Streamline ISO Consultants

  • Home
  • Security & AI
    • ISO 27001 Information Security
    • ISO 42001 AI Management
    • Cyber & Information Security Advisory
    • Essential Eight
    • SOC 2
    • TISAX
  • ISO Consulting Services
    • ISO Consultants Australia
    • ISO 9001 for US Companies
    • ISO Mentoring
    • Independent ISO Internal Audit Services Australia (Clause 9.2)
    • ISO Gap Analysis Audits: Know Where You Stand Before Stage 1
    • ISO Certification Auditors
    • ISO System Development
    • ISO Management System Maintenance & Ongoing Support
  • ISO Standards
    • ISO 9001 Quality Management
    • ISO 45001 Occupational Health and Safety
    • ISO 14001 Environmental Management
    • ISO 17025 Testing and Calibration
    • HACCP Food Safety
    • ISO 19443 Nuclear Supply Chain
  • Resources
    • All Articles
    • ISO Clause Guides
    • Quality Quotes
  • About
    • ISO FAQs
    • Quality Policy
    • Client Testimonials
    • ISO 9001 Certificate
  • Contact
    • Business Info
    • Privacy Policy

By Streamline ISO Consultants

Cyber Security Awareness Training: What Clause 7.3 Requires (and the Best Free Resources)

Ask most people what cyber security looks like and they’ll describe technology: firewalls, antivirus, backups, MFA. All necessary, and all bypassed daily by attacks that target people instead of systems. The overwhelming majority of successful breaches start with a human decision: a click on a convincing email, a password reused at home, a voice on the phone that sounded exactly like the boss.

That’s why awareness isn’t a nice-to-have in a modern management system. It’s a named, auditable requirement (clause 7.3 in both ISO 27001 and ISO 42001), and it’s one of the cheapest, highest-return security controls available to any business. This article covers how the threat landscape has shifted, what clause 7.3 actually asks of you, and two genuinely free resources, KnowBe4’s CAPY program and the Australian Government’s cyber.gov.au Learn the Basics hub, that let you build real awareness across your team without spending a dollar.

The threats have evolved. Has your team?

A decade ago, security awareness meant spotting typo-ridden emails from foreign princes. That era is over. As KnowBe4’s Anna Collard outlined in a recent World Social Media Day piece, today’s social engineering is targeted, multi-layered and increasingly AI-driven:

  • OSINT and oversharing. Viral social media trends (your first car, your childhood pet, your kids’ school) are open-source intelligence goldmines. AI lets attackers mine this data at scale and use it to guess security questions or build hyper-credible lures.
  • Hyper-personalised spear phishing. Attackers scrape LinkedIn, Instagram and public comments to map company hierarchies and personal relationships, then craft business email compromise attacks that reference real projects, real colleagues and real events.
  • AI voice cloning and deepfakes. A few seconds of video posted publicly is enough to clone a voice. Impersonation scams now target not just finance teams, but employees’ own families.

Notice what these have in common: none of them are stopped by your office firewall. They exploit the personal digital lives of your people, which means the traditional line between “work security” and “home security” has effectively dissolved. If your team members are easy targets at home, your business is an easy target full stop. This is the same boundary problem we see with ungoverned AI tools in the workplace: the risk walks in and out the door with your people.

Information security and AI management consulting
Clause 7.3, Awareness, is a named requirement in both ISO 27001 and ISO 42001, covering everyone working under an organisation’s control, not just employees.

Awareness is a certification requirement, not a poster in the lunchroom

Both ISO 27001 (information security) and ISO 42001 (AI management) contain an identical-numbered requirement: clause 7.3, Awareness. In plain English, everyone working under your control must be aware of three things:

  1. The policy: your information security policy (27001) or AI policy (42001);
  2. Their contribution: how their day-to-day work makes the management system effective, and the benefits of doing security well;
  3. The consequences: what it means for the business (and for them) when the rules aren’t followed.

Two words in that requirement do a lot of work. It applies to persons doing work under the organisation’s control, not just employees, but contractors, casuals and anyone else inside your systems. And it demands awareness, not attendance: a certification auditor won’t just check that a training record exists, they’ll ask your receptionist what they’d do with a suspicious email. If the answer is a blank look, a signed induction form won’t save you. We cover how auditors test this, and the rest of the mandatory clauses, in our ISO 27001 requirements checklist.

The good news: clause 7.3 doesn’t mandate expensive training platforms. It mandates an outcome. Which is exactly where free, high-quality resources earn their place in your system.

Free resource #1: KnowBe4 CAPY (awareness that follows people home)

KnowBe4 is the world’s largest security awareness training provider, and CAPY (Cyber Awareness Program for You) is its free community offering: a hub of bite-sized, interactive lessons designed for individuals and families rather than corporate LMS platforms. No logins, no fees, no sales funnel. Most lessons run under four minutes.

CAPY is organised into three paths:

  • Capy’s Cub Corner (kids and teens): games and short lessons on spotting phishing, password basics and safe browsing, plus content for older kids on cyberbullying, AI safety and sextortion;
  • The Capy-bility Hub (adults): home network security, social media privacy, phishing and scam recognition, mobile device safety and building a family safety plan;
  • Capy’s Golden Circle (seniors): clear guides on the scams that disproportionately target older Australians: grandparent scams, identity theft, imposter fraud and AI-generated cons.

Why does a family-oriented resource belong in a business management system? Because of everything in the first section of this article. Your staff member who learns to lock down their social media privacy at home is the same person who won’t leak the OSINT that powers a spear-phishing attack on your business. KnowBe4 frames it as “a lifestyle, not a corporate chore”. Offering CAPY to your team is also simply a good employee benefit: you’re helping protect their kids and their parents, not just your data.

Free resource #2: cyber.gov.au Learn the Basics (the Australian baseline)

The Australian Cyber Security Centre’s Learn the Basics hub is the definitive free Australian resource for personal and small-business cyber hygiene. It covers the fundamentals every person in your business should be able to recite: keeping devices updated, setting up regular backups, turning on multi-factor authentication, using passphrases instead of passwords, and recognising and reporting scams.

Three features make it particularly useful for an awareness program:

  • The free alert service: sign up and the ACSC emails you when new threats emerge, with plain-English guidance on what to do. Subscribing your key staff is an awareness control that costs nothing and runs itself. (We covered this and other alert services in Staying Informed: The Alerts and Groups Worth Following.)
  • A downloadable cyber security toolkit: ready-made material for toolbox talks and inductions;
  • Translated resources: the same advice in community languages, which matters for genuinely reaching a diverse workforce (remember: clause 7.3 requires awareness, not English comprehension).

Learn the Basics is one part of the broader cyber.gov.au platform. If you haven’t seen our full walkthrough of its protect, report and recover resources, read Cyber.gov.au: How to Protect, Report and Recover from Cyber Threats.

Turning free resources into audit-ready evidence

Here’s how we build these into a clause 7.3 awareness program that stands up at certification:

  1. Induction: every new starter (employee or contractor) reads your security/AI policy and completes the cyber.gov.au basics plus two or three CAPY modules relevant to their role. Record the date.
  2. Ongoing rhythm: a short awareness item in each team meeting or a quarterly micro-lesson. Rotate topics: phishing, passphrases, MFA, safe AI use, social media privacy.
  3. Alerts as triggers: when an ACSC alert lands that’s relevant to your business, forward it with a one-line “here’s what this means for us”. That’s live, documented awareness activity.
  4. Test the outcome: periodically ask staff the three clause 7.3 questions (policy, contribution, consequences) in internal audits. If answers are shaky, that’s a finding to fix before the certification body finds it.
  5. Keep the records: a simple register of who completed what, when. Evidence of a working awareness program is one of the easiest wins in a stage 1 or stage 2 audit.

The same program does double duty if you’re pursuing (or already hold) ISO 42001. Extend the topic rotation to cover your AI policy, acceptable AI use and the risks of feeding company data into unapproved tools, and clause 7.3 of your AI management system is covered by the same mechanism.

The bottom line

Technology controls stop the attacks your people never see. Awareness stops the ones engineered specifically to get past the technology. And under ISO 27001 and ISO 42001, building that awareness isn’t optional, it’s clause 7.3. With CAPY and cyber.gov.au, the content problem is solved for free; what’s left is the system: induction, rhythm, records and testing.

That system part is what we do. Whether you want us to design your awareness program as part of a full ISO 27001 certification project, or you’re building your own system (with or without AI) and want an experienced auditor to review and mentor as you go, talk to us. Your system is built to certify first time.

General guidance only. This article is general information, not legal, financial, safety or compliance advice, and it does not take account of your specific circumstances. Streamline ISO Consultants are ISO management-system consultants, not lawyers or licensed advisers. Standards, laws and regulator guidance change, and details were correct only at the time of writing. Always seek professional advice before acting. See our full Disclaimer.

Stay in the Loop

Get an email when we post an article. Your email address will not be used for marketing, and you can unsubscribe at any time.

We handle your details in line with our privacy policy.

More ISO Certification Information

  • ISO Frequently Asked Questions
    Frequently Asked Questions: ISO FAQs
  • ISO 45001 workplace safety inspection
    ISO 45001 Consulting, Safety Audits and Mentoring
  • ISO 14001 environmental management
    ISO 14001 Consulting, Environmental Audits and Mentoring
  • Consultant guiding a business owner through their ISO management system at a laptop
    ISO Mentoring: Expert Guidance for DIY ISO Systems
  • ISO 27001 information security risk analysis
    ISO 27001 Consulting, Internal Audits & Mentoring
  • ISO certification bodies in Australia
    How to Choose an ISO Certification Body in Australia
  • Tilt-shift miniature naval shipyard inspection bay with a submarine hull section on keel blocks and workers in hi-vis checking tagged components in a parts quarantine area
    ISO 19443: The Nuclear Supply Chain Standard, and…
  • Tilt-shift miniature of an AI data centre and microchip: AI tools and ISO 42001
    ISO 42001 AI Management Consulting, Audits & Mentoring
  • Tilt-shift miniature of a collapsed bridge with engineers at a drawing board tracing the failure back to the design
    ISO 9001 Clause 8.3: Design Inputs, Outputs, Review,…

Filed Under: Articles Tagged With: #informationsecurity, #iso27001, #iso42001

Quick Information Request

Brisbane ISO Consultants

Level 14, 167 Eagle St
Brisbane Queensland 4000
Phone: 07 3667 8280
Email: hello@streamline.business

Sydney ISO Consultants

Level 5, 20 Bond Street,
Sydney NSW 2000
Phone: 02 8315 7780
Email: hello@streamline.business

Melbourne ISO Consultants

Level 8, 350 Collins Street
Melbourne, Victoria 3000
Phone: 03 9034 3990
Email: hello@streamline.business

Client and partner logos

KEY ISO ARTICLES

Articles, Deep Dives & More
Frequently Asked Questions
Quality Quotes
Funding Grants for ISO Certification
ISO Consultants
Strategic Planning - Mystical Art?
ISO Certification Auditors
How to get ISO 9001 Certification
ISO Certification Cost
How to tell if your ISO Cert is fake
4-year-olds and Root Cause Analysis
Fast ISO 9001 Certification
The Ultimate Guide to ISO 9001 Audit
ISO 45001 Certification Cost
Who's Interested in a Party?
How to use Smartsheet for ISO
Smarter Quality Objectives
Local Government QMS
Quality Assurance, Quality Control or QMS
ISO Certification in Sydney
ISO Certification in Melbourne
ISO Certification in Brisbane
SAI Global Consultant Affiliate Program

QUICKLINKS TO ISO INFO

ISO Consultants Australia
ISO Mentoring
ISO 27001 Certification Cost
ISO 9001 Quality Management
ISO 45001 Health & Safety
ISO 14001 Environment
ISO 17025 Testing & Calibration
ISO 27001 Information Security
ISO 42001 AI Management
ISO 22000 HACCP Food Safety

Search

FOLLOW OR GET IN TOUCH

linkedinmail
Smartsheet Platinum Partner

Copyright © 2026 Streamline · Log in

Privacy Policy · Terms of Use · Disclaimer

Call us Enquire