What Happened
Australia's cybersecurity crisis is accelerating. The Australian Signals Directorate recorded over 84,700 cybercrime incidents in its latest annual report, alongside more than 42,500 calls to the national hotline, a 16 percent jump from the previous year. Threats are rising. Employee attention is not.
The Communication Angle
Here's the real problem nobody in the cybersecurity industry wants to admit: the communication strategy around cyber threats has been broken for years. Leaders keep turning up the volume on the same message, and teams keep turning down the volume in response. This is not a technology failure. It is a messaging failure.
When every email carries the subject line "URGENT: Security Reminder," urgent stops meaning anything. When every training module opens with a statistic about rising threats, people learn to skip past it. The language of crisis, repeated without variation and without personal relevance, becomes wallpaper. Your team isn't irresponsible. They've been trained by repetition to stop caring.
The fix is not more communication. It is smarter communication. Specifically, it means shifting from broadcasting fear to building consequence. There is a critical difference between telling someone "cybercrime is up 16 percent" and telling them "a company our size lost three months of payroll data last April because one person clicked the wrong link." The first is a statistic. The second is a story. Stories land. Statistics bounce off.
The second shift is moving from organisation-wide messaging to role-specific messaging. A message about phishing that goes to every person from the receptionist to the CFO is a message written for nobody. When your finance team gets a message that says "attackers are specifically targeting payment approval workflows right now, here's what that looks like in your inbox," they pay attention. Precision signals relevance. Relevance triggers action.
The third shift is giving people a role, not just a warning. Passive recipients of scary news check out. Active participants in a solution stay engaged. Reframe your security communications so that every person on your team understands their specific job in the defence of the organisation. Not "be careful out there" but "you are the last line of defence for this, and here is exactly what that looks like on a Tuesday afternoon."
This is exactly the kind of scenario I break down in Say It Right Every Time. The chapter on audience targeting gives you a framework for diagnosing when your message is failing not because the content is wrong, but because you've aimed it at everyone and therefore hit no one. The principle is simple: a message without a specific receiver is not a message. It's noise.
Key Takeaway
Take your next company-wide security email and delete it. Instead, write three separate versions: one for your finance team, one for your operations team, one for your leadership team. Each version should open with one real, recent example relevant to that specific group's work, and close with one specific action they can take before lunch. Send those. Measure who opens them. You will not go back to the generic blast.
