PEXA, the platform that handles most of Australia's property settlements, faced 6.5 million intrusion attempts in the 2025 financial year. That's roughly 17,800 attacks per day against a single company. They defended against every one of them.
You might think this has nothing to do with your accounting practice, law firm, or real estate agency. But PEXA's security chief Graham Fairley uses a phrase that applies to every Australian business: "defence in depth." The idea is simple. Don't rely on one control to keep you safe. Build layers.
For small businesses without dedicated IT teams, phishing training for your Australian staff represents one of the most accessible layers you can add. Your staff are already the first line of defence. The question is whether they know it.
Why Property Professionals Face the Same Threats You Do
PEXA processes over 20,000 property settlements weekly and has handled more than $5 trillion in transactions since 2013. Criminals target them because that's where the money flows. But they also target conveyancers, mortgage brokers, and real estate agents for the same reason.
The attacks follow predictable patterns. Fake invoices with changed bank details. Emails impersonating solicitors requesting urgent fund transfers. Password reset requests that look legitimate but lead to credential harvesting sites.
These same tactics work against any business handling client money or sensitive data. Accountants managing tax returns. Lawyers holding trust funds. Financial planners with access to client portfolios. The criminals don't care about your industry. They care about your access.
The "Defence in Depth" Approach for Small Business
PEXA's security strategy involves sophisticated ways to control who can log in to their systems, sharing information about new threats, and continuous monitoring. Most small businesses can't replicate this. But the underlying principle scales down perfectly.
Think of your security as a series of gates rather than a single wall. If someone gets past one gate, another should stop them. For small businesses, these gates might include:
- Multi-factor authentication on email and financial systems
- Staff trained to recognise phishing attempts
- Verification procedures for payment changes (like calling a known number, not the one in the email)
- Regular software updates
- Backups stored separately from your main network
None of these require an IT department. All of them reduce your risk.
Cyber Security Training for Small Business: The Human Layer
PEXA's Fairley noted that controlling who can log in to your systems is "effectively the front door" into their platform. For most small businesses, email serves the same function. And email security depends almost entirely on the people reading those messages.
This is where security awareness training becomes practical rather than theoretical. Studies of thousands of employees show that standard training programs often fail to change behaviour. In fact, a major study of nearly 20,000 people found that traditional training didn't meaningfully reduce the risk of staff clicking on dangerous links. This is a wake-up call for many. It suggests that if training is going to work, it cannot be a simple box-ticking exercise. It must be ongoing and realistic to make a real difference.
One-off training sessions don't stick. People forget. New staff join without the same knowledge. Phishing tactics evolve while your training materials gather dust.
The solution is regular, simulated phishing tests combined with immediate feedback. When someone clicks a suspicious link in a training simulation, they learn in that moment why it was suspicious. This creates what educators call "teachable moments," instances where the lesson connects directly to the mistake.
What Effective Phishing Training Actually Looks Like
Good training programs share several characteristics. They test employees with realistic scenarios, not obvious spam. They adjust difficulty based on performance. They provide immediate education when someone fails a test. And they require minimal ongoing management from you.
The best programs use AI to research your organisation and create customised simulations. A phishing email targeting a law firm looks different from one targeting a trades business. Context matters because criminals do their homework.
You also need reporting that shows improvement over time. If your staff click on 30% of simulated phishing emails in January and 8% by December, that's measurable progress. If the numbers aren't improving, you know to adjust your approach.
Building this capability internally takes time most small business owners don't have. That's why automated platforms exist. You add your staff email addresses, set a testing frequency, and the system handles the rest. Monthly reports show who needs extra attention.
Lessons from PEXA's Approach
Three principles from PEXA's security strategy translate directly to small business:
Consolidate where possible. PEXA moved to a single identity platform rather than managing multiple tools. For small businesses, this might mean using one password manager across the organisation rather than letting everyone create their own system. Simpler means fewer gaps.
Assume attacks will happen. PEXA didn't experience 6.5 million intrusion attempts because they were careless. They experienced them because they're a target. You're a target too, just at a different scale. Preparing before an incident costs less than recovering after one.
Build layers, not walls. No single control stops everything. Staff training catches what spam filters miss. Verification procedures catch what trained staff miss. Backups recover what prevention missed entirely.
Starting Your Own Defence Strategy
You don't need a security team or a large budget to improve your position. Start with the basics: enable multi-factor authentication on your email accounts today if you haven't already. It takes ten minutes and stops most credential theft.
Then look at your people. Building staff awareness on a budget is achievable when you use automated tools. A platform that sends realistic phishing simulations, tracks results, and delivers training to those who need it can run in the background while you focus on your actual business.
The goal isn't perfection. PEXA, with all their resources, still faces millions of attacks. The goal is making your business harder to breach than the one next door. Criminals, like water, follow the path of least resistance.
Test Your Current Position
Most business owners have no idea how their staff would respond to a well-crafted phishing email. Would your accounts team question a supplier requesting a bank detail change? Would your receptionist verify an urgent request supposedly from you?
You can find out without risk. Send yourself a test phishing email through a Phishing Training Australia free trial. See what a realistic attack looks like. Then decide whether your team needs regular practice identifying these threats.
The property industry handles billions in transactions and takes security seriously because they've seen what happens when it fails. Your business handles something valuable too, whether that's client data, trust funds, or simply your reputation. The same principles apply.
Sign up for a Phishing Training Australia free trial and send yourself a test email. It takes less than five minutes to see where you stand.