Turn your people into your strongest security control. This security awareness training course gives every employee practical, memorable guidance on protecting people, information and assets, spotting suspicious approaches and reporting concerns, built around your own policies and delivered by security practitioners rather than a generic video library.
What your organisation gains
- A workforce that understands its role in security and reports concerns early.
- Fewer avoidable incidents, from tailgating and misdirected emails to phishing and online approaches.
- Evidence of annual training for PSPF Release 2026 and similar obligations.
- Content your own team can reuse for induction and annual refreshers.
Why train with Agilient
Taught by practitioners
Every Agilient consultant has at least 20 years of experience, typically as security managers within large organisations, and has dealt first hand with the issues the course covers.
Built for your organisation
Content, examples and scenarios are shaped around your sites, policies and incident history, not an off-the-shelf syllabus that dates quickly.
Active learning
Participants work through case studies and carry out the activities themselves, so the skills stick after the day.
Designed for you to own
Train-the-trainer options and a strategy for moving the course into your own online learning mean the capability stays in-house.
Why security awareness training matters now
People remain the most targeted part of any organisation. The Australian Signals Directorate’s Annual Cyber Threat Report 2024-25 recorded more than 84,700 cybercrime reports, one every six minutes, and recorded phishing in 60 per cent of incidents reported to its Australian Cyber Security Centre. The average self-reported cost of a cybercrime was $56,571 for a small business, $97,166 for a medium business and $202,691 for a large business.
Simple mistakes matter as much as attacks. The Office of the Australian Information Commissioner’s July to December 2024 report found that sending personal information to the wrong email recipient was the leading human error behind notifiable data breaches.
For government, training is a requirement. PSPF Release 2026 requires security awareness training for personnel, including contractors, at engagement and annually thereafter, and a new requirement from 01/07/2026 adds training on foreign interference, espionage, and cultivation and exploitation by foreign powers. Critical infrastructure owners and defence industry members face similar expectations.
What the course covers
- Security and your role What security means in your organisation, who is responsible for what, and why every role matters.
- The current threat picture Crime, terrorism, espionage, foreign interference and cyber threats, explained in plain terms.
- Physical security Access control, tailgating, visitor management, lock up routines and the layered approach to protecting sites.
- Information security Handling and classifying information, clear desk and clear screen practices, and avoiding misdirected emails.
- Social engineering and online approaches Phishing, phone and in-person pretexting, and suspicious approaches through professional networking sites.
- Cyber hygiene basics Passphrases, multi-factor authentication, safe use of devices and knowing when to call IT.
- Travel security Protecting people, devices and information when travelling for work, including overseas.
- Reporting incidents and concerns What to report, how to report it and why good reports improve security for everyone.
What participants will be able to do
- Explain their personal role in the organisation’s security culture.
- Apply physical, personnel and information security procedures in daily work.
- Recognise phishing, pretexting and suspicious online or in-person approaches.
- Protect devices and information when working remotely or travelling.
- Report incidents and concerns promptly and with the right information.
Who should attend
- All staff, including executives
- Contractors and labour hire workers
- Volunteers
- New starters as part of induction
Choose the level and format that suits you
The course can be run at more than one level, so governance and day-to-day practice are covered together.
- Executive briefing. A short session for executives and boards on accountability, obligations, risk appetite and what good looks like.
- Manager and practitioner workshop. The full course, with case studies and practical exercises for the people who manage the risk day to day.
- Train-the-trainer. Preparing your own trainers to deliver the course inside your organisation, with the materials and guidance to do it well.
- In person or online. Delivered at your premises, at a venue you choose, or live online through Microsoft Teams and other platforms.
Bringing the capability in-house, with Agilient as your partner
More organisations want to build and keep this capability within their own teams. Agilient supports that. After delivering the course, Agilient can train your trainers, help your learning and development team plan the conversion of the course into an online module, and stay involved as an adviser, so your people deliver it with the benefit of Agilient’s hands-on experience.
How it works
- Get in touch. Tell us which course you are interested in, roughly how many people, where and when.
- Scoping conversation. An Agilient consultant discusses your people, sites, policies and recent incidents, and agrees the level, format and duration with you.
- Tailored content. Case studies, scenarios and exercises are built around your own environment and procedures.
- Delivery and handover. The course is delivered in person or online. Agilient can then train your trainers, support an online version, or review related procedures, controls or risk assessments.
Related Agilient services and resources
- Security awareness training programs
- Situational Awareness and Active Armed Offender Training
- Why security awareness training is essential for infrastructure staff
- PSPF Release 2026: what has changed
- Protective security consulting
Frequently asked questions
How often should staff complete security awareness training?
PSPF Release 2026 requires Commonwealth entities to provide security awareness training at engagement and annually thereafter. Agilient recommends the same rhythm for other organisations: training at induction, an annual refresher and short briefings when the threat picture changes.
Is this a cyber security course?
It covers essential cyber hygiene, but it is a broader protective security course. It also covers physical security, personnel security, information handling, social engineering, travel and incident reporting.
Can the course be adapted for our own online learning system?
Yes. Agilient delivers the course in person first and can then adapt the content so the organisation can use it for induction and annual refreshers.
How long is the course?
Duration is agreed with you. Courses range from a two-hour briefing to a one, one and a half or two-day program, depending on your audience, risks and how much practical work you want included.
Can the course be delivered online?
Yes. Agilient delivers courses in person at your premises and live online through Microsoft Teams and other platforms, and can combine the two for teams spread across several locations.
Can our own team deliver this training in future?
Yes. Agilient runs train-the-trainer sessions so your people can deliver the course themselves, and can work with your learning and development team on a strategy for converting the course into an online module for induction and refreshers.
Can individuals book a place on this course?
No. Agilient runs its training in-house for organisations rather than as public courses, so individual places are not available. Group size, timing and content are agreed with each organisation.
Is this an accredited course?
No, and that is deliberate. It is not a nationally recognised qualification that follows a fixed syllabus, which can date quickly. It is designed and delivered by practitioners who have dealt with these issues first hand, tailored to your organisation, and built on case studies, active learning and practical exercises.
Ready to build this capability in your organisation?
Tell us what you need. Agilient will recommend the right level, format and duration, and tailor the course to your organisation.
Other in-house security training courses
- Security Risk Assessment and Management Course
- Security Threat Assessment Training
- Insider Threat Training
- Customer Aggression Training for Managers
- De-escalation Training for Customer-Facing Staff
- Managing Physical Aggression in the Workplace
- Patient De-escalation Training for Healthcare Workers
- Occupational Violence and Aggression (OVA) Training for Healthcare
- Crisis Management Team Training and Tabletop Exercises
- Situational Awareness and Active Armed Offender Training
- Physical Restraint and Personal Protection Training
- CPTED Training: Crime Prevention Through Environmental Design
Sources
- Annual Cyber Threat Report 2024-2025, Australian Signals Directorate
- Notifiable Data Breaches Report July to December 2024, OAIC
- PSPF Release 2026 List of Requirements, Department of Home Affairs
- Think Before You Link, ASIO
Last updated 29/09/2026.