Streamline ISO Consultants

  • Home
  • Security & AI
    • ISO 27001 Information Security
    • ISO 42001 AI Management
    • Cyber & Information Security Advisory
    • Essential Eight
    • SOC 2
    • TISAX
  • ISO Consulting Services
    • ISO Consultants Australia
    • ISO 9001 for US Companies
    • ISO Mentoring
    • Independent ISO Internal Audit Services Australia (Clause 9.2)
    • ISO Gap Analysis Audits: Know Where You Stand Before Stage 1
    • ISO Certification Auditors
    • ISO System Development
    • ISO Management System Maintenance & Ongoing Support
  • ISO Standards
    • ISO 9001 Quality Management
    • ISO 45001 Occupational Health and Safety
    • ISO 14001 Environmental Management
    • ISO 17025 Testing and Calibration
    • HACCP Food Safety
    • ISO 19443 Nuclear Supply Chain
  • Resources
    • All Articles
    • ISO Clause Guides
    • Quality Quotes
  • About
    • ISO FAQs
    • Quality Policy
    • Client Testimonials
    • ISO 9001 Certificate
  • Contact
    • Business Info
    • Privacy Policy

By Streamline ISO Consultants

Awareness Is a Behaviour, Not a Slide Deck: Simulated Phishing and Clause 7.3

Tilt-shift office scene of a hooded scammer casting a phishing hook labelled click here at an employee's screen
A phishing simulation recreates this exact moment safely, then trains whoever takes the bait. That repeatable loop is how you evidence ISO 27001 clause 7.3.

Ask most businesses how they handle security awareness and you will hear the same answer: an annual slide deck and a quiz nobody remembers by lunchtime. It ticks a box. It changes almost nothing. When a well-crafted phishing email lands three months later, the slide deck is not in the room. The habit is, or it is not.

Clause 7.3 of ISO/IEC 27001 asks for awareness, and reading it plainly, it asks for a behaviour, not an attendance record. The most reliable way I know to build that behaviour, and to prove it to an auditor, is to practise the real thing in a safe way: simulated phishing exercises.

What clause 7.3 asks for

Clause 7.3 says people doing work under your control must be aware of three things: the information security policy, their own contribution to the information security management system (including the benefits of doing it well), and the consequences of not following it. ISO 27001:2022 backs this with Annex A control A.6.3, information security awareness, education and training.

Notice what is not there. It does not say “run a session once a year.” It says people must be aware, which an auditor reads as: can they recognise a threat and do the right thing when it matters? A register of who attended a webinar does not answer that. A record of how your people responded to a realistic phishing email, and how that response improved over time, does.

Why simulated exercises work

A phishing simulation sends your own people a safe, controlled version of the emails attackers actually use. Nobody is harmed and nothing leaves the building, but the moment is real: the same hover-or-click decision, on an ordinary Tuesday, in the flow of work.

Three things make it effective. It is safe practice, so people learn the tell without paying for the lesson. It is measurable, so you get a click rate, a report rate and a trend instead of a vibe. And it closes the loop: the people who click get short, targeted training then and there, and you test them again. Run that cycle a few times and the click rate falls. That falling number is the evidence, and it is also the point.

One thing worth measuring that most people forget: not just who clicked, but who reported it. A workforce that clicks less is good. A workforce that clicks less and reports more is a functioning detection layer, which is exactly what your incident response process (Annex A controls A.5.24 to A.5.28) depends on.

Three ways to run it, from what you already own to the specialists

You do not need a big budget to start. Here are three routes, and the right one usually comes down to what you already pay for, whether Australian data residency matters to you, and how much program depth you need.

Microsoft Attack Simulation Training (you might already have it)

If your business runs on Microsoft 365 with Defender for Office 365 Plan 2 (included in the E5 suites, or available as an add-on), phishing simulation is already built in. It covers the techniques attackers really use, grouped as credential harvest, malware attachment, link in attachment, link to malware, drive-by URL and OAuth consent grant, plus a no-payload “how-to” teaching option. You pick a lure from Microsoft’s library or build your own, target a group, and the platform assigns training automatically to anyone who takes the bait, then reports who did what. If you already pay for the licence, this is the cheapest way to run a credible program.

Phriendly Phishing (built for Australia)

An Australian platform, developed by local professionals, hosted on Australian cloud and supported locally, which matters if data residency and sovereignty are on your radar. Its content is written for the Australian and wider APAC market and delivered as short microlearning modules, and its stated approach is to train rather than trick, which is the right instinct. If you want local content, local support and Australian data handling, it is a natural fit.

KnowBe4 (the global heavyweight)

The largest and most mature platform in the category, with an enormous library of phishing templates and training content, automated program builders, risk scoring at the individual and organisation level, and gamification to keep people engaged. If you want depth, breadth and mature reporting, and you are running a larger or more complex program, this is the benchmark most others are measured against.

All three do the same core job: simulate, measure, train, repeat. Start with what you already own, and step up to a specialist platform when your program outgrows it.

What an auditor wants to see

When I audit clause 7.3 and A.6.3, I am not looking for a certificate of attendance. I am looking for evidence that awareness is real and maintained. A simulation program gives me exactly that: the information security policy people are being made aware of, simulation results showing response rates, records of training assigned and completed, and a trend over several rounds. If your click rate is lower this quarter than last, you are not asserting awareness, you are demonstrating it.

Do it properly, not as a gotcha

A word of caution, because this can be done badly. The goal is behaviour change, not catching people out. Simulations that humiliate staff, or that use cruel lures such as a fake bonus or a fake redundancy notice, damage trust and teach people to fear the IT team rather than the attacker. Keep it fair, make the follow-up training genuinely useful, fold it into onboarding so new starters are covered, and judge the program by the trend, not by any single person’s slip. Awareness is a team outcome.

Where this fits

Simulated phishing is one part of a working information security management system, not the whole of it. If you want awareness that stands up to both an attacker and an auditor, we build practical ISO 27001 systems (including the clause 7.3 awareness program and the Annex A controls behind it) and provide cyber and information security advisory. For teams building their own system, our ISO mentoring service guides you and provides the independent internal audit. Our companion guide on cyber security awareness training and clause 7.3 covers the free resources worth starting with.

Want awareness you can actually prove? Get in touch for a straight conversation about where your awareness program stands and how to evidence it for certification.

Sources: Microsoft, Attack simulation training in Microsoft Defender for Office 365; Phriendly Phishing; KnowBe4 Security Awareness Training. Product features change; confirm current licensing and capabilities with each vendor before relying on them.

General guidance only. This article is general information, not legal, financial, safety or compliance advice, and it does not take account of your specific circumstances. Streamline ISO Consultants are ISO management-system consultants, not lawyers or licensed advisers. Standards, laws and regulator guidance change, and details were correct only at the time of writing. Always seek professional advice before acting. See our full Disclaimer.

Stay in the Loop

Get an email when we post an article. Your email address will not be used for marketing, and you can unsubscribe at any time.

We handle your details in line with our privacy policy.

More ISO Certification Information

  • ISO Frequently Asked Questions
    Frequently Asked Questions: ISO FAQs
  • Consultant guiding a business owner through their ISO management system at a laptop
    ISO Mentoring: Expert Guidance for DIY ISO Systems
  • ISO 45001 workplace safety inspection
    ISO 45001 Consulting, Safety Audits and Mentoring
  • ISO 14001 environmental management
    ISO 14001 Consulting, Environmental Audits and Mentoring
  • ISO 27001 information security risk analysis
    ISO 27001 Consulting, Internal Audits & Mentoring
  • Tilt-shift miniature naval shipyard inspection bay with a submarine hull section on keel blocks and workers in hi-vis checking tagged components in a parts quarantine area
    ISO 19443: The Nuclear Supply Chain Standard, and…
  • Tilt-shift miniature of a submarine periscope casting a narrow cone of light onto one small island of activity in a vast dark ocean
    ISO Clause 4.3: Determining Your Scope (Inside Your…
  • Tilt-shift miniature of an AI data centre and microchip: AI tools and ISO 42001
    ISO 42001 AI Management Consulting, Audits & Mentoring
  • Tilt-shift miniature of a collapsed bridge with engineers at a drawing board tracing the failure back to the design
    ISO 9001 Clause 8.3: Design Inputs, Outputs, Review,…

Filed Under: Articles Tagged With: #informationsecurity, #iso27001

Quick Information Request

Brisbane ISO Consultants

Level 14, 167 Eagle St
Brisbane Queensland 4000
Phone: 07 3667 8280
Email: hello@streamline.business

Sydney ISO Consultants

Level 5, 20 Bond Street,
Sydney NSW 2000
Phone: 02 8315 7780
Email: hello@streamline.business

Melbourne ISO Consultants

Level 8, 350 Collins Street
Melbourne, Victoria 3000
Phone: 03 9034 3990
Email: hello@streamline.business

Client and partner logos

KEY ISO ARTICLES

Articles, Deep Dives & More
Frequently Asked Questions
Quality Quotes
Funding Grants for ISO Certification
ISO Consultants
Strategic Planning - Mystical Art?
ISO Certification Auditors
How to get ISO 9001 Certification
ISO Certification Cost
How to tell if your ISO Cert is fake
4-year-olds and Root Cause Analysis
Fast ISO 9001 Certification
The Ultimate Guide to ISO 9001 Audit
ISO 45001 Certification Cost
Who's Interested in a Party?
How to use Smartsheet for ISO
Smarter Quality Objectives
Local Government QMS
Quality Assurance, Quality Control or QMS
ISO Certification in Sydney
ISO Certification in Melbourne
ISO Certification in Brisbane
SAI Global Consultant Affiliate Program

QUICKLINKS TO ISO INFO

ISO Consultants Australia
ISO Mentoring
ISO 27001 Certification Cost
ISO 9001 Quality Management
ISO 45001 Health & Safety
ISO 14001 Environment
ISO 17025 Testing & Calibration
ISO 27001 Information Security
ISO 42001 AI Management
ISO 22000 HACCP Food Safety

Search

FOLLOW OR GET IN TOUCH

linkedinmail
Smartsheet Platinum Partner

Copyright © 2026 Streamline · Log in

Privacy Policy · Terms of Use · Disclaimer

Call us Enquire