Cyber awareness training your team will actually finish
Six short modules on the scams genuinely reaching Australian businesses — invoice fraud, email compromise, ATO impersonation, ransomware. About 45 minutes, with a dated certificate at the end.
What you’ll cover
Six short modules on the scams actually reaching Australian businesses. Each one has a real scenario, the red flags to look for, and a few questions to check it landed. About 45 minutes end to end, and you can stop and come back.
- 1
Invoice fraud and payment redirection
8 min
- 2
Business email compromise
8 min
- 3
Phishing and government impersonation
7 min
- 4
Passwords, passphrases and MFA
7 min
- 5
Ransomware and everyday device habits
7 min
- 6
Data breaches and what Australian law expects
8 min
No signup to start. Your progress stays in this browser.
Built around what's actually costing Australian businesses money
Not a generic overseas course with the spelling changed. Every module is grounded in ACSC, ATO and OAIC guidance, and every scenario is one we've seen play out here.
Invoice fraud and payment redirection
This is the one that empties bank accounts. An attacker doesn't need to break anything — they just need your accounts team to pay a real invoice into the wrong account. The money is usually gone before anyone notices, and it is rarely recoverable.
Business email compromise
Once someone else can read your mailbox, they can see every deal, every invoice and every relationship you have — and they can write as you. Most victims have no idea it happened until a customer or supplier tells them.
Phishing and government impersonation
Australians get impersonated by the same handful of trusted brands — the ATO, myGov, Australia Post, the major banks and the big telcos. They work because everyone genuinely deals with those organisations, so the message is plausible for almost anyone who receives it.
Passwords, passphrases and MFA
Reused passwords are the reason one unrelated breach turns into a problem at work. Multi-factor authentication is the single most effective control against account takeover — but only if nobody can talk you into approving it.
Ransomware and everyday device habits
Ransomware stops a business trading. Attackers now steal the data first and threaten to publish it, so paying a ransom doesn't undo the breach — and backups you've never tested tend to fail on the day you need them.
Data breaches and what Australian law expects
If personal information is exposed, the business may have legal obligations under the Privacy Act — and the clock starts when someone becomes aware of it, not when management decides it's serious. Staff who know to speak up early are the reason those deadlines get met.
Guidance referenced throughout is published by the Australian Cyber Security Centre at cyber.gov.au, the ATO, and the OAIC. Nexcentric is not affiliated with or endorsed by any of them.
About the training
What it covers, what the certificate is worth, and what happens if you want it across the whole team.
Is this really free?
Yes. All six modules and the quiz are free and you don't need to sign up to start — your progress stays in your own browser. We only ask for your name and email at the end, when you want the certificate issued, because a certificate with no name on it isn't much use to anyone.
How long does it take?
About 45 minutes end to end across six modules. You don't have to do it in one sitting — progress is saved in your browser, so you can close the tab and pick up where you left off on the same device.
Does the certificate satisfy our insurer or a tender requirement?
It records that a named person completed awareness training on a given date and what they scored, which is usually what's being asked for. It is not an accreditation and it isn't a formal assessment against a standard. If you need a completion register across your whole team, or evidence mapped to a specific framework, that's something we set up properly rather than something a free tool can produce.
Can I run this across my whole team?
Each person can take it themselves and get their own certificate, which works fine for a small team. Once you need to know who has and hasn't completed it, chase the stragglers, and hold a register you can hand to an auditor, you want it managed — that's a conversation worth having, and it's usually cheaper than people expect.
Why is the training Australia-specific?
Because the scams are. Australian businesses get impersonated by the ATO, myGov, Australia Post and the major banks, and the obligations that follow a data breach come from the Privacy Act and the Notifiable Data Breaches scheme rather than GDPR. Generic overseas training teaches people to look for the wrong things and quotes the wrong deadlines.
What happens if I fail?
Nothing bad. You need 80% overall for a certificate. If you're under it, the results screen shows exactly which modules let you down and lets you review and retake just those — the questions you already got right are kept.
One trained person isn’t a control
Attackers only need the one person who didn’t do it. Book a free 30-minute review and we’ll show you how to get this across your whole team, keep a register you can hand to an insurer, and back it with controls that don’t rely on anyone being alert on the day.