← SecureAZ Blog

Security Awareness · 8 min read · Published 10 May 2026 · Reviewed 17 August 2026

Cyber Awareness Training 2026: What NZ Businesses Are Getting Wrong

Cyber awareness 2026 looks different from five years ago. Here is what NZ businesses need to update in their programme — and where the compliance bar has moved.

Cyber awareness training in 2026 is not the same problem it was in 2021. The threat landscape has changed. Staff expectations have changed. Regulator and insurer requirements have raised the bar. And most importantly, the research on what actually changes human behaviour has matured enough that there is no longer any excuse for running a once-a-year module and calling it a programme.

This post covers what the cyber awareness challenge looks like in 2026 for NZ businesses, what has changed, and what a compliant programme actually needs to include.

---

What Has Changed Since 2021

AI-generated attacks. Phishing emails, voice clones, and deepfake video are now accessible to low-skill attackers. The visual and language cues staff were trained to spot — awkward grammar, obviously fake logos, spelling errors — are largely gone. Training needs to shift from "spot the mistakes" to "trust the process."

The supply chain threat. Attacks increasingly arrive through compromised supplier accounts, not spoofed addresses. The email looks legitimate because it is from a legitimate address — just one that belongs to a compromised supplier. This is covered in detail in the supply chain phishing guide.

Regulatory escalation. New Zealand's Cyber Security and Resilience Bill introduces civil penalties tied to risk management programmes. Cyber insurers are adding security awareness training as a condition of cover, not just a renewal question. The NCSC's minimum cyber security standards explicitly call out awareness training. "We did a training once" is no longer a defensible position.

Remote and hybrid work. The attack surface for social engineering has expanded. Home networks, personal devices, casual communication channels, and informal verification practices all create openings that a centralised office environment reduced.

What a 2026-Compliant Programme Looks Like

The NCSC, CERT NZ, and Australian Cyber Security Centre all publish guidance aligned on the same core structure. A programme that passes scrutiny includes:

Regular, short training. Twelve months of monthly 10-minute modules outperforms one annual 2-hour session. This is not a matter of preference — it is what the behaviour change research consistently shows. Spaced repetition works; block training does not.

Phishing simulations. At least quarterly. NZ-localised templates that reflect real campaigns — IRD, NZ Post, myIR, government impersonation, bank fraud. Templated simulations using US or UK lures are easier to spot and understate actual risk exposure. The detail on running an effective phishing test is in employee phishing tests for NZ.

Role-based training. Finance staff, executives, administrators, and IT staff face different threats. A one-size programme undertrains the highest-risk roles and bores everyone else. Finance staff need wire fraud and invoice fraud modules. Executives need deepfake and social engineering content.

Metrics and reporting. Click rates, completion rates, report rates, and trend over time. These need to be available to management on demand and included in the risk reporting pack for the board or senior leadership team.

Onboarding integration. Every new starter completes awareness training before or on their first day. Not in their first month. Not "when they get around to it."

The Cyber Awareness Challenge

"Cyber awareness challenge" as a concept — popularised by Department of Defense programmes in the US — is the annual or periodic knowledge-check approach to cyber security. Many NZ organisations still run this model: enrol everyone in the cyber awareness challenge each year, get completion certificates, file them for the audit.

The problem is not that the content is wrong. The problem is that a once-a-year challenge does not build the automatic responses that prevent incidents. The staff member who completed the challenge in February and clicks a phishing email in October is not protected by their certificate.

The 2026 shift is from the cyber awareness challenge model to a continuous awareness programme model. The compliance bar — as set by NZ cyber insurers, NCSC, and the emerging Cyber Security and Resilience Bill requirements — now expects both a regular training cadence and simulation evidence, not just completion certificates.

CyberSmart and Government Guidance

NCSC NZ's CyberSmart programme provides baseline guidance for NZ organisations on foundational cyber hygiene, including security awareness. For small businesses, CyberSmart is a useful starting point. For organisations accountable to regulators, insurers, or government procurement requirements, it is the floor rather than the ceiling.

The NCSC's minimum cyber security standards, which apply to organisations handling government information, are explicit about what an acceptable awareness programme includes. These standards increasingly flow through to suppliers and contractors of government agencies through procurement requirements.

What Insurers Are Looking For in 2026

NZ cyber insurer renewal questionnaires in 2026 commonly ask:

  • Do you run security awareness training? How often?
  • Do you run phishing simulations? What is your current click rate?
  • Is training mandatory for all staff, including executives?
  • Do you have documented training records available on request?
  • Have you had training-related incidents — staff clicking phishing emails — in the past 12 months?

The last question is the revealing one. Insurers are using incident history to calibrate what "reasonable" awareness training means for your organisation. An organisation with three phishing-related incidents and an annual-only training programme is likely to face a conversation about programme adequacy at renewal.

Practical Steps for a 2026-Ready Programme

  1. Move from annual to monthly training cadence
  2. Add quarterly phishing simulations with NZ-localised templates
  3. Build role-specific modules for finance, executive, and IT
  4. Wire a report phishing button into your email client
  5. Integrate awareness training into the onboarding workflow
  6. Report click rate, completion rate, and report rate to management monthly
  7. Document the programme for your insurer and any compliance audit

Start your free SecureAZ trial to build a 2026-ready cyber awareness programme with NZ-localised simulations, automated scheduling, and insurer-ready reporting.

External references: