Skip to content
2026

Now taking on 4 new clients this year — white-glove onboarding, month to month.

Book a call
HomeBlogCost Guides

Security Awareness and Phishing Training Cost

Employee scrutinizing a suspicious email on a laptop in an open-plan office

Security awareness and phishing training cost is almost always quoted per user per year, and the per-user platform fee is the smaller part of the real number. What moves the total is how often you run simulated phishing campaigns, whether someone inside your business or the provider runs them, what reporting your insurer and regulators expect to see, and the staff time the program consumes. NetSys delivers awareness training as part of its cybersecurity services and quotes programs per business, month to month, rather than publishing a per-user rate. This guide covers what the platforms charge for, what changes the price, and how to compare two programs that both promise to make people stop clicking.

How is security awareness training priced?

Cost driverWhat it coversHow it is usually billed
Platform subscriptionTraining library, phishing simulator, reporting, learner portalPer user per year, tiered by features
Simulation cadenceHow many campaigns run and how targeted they areLabor, or a higher managed tier
Managed serviceSomeone designs, schedules, reviews and reports on campaignsPer user per month, or bundled with managed security
Content and compliance modulesHIPAA, PCI DSS, state privacy, role-specific coursesIncluded in higher tiers or sold as add-ons
Onboarding and integrationUser sync from Entra ID, mail allow-listing, report-phish buttonOne-time setup labor
Staff timeMinutes per person per month, plus the administrator's hoursNever on the invoice, always real

Vendors publish their own per-user tiers, and those pages are the right place to read current figures. The rest of this guide is about the rows a platform price does not include.

How does simulation cadence change the cost?

A phishing simulation is a fake malicious email sent to your staff to see who clicks, who reports it, and who types a password into the fake login page. The platform fee usually allows unlimited campaigns; what costs money is designing and running them well. A program that sends one generic template a quarter costs little and teaches little, because staff learn to spot that one template. A program that sends a varied campaign monthly, targets departments with the lures they would really receive (a fake invoice to accounts payable, a fake resume to HR, a fake password reset to everyone), and follows each click with a short lesson takes hours of administration each month.

Cadence also affects the reporting your insurer sees. Click rates from a single annual test are close to meaningless. A monthly series over a year shows a trend, and a trend is what underwriters and auditors want. Decide the cadence first and price the labor from it, rather than buying a platform and hoping someone finds time.

Self-run or managed: who does the work?

Self-run means your office manager or internal IT person owns the platform: builds campaigns, assigns training, chases the people who never finish it, and pulls reports before the insurance renewal. The platform fee is the only invoice, and the cost is hidden in somebody's week. This works in firms with a person who wants the job and has time for it. It fails quietly when that person gets busy, which is usually the third month.

Managed means the provider runs the program: campaign design, scheduling, remedial training for repeat clickers, and a monthly report that lands in the owner's inbox without anyone asking. The invoice is higher, the hidden cost is gone, and the program keeps running. NetSys runs awareness training this way, tied to the same reporting the rest of the security program produces, so the phishing results sit next to the MFA coverage, patch status and backup tests an insurer will ask about at the same time.

What do cyber insurers and regulators expect to see?

Cyber insurance applications routinely ask whether employees receive security awareness training, how often, and whether phishing simulations are run. Some carriers ask for the completion rate and the click trend. A one-time onboarding video does not satisfy the question the way a scheduled program with records does, and after a claim the carrier may ask for the records. Our guide to cyber insurance requirements lists the other controls that appear on the same form.

Regulation adds its own drivers. HIPAA's Security Rule requires a security awareness and training program for workforce members. PCI DSS requires a formal awareness program for personnel. New York's Department of Financial Services cybersecurity regulation requires regular training for covered entities, and the state's SHIELD Act expects reasonable safeguards that include training. Each of those raises the cost slightly, because the program needs role-specific content and records that survive an audit, and each of them makes skipping the program far more expensive than running it.

Is there a version already in Microsoft 365?

Microsoft includes Attack Simulation Training in Microsoft Defender for Office 365 Plan 2 and in the Microsoft 365 E5 suite, according to Microsoft's documentation. Microsoft 365 Business Premium includes Defender for Office 365 Plan 1, which does not include it. So a business on Business Premium either upgrades the relevant seats or buys a third-party platform. Microsoft's tool covers simulations and a training library inside the Defender portal; it does not run the program for you, so the labor question above still applies.

Whichever platform you use, the report-phish button in Outlook matters more than the simulation itself. Training people to report suspicious mail, and routing those reports to someone who looks at them, is what turns a training expense into an early-warning system. Ask any provider how reported messages are handled and how fast.

How do you compare security awareness training quotes?

  • Per-user fee, and which tier. Simulator, content library, integrations and reporting differ by tier.
  • Cadence and targeting. How many campaigns per year, whether they are department-specific, and who designs them.
  • Who runs it. Self-service with your staff's time, or managed with the provider's.
  • Reporting. A sample of the monthly report, and whether it is written for an insurer and an owner or only for an administrator.
  • Repeat clickers. What happens after the third click: more training, a manager conversation, or nothing.
  • Contract term. Many platforms sell annual or multi-year terms; a managed program on month-to-month terms keeps the pressure on the provider to show results.

Frequently asked questions

How much does phishing training cost per user?

Platform vendors publish per-user annual pricing on their own sites, tiered by features, and that is the reliable source for a current figure. The full cost is the platform fee plus the labor to run monthly campaigns and produce reports, which is either your staff's time or a managed service fee. NetSys quotes awareness training per business, standalone or within a managed security agreement, month to month, after looking at headcount, compliance obligations and who will own the program.

How often should we run phishing simulations?

Monthly is the practical answer for most small businesses: frequent enough that people stay alert and the trend is meaningful, infrequent enough that the program does not become noise. Vary the templates and target departments with realistic lures. Pair each campaign with a short lesson for anyone who clicks. Quarterly is the floor at which results still mean something; annual testing is a checkbox, and insurers increasingly treat it as one.

Does security awareness training count for cyber insurance?

Yes, and it is usually asked about directly. Carriers want to know that training happens on a schedule, that phishing simulations run, and that records exist. A managed program produces those records automatically. Training alone does not satisfy an application; MFA, endpoint detection, backups and email filtering appear on the same form, and the training program is strongest when it is reported alongside them.

What should we do about employees who keep clicking?

Treat it as a process problem before a people problem. Repeat clickers usually sit in roles that receive the most external mail, such as accounts payable, HR and reception, so start by tightening the controls around those roles: stricter email filtering, payment verification steps, and link isolation in the browser. Then add short, role-specific training and a manager conversation. Firing people for failing simulations makes staff stop reporting real phishing, which is the worst possible outcome.

Building a program with NetSys

NetSys runs security awareness training as a managed program: campaigns designed for your departments, monthly reporting written for owners and insurers, and results that sit alongside the rest of your security controls. See our security awareness training page, or read our broader guide to security awareness training for small business.

Sources and further reading

Reading is free. So is knowing where you stand.

Turn insight into action.

Take a free cybersecurity or AI readiness assessment, or book a call with a NetSys engineer — no obligation, no runaround.