
Cyber Security Awareness Training
Practical Cyber Security Training for Defence Industry and Critical Infrastructure
People remain one of the most targeted attack vectors in any organisation. Effective cyber security awareness training reduces human risk by equipping staff with the knowledge and confidence to recognise, respond to and report cyber threats before they become security incidents.
Calexi delivers practical, instructor-led cyber security awareness training for Defence industry, critical infrastructure and other regulated organisations across Australia. Our training is tailored to your operational environment and designed to support your organisation’s security, contractual and regulatory obligations.
Whether you require annual workforce awareness training, privileged user education, board and executive briefings or customised security workshops, our courses focus on practical skills that can be applied immediately.
Annual Cyber Security Awareness Training
Annual cyber security awareness training helps employees recognise and respond to today’s most common cyber threats while reinforcing a strong organisational security culture.
Topics include:
- Phishing and business email compromise
- Social engineering
- Password security and multi-factor authentication
- Safe web browsing
- Ransomware
- Data handling and information protection
- Mobile device security
- Remote and hybrid working
- Removable media
- Incident identification and reporting


Privileged User Security Training
Users with elevated privileges are among the highest-value targets for cyber attackers. This course provides administrators and privileged users with the knowledge required to securely manage critical systems and reduce administrative risk.
Training covers:
- Administrative account security
- Privileged Access Management (PAM)
- Secure remote administration
- Password and multi-factor authentication best practice
- Administrative workstation security
- Common attack techniques targeting privileged accounts
- Logging, auditing and accountability
- Secure configuration management
- Change management
- Incident response responsibilities
Board and Executive Cyber Awareness
Directors and executives play a critical role in managing cyber risk and organisational resilience.
This course provides practical guidance on governance, strategic risk and executive decision making during cyber security incidents.
Topics include:
- The current cyber threat landscape
- Governance responsibilities
- Cyber risk as business risk
- Essential Eight and organisational maturity
- Supply chain security
- Security of Critical Infrastructure (SOCI) obligations
- Defence Industry Security Program (DISP)
- Incident response and executive decision making
- Business resilience
- Regulatory and contractual obligations


Custom Cyber Security Training
Every organisation faces different threats, technologies and regulatory obligations.
Calexi develops customised cyber security training aligned to your systems, policies, operational environment and business objectives.
Examples include:
- Microsoft 365 security
- Secure software development
- Defence industry cyber security
- Incident response
- Secure remote working
- Artificial Intelligence security
- Social engineering
- Insider threats
- Secure system administration
- Organisation-specific policies and procedures
Supporting Regulatory Requirements
Our cyber security awareness programs are designed to support organisations in meeting the security awareness and personnel education requirements of recognised security frameworks and contractual obligations, including:
- Defence Industry Security Program (DISP)
- Security of Critical Infrastructure Act (SOCI)
- Essential Eight
- ASD Information Security Manual (ISM)
- Protective Security Policy Framework (PSPF)
- ISO/IEC 27001
- NIST Cybersecurity Framework
Training can also be customised to align with your organisation’s internal security policies, customer requirements and contractual obligations.
Industries We Support
- Defence Industry
- Critical Infrastructure
- Defence Supply Chain
- Engineering
- Professional Services
- Technology organisations operating in regulated environments
Proven Capability in the Field
![A glowing digital shield symbolising Defence assurance stands at the centre, surrounded by four illuminated pillars. Each pillar features an icon representing a DISP domain: governance, physical security, personnel security, and information & cyber security. The image uses blue and teal tones with subtle circuitry patterns to convey trust, structure, and compliance.]()
DISP – Defence Industry Security Program Uplift
A Defence SME needed DISP compliance but faced limited resources and low security maturity. Calexi delivered a full uplift within 6 months, achieving Maturity Level 2, Defence approval, and cost savings all while improving security culture and posture.
![fixing the cracks in broken projects professionals reviewing where projects are broken down.]()
Ransomware Incident Response
When a ransomware attack exposed poor practices and failed backups, Calexi led the recovery, restored three months of data, implemented emergency fixes, and re-architected the ICT environment. The organisation avoided major reputational and financial loss while strengthening long-term resilience.
![critical infrastructure elements security]()
Critical Infrastructure Uplift
A transport-sector organisation faced compliance gaps and conflicting advice. Calexi identified redundant technology, leveraged existing licences, and implemented targeted improvements, saving hundreds of thousands while delivering major security and compliance uplifts — without disrupting critical operations.
Why Organisations Choose Calexi
Our instructors are experienced cyber security practitioners who work with regulated organisations every day.
Rather than delivering generic awareness presentations, we provide practical, engaging training built around current threats, operational experience and real-world scenarios.
Every course is designed to deliver measurable improvements in cyber security awareness and organisational resilience.
Our training includes:
- Developed specifically for regulated industries
- Delivered by experienced cyber security practitioners
- Australian-developed content
- Current real-world attack scenarios
- Practical demonstrations and discussions
- Customised to your organisation
- Available on-site or remotely
- Supports annual awareness programs
- Completion certificates for participants
Our objective is simple: build confident people who make better security decisions every day.
Frequently Asked Questions
Cyber security awareness training should be delivered at least annually as part of your organisation’s ongoing security program. Additional training is recommended when new cyber threats emerge, significant technology or policy changes occur, following security incidents, or when staff move into privileged or high-risk roles.
Regular refresher training helps reinforce secure behaviours, keeps employees informed of evolving threats and supports organisations meeting the ongoing security awareness requirements of frameworks such as the Defence Industry Security Program (DISP), the Security of Critical Infrastructure (SOCI) Act, ISO/IEC 27001 and other contractual or regulatory obligations.
Yes. Our training is designed to support organisations implementing the Essential Eight and meeting personnel security awareness obligations under frameworks including DISP, the Security of Critical Infrastructure Act (SOCI), the ASD Information Security Manual (ISM), the Protective Security Policy Framework (PSPF) and ISO/IEC 27001.
Yes. Every course can be customised to reflect your technologies, security policies, procedures, regulatory obligations and operational environment.
Yes. Participants receive a certificate of completion that can assist organisations maintaining training records for audits, contractual obligations and internal governance.
Yes. We deliver instructor-led cyber security awareness training on-site throughout Australia.
Yes. Training can be delivered remotely using secure online platforms while maintaining participant engagement and interaction.
Yes. Board and executive training focuses on governance, organisational risk, strategic decision making, regulatory responsibilities and cyber resilience rather than day-to-day user security awareness.
Course duration depends on the audience and objectives. Annual awareness training typically runs for 60 to 90 minutes, while executive workshops and customised technical courses may range from two hours to a full day.
Yes. Phishing simulations can be incorporated into awareness programs to reinforce learning, assess user behaviour and identify opportunities for further education.
Yes. We regularly develop customised training using client policies, technologies, operational scenarios and recent cyber threats relevant to your organisation.
Privileged user training is recommended and may be a regulatory requirement for system administrators, cloud administrators, network engineers, database administrators, security personnel, help desk staff with elevated access and anyone responsible for administering critical systems.
Yes. Annual refresher training helps staff remain aware of emerging cyber threats, reinforces secure behaviours and supports ongoing compliance obligations.
Yes. Attendance records, certificates and training documentation can assist organisations demonstrating that ongoing cyber security awareness activities have been implemented as part of broader governance and compliance programs.
Get In Touch
Strengthen your organisation’s first line of defence through practical cyber security awareness training designed for regulated industries.
Whether you require annual workforce awareness, privileged user education, board-level cyber security training or a customised program aligned to your business, Calexi can develop a solution that meets your operational and regulatory requirements.


