Executive Summary
Cyber threats don’t wait, and neither should security awareness training. IA Group, a leading provider of workforce solutions across Australia, recognised the need to move beyond generic security training and build a security-conscious workforce capable of identifying and responding to modern cyber threats. Partnering with Morrisec for the second year in a row, IA Group sought a customised security awareness training program tailored to the latest threat landscape, their industry-specific risks, and internal security challenges.
Unlike traditional, static security awareness programs, Morrisec delivered an interactive, gamified, and highly engaging training experience, designed to cater to various learning styles. By focusing on real-world attack demonstrations, hands-on exercises, and scenario-based learning, IA Group saw a noticeable shift in security awareness and proactive employee behaviour. This case study explores how IA Group’s security culture was strengthened through targeted, practical, and engaging security training.
We engaged Morrisec for our annual Cyber Security training because of their expert knowledge, hands on approach, and up to date insights, ensuring our people stays ahead of emerging threats both in the business and their personal lives.
The Challenge: Moving Beyond Canned Training
Organisations often implement general security awareness training only to find that traditional, one-size-fits-all programs lack engagement and fail to drive meaningful change in employee behaviour. Challenges include:
Lack of Relevance
Generic training does not address specific threats facing the organisation’s industry and specific business.
Low Engagement
Employees often find the training boring and uninspiring.
Missed Learning Opportunities
Traditional methods do not cater to different learning styles, leaving some employees disengaged and disinterested.
Limited Real-World Impact
Training lacks practical demonstrations of real cyber threats, reducing retention and application of knowledge.
IA Group required a security awareness program that would captivate employees, address specific organisational risks, and drive long-term behavioural change.
The Solution: A Bespoke, Interactive Approach to Security Awareness
Morrisec worked closely with IA Group to design a custom security awareness training program, ensuring that every aspect was relevant, engaging, and impactful. The key differentiators of the program included:
- Threat-Led Training: Morrisec analysed the current cyber threat landscape, aligning training content with global, industry-specific, and company-specific threats.
- Gamification & Hands-On Learning: Training incorporated interactive challenges, real-world attack demonstrations, and role-based scenarios to ensure high engagement.
- Tailored Learning Modalities: The program was designed to suit all learning preferences, incorporating reading, writing, interactive participation, and presentations.
- Real Attack Demonstrations: This year’s training featured live demonstrations of attacks, including a Man-in-the-Middle (MitM) attack, to show employees exactly how cyber threats operate in real time.
- Security Culture Reinforcement: Beyond technical knowledge, the training emphasised critical thinking, proactive security habits, and an open security dialogue within IA Group.
The Result: A Stronger Security Culture & Employee Engagement
One of the most effective exercises we ran in 2024 was having staff craft their own phishing emails against a volunteer. By thinking like a threat actor, they saw firsthand how easy it is to gather information from social media and craft highly convincing attacks. This hands-on approach transformed their understanding of phishing and made the lessons stick.
Following the Morrisec-led training, IA Group experienced tangible improvements in security awareness and engagement, including:
- Increased Phishing Awareness & Reporting – Employees became more vigilant and proactive in identifying and reporting phishing emails.
- Improved Incident Response Mindset – The training fostered confidence in recognising and responding to security threats, reducing risky behaviours.
- High Engagement & Positive Feedback – Employees actively participated, with many sharing that the interactive nature of the training helped them better understand security concepts.
- Sustained Behavioural Changes – IA Group saw a lasting impact, with employees continuing to discuss security best practices long after the training concluded.
Why Morrisec’s Security Awareness Training Stands Out
As a trainer, my goal is to ensure every session is engaging and directly applicable to the organisation’s security challenges. We don’t just present information—we simulate real threats, encourage discussion, and take security out of the shadows and make it a tangible thing. Seeing participants actively engage, ask questions, and apply what they’ve learned in their daily work is the most rewarding part of delivering this type of training.
Most security awareness training is commoditised – generic, one-size-fits-all content that fails to engage or address the specific risks your organisation faces. At Morrisec, we take a different approach.
- Not One-Size-Fits-All – Each training program is tailored to the organisation’s industry, threat landscape, and unique risks.
- Gamified & Interactive – Engaging exercises ensure employees stay involved and retain key lessons.
- Multi-Modal Learning – Training is designed for all learning preferences, ensuring maximum impact.
- Delivered by Educators – Our trainers have a strong teaching background, having experience teaching at high schools, TAFE, and universities, making security accessible to all audiences.
- Proven Success – Organisations like IA Group return year after year because the training works.
What stood out the most from the training was the discussion and demonstration of various hacking and scamming methods. It highlighted how easily individuals can obtain or download the necessary software and equipment to carry our malicious acts. This increased our awareness of how to protect ourselves.
Looking to Build a Security-Conscious Workforce?
If your organisation is struggling to make security awareness engaging and impactful, Morrisec’s custom security awareness training can help. Whether you’re just starting your security journey or looking to improve your existing training, we provide tailored, effective solutions that drive real change.
Contact us today to discuss your security awareness needs.
0 Comments