25
- Australian Signals Directorate (2025), ASD Annual Report 2024-25
- Australian Federal Police (2025), Criminals target construction sector with Business Email Compromise scams
- Australian Signals Directorate (2025), Annual Cyber Threat Report 2024-25: fact sheet for businesses and organisations
- Practice Protect AU (2025), The devil is still in the email: what BEC looks like in 2025.
- Riposte Cybersecurity Consultancy (2025) Phishing threats in Australia's legal sector
- SecurityBrief Australia (2025) Email attacks surge in APAC, phishing up by 30% in 2024
- Australian Signals Directorate (2025), ASD Annual Report 2024-25.
- Australian Institute of Criminality (2024), Cybercrime in Australia 2023-24
- DeepStrike (2025), AI cybersecurity threats 2025: how to survive the AI arms race
- Keepnet Labs (2024), Navigating the email security market in 2025
- Abnormal Security (2024), H1 2024 Phishing Frenzy: C-suite receives 42x more QR code attacks than average employee
- Integris (2025) 2025 Integris report: law firms, cybersecurity and AI - what clients really think
- Google Threat Intelligence Group, Mandiant & Google Security Operations, (2025) Cybersecurity Forecast 2026
- VIPRE Security Group (2025) Cyber threats in 2025: how AI is changing phishing tactics
- StrongestLayer (2025) StrongestLayer secures US$5.2M to combat emerging AI-driven email threats
- Australian Institute of Criminality (2024), Cybercrime in Australia 2023-24
Scope
This report evaluates platforms delivering phishing simulations, in-email reporting, and cybersecurity awareness education. It does not cover standalone email security gateways, broader governance/risk/compliance platforms, or physical security awareness programs.
Twenty-three vendors were researched. Three were excluded as out-of-category following technical review, leaving 20 platforms in the final evaluation.
Scoring Methodology
One hundred and forty-four enriched features were normalised into 32 canonical capabilities across 20 evaluated vendors. Each capability was classified into one of three maturity bands based on how many vendors offer it.
Tablestakes capabilities (offered by 13 or more vendors) represent market baseline. Common capabilities (5-12 vendors) represent meaningful differentiation. Advanced capabilities (4 or fewer vendors) represent specialist depth.
A weighted scoring model assigns higher value to capabilities requiring greater technical depth, producing a single maturity score per vendor.
Feature Granuality Model
At the outset, we aimed to produce an analysis that is both strategic and practical. It needs to be useful to all IT leaders, regardless of how familiar they are with a given product domain.
In doing so, we gave consideration to how products are compared against one another.
Comparison at a superficial level is too shallow and doesn't give insight as to differentiation between products. At the same time, diving into technical minutiae can often mean losing focus of how products are meaningfully differnt.
As such, we conduct our evaluation at what we call, Level 2: The Functional Group.
In doing so, we can consistently assess whether a product's capabilities are more or less likely to help IT leaders achieve their desired outcomes.
| Domain | Level 1 The Module |
Level 2 The Functional Group |
Level 3 The Micro-Feature |
|---|---|---|---|
| Grocery | Fruit | Banana | Sold in bunches of 5 |
| Automotive | Car | Wheels | 5 spokes, 5 lug nuts |
| Education | Course | Mathematics | Weekly problem sets |
| Healthcare | Clinic | GP Consultations | 15 Minute Standard Appointment |
Disclaimers
Where commercial relationships exist, we apply the same evaluation criteria we use for all technologies, including tools we do not resell. We recognise the importance of independence in this research, and do not let commercial relationships affect our framework.
Findings reflect our professional judgement at the time of publication, based on the data available to us. Product capabilities and roadmaps change, so organisations should treat this report as a guide to practical decision making, not as a substitute for their own due diligence.
If you have identified errors in this report, or wish to have another product assessed, please contact our team.
Contact our team