Cheddar IT
Book a call1300 757 632
Security Awareness Training

Phishing training your team won't game.

Knowledge assessments, simulated attacks, interactive modules, videos and materials — customisable to your brand. Reporting that drives real behavioural change.

Customisable · Interactive
Customisable · Interactive
Capabilities

What's included

Customisable content
Engaging, interactive modules built around your brand, tone and industry. Scenarios feel like real work — not a generic tick-box compliance video.
Realistic phishing simulations
A library of hundreds of templates ranging from obvious to near-perfect — plus BEC, smishing (SMS), QR-code and vishing (voice) scenarios that mirror current real-world attacks.
Directory sync
End-user sync via Active Directory, Entra ID or SCIM. New starters auto-enrol; leavers are removed. Groups drive content targeting by role, risk or department.
Risk scoring per user
Each person gets a risk score based on clicks, reports, training completion and recency. High-risk users trigger remedial content automatically.
Compliance modules
Mapped content for Essential Eight, ISO 27001, PCI DSS, HIPAA-equivalent, Privacy Act and industry-specific codes — with completion evidence for auditors.
Real-time reporting
Exportable dashboards for leaders, board packs and auditors. Trend analysis, click rates, report rates and the metrics that actually predict breach risk.
Every engagement includes
Knowledge assessments
Simulated phishing (email, SMS, QR, voice)
Interactive training modules
Security awareness videos
Just-in-time micro-learning
Active Directory / Entra ID / SCIM sync
Per-user risk scoring
Automatic remedial training
Compliance library (E8, ISO, PCI, Privacy Act)
Completion certificates
Random phishing scheduling
Brand-customised materials
Service levels

The SLAs, on paper

No weasel-words. These are the response and resolution commitments we write into the contract.

Classification
Response
Resolution
Campaign launch
2 hours
Next business day
Incident-triggered training
1 hour
Same day
Compliance report
4 hours
Monthly
Auditor evidence pack
4 hours
2 business days
Content customisation
Same day
1 week
FAQ

What clients ask before signing

Yes. The platform is built around customisable, interactive content — multiple opportunities to incorporate your brand and tailor your message.
It spreads out and randomises distribution, which reduces the chance employees figure out — and discuss — the simulated attacks, preserving the integrity of your data.
Yes. Admins can leverage on-premise Active Directory and cloud Azure AD to automatically populate and maintain users and groups.
A brief, non-punitive teachable moment immediately, then a follow-up micro-module in their next scheduled training slot. Repeat clickers get targeted remediation rather than a shame email to their manager.
Yes — the core library covers the major languages we see across Australian and New Zealand workforces, and we can commission bespoke translations for specific modules.
Yes. Completion records, phishing results, risk scores and content mappings export as audit-ready packs. We've walked ISO 27001, SOC 2 and APRA CPS 234 auditors through them.
Next step

30 minutes.
One straight answer.

Book a discovery call with one of our principal engineers. We'll look at what's actually breaking, and tell you whether we're the right fit — straight up.