Phriendly Phishing training platform
Haumarutanga Hītinihanga
This page has everything you need to know about the rollout of Phriendly Phishing across the tertiary sector.
This page has everything you need to know about the rollout of Phriendly Phishing across the tertiary sector.
Phriendly Phishing is a fully digital, automated training and phishing simulation platform that uses simple content to make the learning memorable and enjoyable.
Tertiary education organisations (TEOs) participating in the Cyber Security for the Tertiary Sector (CSTS) initiative have benefited from funded Phriendly Phishing licences since 2024. This funding ends on 17 March 2027.
After this date, organisations will need to fund their own cyber security training solution. We strongly encourage TEOs to continue providing cyber security training to staff, and to start planning for the transition in March.
What are my options after funding ends?
TEOs wishing to continue cyber security awareness training can:
- work directly with the Phriendly Phishing team to arrange ongoing licensing and support
- evaluate alternative cyber security awareness training tools and select a solution that best meets their needs.
TEOs not continuing with the Phriendly Phishing platform after 17 March 2027 will be automatically withdrawn from the programme.
Interested in learning more?
On 12 and 13 October 2026, the Tertiary Education Commission will host separate Q+A sessions with Phriendly Phishing and KnowBe4 to help TEOs understand the options available, compare products, and learn more about transitioning to a self-funded arrangement.
These sessions are provided for information purposes only and do not constitute a recommendation, endorsement, or preferred supplier arrangement by TEC. Other suppliers are also available and may be considered by TEOs as part of their evaluation process. TEOs are responsible for assessing their own requirements, undertaking any applicable procurement processes, and selecting the solution that best meets their needs.
To receive Q+A invitations, and information packs and updates, register your interest by Friday 9 October 2026.
Register for vendor Q+A sessions
If you’re unable to make the Q+A sessions, you can request a link to the recordings and information packs. Send us an email at customerservice@tec.govt.nz.
Why should you continue cyber security awareness training?
Cyber threats continue to evolve, and people remain one of the most important lines of defence against phishing, scams, credential theft, and other cyber attacks. Ongoing awareness training helps staff:
- recognise and report suspicious emails and scams
- develop safe online habits at work and at home
- reduce the likelihood of successful phishing attacks
- support a stronger cyber security culture across the organisation.