84% of security breaches involve a human element — an employee who clicked a link, reused a password, or transferred funds to a fraudulent account. That figure, from the Verizon 2024 Data Breach Investigations Report, hasn't changed significantly in a decade. The technology gets harder to crack; the people remain the variable.
For NZ businesses, cybersecurity awareness training is no longer optional. The NCSC's minimum cyber security standards, introduced for government agencies in 2025, set a baseline that is rapidly becoming the expected norm across all sectors. Here's what a programme that actually meets that bar looks like.
What the NCSC minimum standards require
The NCSC's minimum cyber security standards include a specific requirement for staff security awareness. Covered organisations must ensure staff are trained to recognise and respond to phishing, social engineering, and other human-targeted attacks. A compliance tick-box video watched once a year does not meet this standard.
The key words in the framework are *ongoing* and *role-based*. Awareness training must be:
- Delivered at least annually (quarterly is better practice)
- Tailored to the specific risks of different roles — finance staff need different training than warehouse staff
- Tested, not just delivered — passive training without retention testing shows low ROI
- Documented, so you can evidence compliance if audited
What effective training actually covers
The most common gap in NZ business training programmes is specificity. Generic "cybersecurity hygiene" videos cover broad concepts that don't match the threats employees actually face. An effective programme covers:
Phishing recognition — Modern phishing is personalised. Business Email Compromise (BEC) attacks in NZ impersonate CEOs, suppliers, and IRD. Training should include real examples of NZ-specific lures, not American bank phishing screenshots.
Social engineering — Vishing (voice phishing), pretexting, and physical tailgating are underrepresented in most training. Staff who would spot an obvious email link won't hesitate to hold a door open for someone carrying a box.
Password and MFA hygiene — Why password reuse is dangerous, what a credential stuffing attack looks like, and how to set up an authenticator app correctly.
Reporting procedures — What to do when you suspect a phishing email. Who to call, how to report it in your ticketing system, and critically — that reporting is encouraged and won't result in blame.
Simulation vs. passive training
Passive training (videos, slides, PDFs) builds awareness. Simulated phishing builds behaviour. The research consistently shows that employees who receive training AND experience a simulated phishing attempt are significantly more likely to report real phishing in the future.
CERT NZ recommends combining educational content with regular simulated phishing exercises as part of a layered security approach. The simulation isn't a gotcha — it's a measurement tool. If 40% of your staff click a simulated credential-harvesting link, you have a specific, measurable problem to address.
Key elements of a well-run simulation programme:
- Monthly or quarterly simulations, not just annual
- Varied templates — invoice phishing, delivery notifications, password reset requests, HR policy updates
- Immediate teachable moment for anyone who clicks
- Trend reporting so you can track improvement over time
Documentation and evidence
If you're subject to a security audit, a Privacy Act complaint investigation, or a contract requiring you to demonstrate security controls, you need to be able to show that training happened. That means:
- A record of who completed which training and when
- Sign-off records for policy acknowledgements
- Simulation results showing click rates over time
- Evidence that failed simulations triggered follow-up training
A spreadsheet tracking completion is better than nothing. A proper system that tracks completion, generates certificates, and logs simulation results is what auditors and cyber insurers increasingly want to see.
What good documentation enables
Beyond compliance, documented training records open specific commercial doors. Cyber insurers in NZ are now asking for evidence of staff training as part of the underwriting process. Businesses that can show a structured, ongoing programme — with completion tracking and simulation results — qualify for better premiums and fewer exclusions.
See our post on phishing training for employees for a detailed breakdown of what each role group needs to cover.
What to do next
If your current programme is a once-a-year video, here's a realistic path to compliance:
- Audit what you have — What training exists? Who's completed it? When? Is there a record?
- Identify role groups — Finance, operations, IT, and leadership have different risk profiles and need different content
- Add simulation — Even quarterly simulated phishing adds measurable behavioural change
- Document everything — Completion records, dates, results
- Review annually at minimum — Threat templates change; training content should too
SecureAZ provides cybersecurity awareness training built for NZ and Australian businesses — with role-based modules, phishing simulations, and automatic completion tracking. Start a free trial to see how your current programme compares.