Ask most people what cyber security looks like and they’ll describe technology: firewalls, antivirus, backups, MFA. All necessary, and all bypassed daily by attacks that target people instead of systems. The overwhelming majority of successful breaches start with a human decision: a click on a convincing email, a password reused at home, a voice on the phone that sounded exactly like the boss.
That’s why awareness isn’t a nice-to-have in a modern management system. It’s a named, auditable requirement (clause 7.3 in both ISO 27001 and ISO 42001), and it’s one of the cheapest, highest-return security controls available to any business. This article covers how the threat landscape has shifted, what clause 7.3 actually asks of you, and two genuinely free resources, KnowBe4’s CAPY program and the Australian Government’s cyber.gov.au Learn the Basics hub, that let you build real awareness across your team without spending a dollar.
The threats have evolved. Has your team?
A decade ago, security awareness meant spotting typo-ridden emails from foreign princes. That era is over. As KnowBe4’s Anna Collard outlined in a recent World Social Media Day piece, today’s social engineering is targeted, multi-layered and increasingly AI-driven:
- OSINT and oversharing. Viral social media trends (your first car, your childhood pet, your kids’ school) are open-source intelligence goldmines. AI lets attackers mine this data at scale and use it to guess security questions or build hyper-credible lures.
- Hyper-personalised spear phishing. Attackers scrape LinkedIn, Instagram and public comments to map company hierarchies and personal relationships, then craft business email compromise attacks that reference real projects, real colleagues and real events.
- AI voice cloning and deepfakes. A few seconds of video posted publicly is enough to clone a voice. Impersonation scams now target not just finance teams, but employees’ own families.
Notice what these have in common: none of them are stopped by your office firewall. They exploit the personal digital lives of your people, which means the traditional line between “work security” and “home security” has effectively dissolved. If your team members are easy targets at home, your business is an easy target full stop. This is the same boundary problem we see with ungoverned AI tools in the workplace: the risk walks in and out the door with your people.

Awareness is a certification requirement, not a poster in the lunchroom
Both ISO 27001 (information security) and ISO 42001 (AI management) contain an identical-numbered requirement: clause 7.3, Awareness. In plain English, everyone working under your control must be aware of three things:
- The policy: your information security policy (27001) or AI policy (42001);
- Their contribution: how their day-to-day work makes the management system effective, and the benefits of doing security well;
- The consequences: what it means for the business (and for them) when the rules aren’t followed.
Two words in that requirement do a lot of work. It applies to persons doing work under the organisation’s control, not just employees, but contractors, casuals and anyone else inside your systems. And it demands awareness, not attendance: a certification auditor won’t just check that a training record exists, they’ll ask your receptionist what they’d do with a suspicious email. If the answer is a blank look, a signed induction form won’t save you. We cover how auditors test this, and the rest of the mandatory clauses, in our ISO 27001 requirements checklist.
The good news: clause 7.3 doesn’t mandate expensive training platforms. It mandates an outcome. Which is exactly where free, high-quality resources earn their place in your system.
Free resource #1: KnowBe4 CAPY (awareness that follows people home)
KnowBe4 is the world’s largest security awareness training provider, and CAPY (Cyber Awareness Program for You) is its free community offering: a hub of bite-sized, interactive lessons designed for individuals and families rather than corporate LMS platforms. No logins, no fees, no sales funnel. Most lessons run under four minutes.
CAPY is organised into three paths:
- Capy’s Cub Corner (kids and teens): games and short lessons on spotting phishing, password basics and safe browsing, plus content for older kids on cyberbullying, AI safety and sextortion;
- The Capy-bility Hub (adults): home network security, social media privacy, phishing and scam recognition, mobile device safety and building a family safety plan;
- Capy’s Golden Circle (seniors): clear guides on the scams that disproportionately target older Australians: grandparent scams, identity theft, imposter fraud and AI-generated cons.
Why does a family-oriented resource belong in a business management system? Because of everything in the first section of this article. Your staff member who learns to lock down their social media privacy at home is the same person who won’t leak the OSINT that powers a spear-phishing attack on your business. KnowBe4 frames it as “a lifestyle, not a corporate chore”. Offering CAPY to your team is also simply a good employee benefit: you’re helping protect their kids and their parents, not just your data.
Free resource #2: cyber.gov.au Learn the Basics (the Australian baseline)
The Australian Cyber Security Centre’s Learn the Basics hub is the definitive free Australian resource for personal and small-business cyber hygiene. It covers the fundamentals every person in your business should be able to recite: keeping devices updated, setting up regular backups, turning on multi-factor authentication, using passphrases instead of passwords, and recognising and reporting scams.
Three features make it particularly useful for an awareness program:
- The free alert service: sign up and the ACSC emails you when new threats emerge, with plain-English guidance on what to do. Subscribing your key staff is an awareness control that costs nothing and runs itself. (We covered this and other alert services in Staying Informed: The Alerts and Groups Worth Following.)
- A downloadable cyber security toolkit: ready-made material for toolbox talks and inductions;
- Translated resources: the same advice in community languages, which matters for genuinely reaching a diverse workforce (remember: clause 7.3 requires awareness, not English comprehension).
Learn the Basics is one part of the broader cyber.gov.au platform. If you haven’t seen our full walkthrough of its protect, report and recover resources, read Cyber.gov.au: How to Protect, Report and Recover from Cyber Threats.
Turning free resources into audit-ready evidence
Here’s how we build these into a clause 7.3 awareness program that stands up at certification:
- Induction: every new starter (employee or contractor) reads your security/AI policy and completes the cyber.gov.au basics plus two or three CAPY modules relevant to their role. Record the date.
- Ongoing rhythm: a short awareness item in each team meeting or a quarterly micro-lesson. Rotate topics: phishing, passphrases, MFA, safe AI use, social media privacy.
- Alerts as triggers: when an ACSC alert lands that’s relevant to your business, forward it with a one-line “here’s what this means for us”. That’s live, documented awareness activity.
- Test the outcome: periodically ask staff the three clause 7.3 questions (policy, contribution, consequences) in internal audits. If answers are shaky, that’s a finding to fix before the certification body finds it.
- Keep the records: a simple register of who completed what, when. Evidence of a working awareness program is one of the easiest wins in a stage 1 or stage 2 audit.
The same program does double duty if you’re pursuing (or already hold) ISO 42001. Extend the topic rotation to cover your AI policy, acceptable AI use and the risks of feeding company data into unapproved tools, and clause 7.3 of your AI management system is covered by the same mechanism.
The bottom line
Technology controls stop the attacks your people never see. Awareness stops the ones engineered specifically to get past the technology. And under ISO 27001 and ISO 42001, building that awareness isn’t optional, it’s clause 7.3. With CAPY and cyber.gov.au, the content problem is solved for free; what’s left is the system: induction, rhythm, records and testing.
That system part is what we do. Whether you want us to design your awareness program as part of a full ISO 27001 certification project, or you’re building your own system (with or without AI) and want an experienced auditor to review and mentor as you go, talk to us. Your system is built to certify first time.
Stay in the Loop
Get an email when we post an article. Your email address will not be used for marketing, and you can unsubscribe at any time.
We handle your details in line with our privacy policy.











