Information Security & Data Protection Training Programme

SyncMate — WYHEN Pty Ltd (ABN 57 688 078 999) Version 1.0 · Effective 31 August 2026 · Owner: Founder/Technical Operator · Review: annually

1. Purpose and scope

This programme ensures every person with access to SyncMate systems or customer data understands their security and privacy obligations. It applies to all personnel — the Founder, any employee, contractor, or third party granted access — without exception. Completion is a precondition of access.

2. Training components

2.1 Induction module — before any access is granted

Mandatory. Estimated 90 minutes. Covers:

2.2 Annual refresher — every 12 months

Mandatory. Estimated 60 minutes. Re-covers the induction content, updated with the past year's incidents, near-misses, threat landscape changes, and any changes to our policies, subprocessors or architecture.

2.3 Quarterly awareness update — every 3 months

Estimated 15–30 minutes. A short written brief on current threats relevant to us: active phishing campaigns targeting accounting and Xero users, credential-stuffing trends, supply-chain and dependency compromises, and any ACSC or OAIC advisory of relevance. Delivered from the threat intelligence process (A7).

2.4 Secure development module — before writing or reviewing code

Mandatory for anyone contributing code. Estimated 2 hours. Covers:

3. Records

For each person and each training event we record: name, role, module, date completed, version of the material, and a signed or electronically acknowledged attestation. Records are retained for the duration of the engagement plus 7 years and are available to customers as evidence on request.

4. Non-completion

Access is not granted until induction is complete. Failure to complete an annual refresher within 30 days of its due date results in suspension of administrative access until completed.

5. Effectiveness review

Annually the Founder reviews: completion rates, incidents or near-misses attributable to a knowledge gap, and whether the material still reflects the architecture and threat landscape. Material is updated accordingly.

6. Current status

As at the effective date, WYHEN is operated by a single principal, who has completed the induction and secure-development modules and is subject to the annual refresher and quarterly update cycle on the same terms as any future employee or contractor.