When I launched Eito, the goal was simple: give Australian small businesses a way to assess their Essential Eight posture without expensive consultants or messy spreadsheets. That part works. People run the assessment, find their gaps, and take the report to their IT provider.
But a pattern kept showing up in the results. Businesses would nail the technical controls and then get caught by something no firewall can stop: a convincing email, a fake invoice, a phone call that sounded exactly right. The Essential Eight secures your systems. It does nothing for the person who clicks the link.
So I built the second half. Today Eito has a free cyber awareness training hub, and it's live right now.
The Problem with Most Training
Most security awareness training is built for corporations. It assumes you have an IT department to administer it, a budget to pay for it, and staff who will sit through hour-long modules about threat actors and attack vectors.
If you run a five-person electrical company or a ten-person bookkeeping practice, none of that applies to you. You need something your receptionist, your apprentice, and your business partner can all finish in fifteen minutes and actually remember tomorrow.
Small businesses don't need compliance modules. They need practical habits they can learn over a cup of coffee and use the same afternoon.
What I Built
Nine training pathways, written specifically for Australian small businesses. Free, private, no accounts, no setup. Everything runs in the browser, same as the assessment. Each one takes between 10 and 18 minutes:
- Foundations (12 min): The five habits that stop most incidents before they start.
- Phishing & Scams (18 min): How to spot dodgy messages across email, SMS, and messaging apps.
- Passwords & MFA Habits (15 min): Strong passphrases and multi-factor authentication without the pain.
- Safe AI at Work (15 min): Using AI tools productively without leaking client data.
- Invoice Fraud & Payment Scams (15 min): Business email compromise, altered bank details, and payment redirects.
- The First Hour (12 min): What to do immediately if you think something's gone wrong.
- Customer Data & Privacy Basics (14 min): What counts as personal information, your Privacy Act obligations, and what to do if something goes wrong.
- Working from Anywhere (15 min): Public Wi-Fi, home devices, and staying safe on the road.
- New Starter Cyber Induction (12 min): The five things every new team member needs on day one.
Finish a pathway and you get a certificate with a tamper-evident code anyone can check at eito.com.au/training/verify. No personal details stored anywhere. It's a record of completion, nothing more.
Try one right now. Pick any pathway, finish it over a coffee, and download the certificate at the end.
Explore the training hubHow It Fits with the Assessment
The assessment and the training do different jobs. The assessment looks at your systems: patching, admin access, backups. The training looks at your people: spotting a fake invoice, setting up an authenticator app, knowing who to call when something feels off.
You need both. A business with perfect patching and a team that clicks every link is still exposed. A business with savvy staff and no MFA is too.
And to be clear about what this is: it's practical awareness training, not an accredited qualification or a compliance sign-off. It builds everyday habits. That's the whole point.
What's Next
More pathways are already in the works, and I'm watching the ACSC's Essential Eight evolution closely. When the guidance changes, Eito changes with it.
If your team tries a pathway and something doesn't land, I want to know. hello@eito.com.au. This stuff only works if it works for real people.
