Security Awareness Training for Australian Businesses — KnowBe4 and Managed SOC
· By Paul Harvey
Security awareness training is the human layer of your Security Operations Centre — Mycelium 365 includes KnowBe4 Security Awareness Training in every managed SOC plan because technology alone cannot stop a staff member clicking a phishing link. This post explains what KnowBe4 training includes, why it complements your technical SOC defences, and how Mycelium 365 delivers it as an integral part of the managed SOC rather than a separate product.
Why security awareness training is part of your SOC — not a separate product
More than 80% of cyber incidents involve a human element — a phishing click, a reused password, a social-engineered wire transfer, or an MFA prompt approved under pressure. Technical controls like endpoint detection and response (EDR), identity threat detection and response (ITDR), and SIEM correlation are essential, but none of them stop a well-briefed staff member from handing over credentials to a convincing lookalike login page. That is why Mycelium 365 treats security awareness training as an integral layer of the managed SOC, not an optional add-on. A modern defence-in-depth model has three co-equal layers: prevention (Microsoft Defender), detection and response (the Huntress SOC), and education (KnowBe4 Security Awareness Training). Training also supports the ASD Essential Eight — particularly Mitigation Strategy #7, Multi-Factor Authentication, by teaching users to recognise MFA bypass attempts and adversary-in-the-middle prompts before they approve them.
What does KnowBe4 Security Awareness Training include?
KnowBe4 is the world's largest security awareness and simulated phishing platform, and Mycelium 365 delivers the full stack as part of the managed SOC. The content library covers phishing and spear-phishing, business email compromise, password hygiene, social engineering, MFA awareness, insider risk, and safe use of Microsoft 365, Teams, and mobile devices — with training modules ranging from short-form video and interactive scenarios through to longer role-based courses for finance, HR, and executive teams. The platform includes an industry-leading library of realistic phishing templates modelled on live campaigns targeting Australian businesses, together with automated user enrolment from your Microsoft Entra ID tenant, per-user progress and completion tracking, and reporting suitable for auditors, boards, and cyber insurers. Simulated phishing campaigns are included as standard, safely testing whether staff actually recognise the techniques attackers are using against Australian organisations right now.
How Mycelium 365 delivers KnowBe4 as part of the managed SOC
Buying KnowBe4 directly means a separate contract, a separate admin console, and someone on your team owning training campaigns, phishing simulations, exemptions, and reporting alongside the rest of their job. Mycelium 365 includes KnowBe4 at no additional cost in every managed SOC plan and takes on the operational load: we handle tenant setup, integration with Microsoft Entra ID for automated enrolment, curriculum design, monthly module assignment, and quarterly phishing simulation campaigns tuned to your industry and previous results. Because KnowBe4 sits inside the same managed SOC as Microsoft Defender and Huntress, real-world threats detected by the SOC feed directly into what training is prioritised next — if we see credential-harvesting phishing landing against your users, the next campaign focuses on that pattern. Clients receive plain-English quarterly reporting covering completion rates, click and report rates, and remediation recommendations.
What security awareness training topics matter most for Australian businesses in 2026?
Training content has to keep pace with how attackers actually work. In 2026 the priorities for Australian businesses are: phishing and spear-phishing — including AI-generated phishing, which industry telemetry showed increasing more than 80% during 2025 as attackers adopted generative AI to remove the grammar and formatting cues staff had been trained to spot; business email compromise (BEC), which the FBI's Internet Crime Complaint Center recorded as driving more than USD 6.3 billion in reported losses globally in 2024 and which continues to dominate ACSC's annual cyber threat report for Australian SMBs; adversary-in-the-middle MFA bypass attacks, which jumped sharply through 2025 as toolkits like Evilproxy commoditised session-token theft; identity-based attacks targeting Microsoft 365 accounts through OAuth consent phishing and token replay; and ransomware social engineering, including pretexting and fake IT helpdesk calls used to seed initial access. KnowBe4's Australian and APAC content packs cover each of these, and Mycelium 365 aligns every client curriculum to the ASD Essential Eight so training is defensible and framework-based.
How does KnowBe4 training help with cyber insurance in Australia?
Almost every Australian cyber insurer now includes security awareness training as a specific line item in the renewal questionnaire — and increasingly requires evidence, not just a tick. KnowBe4 reporting provides exactly the documentation insurers ask for: per-user completion rates, phishing simulation click-through and report rates, campaign history, and trend data over time. Combining continuous KnowBe4 training with a managed SOC demonstrates a genuine defence-in-depth posture — the kind that underwriters now use to price risk down, or to keep cover available at all in higher-risk sectors. There is a real difference between box-ticking annual training, which briefly lifts scores and then fades from memory within weeks, and continuous monthly training that measurably changes behaviour over time. Monthly cadence, real-world simulations, and short-form content are what actually shift click rates — and what insurers are learning to look for.
How the triple-layer SOC uses KnowBe4 alongside Microsoft Defender and Huntress
KnowBe4 is included at no additional cost in every Mycelium 365 managed SOC plan alongside the Huntress SOC and Microsoft Defender endpoint protection. Deployment and user enrolment from your Microsoft Entra ID tenant are handled by Mycelium 365, so there is nothing for your team to configure. Monthly training modules and quarterly phishing simulations run automatically, with results reviewed by the Mycelium 365 SOC team and reported to clients quarterly with plain-English commentary and remediation recommendations.
Read more about our managed Security Operations Centre and how KnowBe4 training fits alongside governance and compliance readiness for Australian businesses.
Frequently asked questions
Is KnowBe4 security awareness training included in Mycelium 365's managed SOC plans?
Yes. KnowBe4 Security Awareness Training and simulated phishing are included at no additional cost in every Mycelium 365 managed SOC plan. Deployment, user enrolment from Microsoft Entra ID, monthly training assignment, and phishing simulation campaigns are all handled by Mycelium 365, with completion and click-rate reporting delivered to clients quarterly.
Why does Mycelium 365 use KnowBe4 rather than another awareness platform?
KnowBe4 is the world's largest security awareness and simulated phishing platform, with the deepest content library, the most mature phishing template set, and the strongest reporting for Australian cyber insurance and Essential Eight evidence. Rolling KnowBe4 into the managed SOC gives clients a best-of-breed human layer alongside Microsoft Defender (prevention) and Huntress (24/7 detection and response), without a separate KnowBe4 contract or admin console for the client to manage.
How often should staff complete KnowBe4 training?
Annual training is a compliance minimum but does not change behaviour — click rates rebound within weeks. We recommend, and deliver, continuous monthly KnowBe4 modules with quarterly phishing simulations. This cadence is what Australian cyber insurers increasingly expect and what actually shifts phishing click rates over time.
Can KnowBe4 security awareness training help us meet Essential Eight requirements?
Yes. While security awareness training is not itself one of the eight mitigations, it materially supports several — most directly Multi-Factor Authentication (Strategy #7), by training users to recognise MFA bypass and adversary-in-the-middle prompts. It also strengthens Restrict Administrative Privileges and Application Control outcomes by reducing the social-engineering pathways attackers use. Combined with a managed SOC and Microsoft Defender, KnowBe4 gives you defensible, framework-aligned evidence of a mature security posture.