← All posts

Phishing Training for Employees: Cost, ROI, What Works

Picture Karen from accounting (a composite of incidents security teams see constantly). Fifteen years with the company, never missed a deadline, makes excellent banana bread for office birthdays. One morning, Karen receives an email from “IT Support” saying her password is about to expire. The logo is perfect. The urgency feels real.

Karen clicks.

Within hours, ransomware encrypts every file server in the organisation, and the attackers demand a seven-figure ransom. Karen still makes great banana bread, but the company now has weeks of downtime, a crisis-management bill, and a very expensive lesson about where its security perimeter actually sits.

The uncomfortable part: Karen isn’t careless. She’s normal. The composite above is assembled from the most common breach pattern in the industry, and it starts in an inbox.

Phishing is still how most attacks begin

You’ll see “90% of attacks start with phishing” quoted around the internet. That figure doesn’t survive contact with the major breach reports, so we won’t use it. The defensible version is bad enough: year after year, studies like the Verizon Data Breach Investigations Report find that the majority of breaches involve a human element, and phishing remains the most common way attackers get their first foothold.

A few honest reference points:

  • IBM’s Cost of a Data Breach Report consistently puts the global average breach cost well above $4 million US — and phishing and stolen credentials sit at or near the top of the initial-attack-vector list.
  • The FBI’s Internet Crime Complaint Center (IC3) reports cybercrime losses exceeding $10 billion US a year — and that’s reported losses only. Business email compromise, which usually starts with a phish, is one of the largest single categories.
  • Proofpoint’s State of the Phish surveys repeatedly find that a large majority of organisations experience at least one successful phishing attack in a given year.

Modern phishing emails don’t look like they came from a foreign prince. They look like messages from your CEO, your bank, your cloud provider, or your own IT department. Your employees aren’t stupid — they’re busy, distracted, and up against attackers who do this for a living.

Why annual security training fails

Remember the mandatory annual security training everyone completes while answering email and mentally planning the weekend? That’s not working, and the reasons are structural:

  1. It’s once-and-done. An hour-long slideshow once a year doesn’t build lasting behaviour change. It builds the ability to click “Next” really fast.
  2. It’s not realistic. Generic modules about hypothetical threats don’t prepare anyone for a well-crafted spear-phishing email targeting their actual role.
  3. It’s not measured. Most organisations have no idea whether their training works until they’re mid-incident. “We do annual training” is a checkbox, not a strategy.
  4. It’s boring. When training is boring, people tune out. When people tune out, they don’t learn. When they don’t learn, they click.
  5. It’s priced for enterprises. Established awareness platforms are typically quoted in the five figures annually for a mid-sized company — money many small and medium businesses don’t have, which leaves them exposed.

How phishing simulations actually change behaviour

Simulation-based training flips the model: instead of telling people about phishing once a year, you send them realistic, safe, simulated phishing emails all year and teach at the moment of the click.

  • Continuous practice. Employees face regular simulated attacks at randomised intervals. Behaviour change comes from repetition, not lectures.
  • Realistic scenarios. Campaigns mirror the threats your industry actually faces — finance teams get fake wire-transfer requests, HR gets fake resume attachments, IT gets fake vendor security alerts.
  • Adaptive difficulty. People who keep catching simulations get harder ones; people who keep clicking get scenarios pitched to where they are. Everyone is challenged appropriately.
  • Microlearning on click. Click a simulated link and you immediately get a short, focused explanation of what you missed — a two-minute intervention at the moment you’re most receptive, not a 30-minute course three months later.
  • Measurement. Click rates, reporting rates, and per-department trends turn awareness from a checkbox into data the security team can act on.

This is the model behind ThinSky’s phishing training (TCRE): AI-generated campaigns matched to your industry and tone, adaptive difficulty per user, and a resilience score leadership can actually trust. It also pairs naturally with the technical side of the house — simulations train the humans while managed security monitoring watches the systems.

The graduate-out program

Here’s the part of ThinSky’s approach worth pausing on: the goal is to put ourselves out of a job.

Most security vendors are built on dependency — the longer you stay vulnerable, the longer you pay. Our graduate-out model inverts that. As your team’s detection rate climbs and holds steady over consecutive months, you graduate from the intensive program: drop to a reduced-frequency maintenance cadence at a lower per-user rate, or pause entirely and come back for periodic refreshers. We think training vendors should align their incentives with your improvement, not your dependence.

What phishing training costs

Per-user, per-month pricing is the industry norm, and it’s the right mental model. As a representative figure, plans start around $8 per user per month — request a quote for pricing matched to your organisation, since team size and program intensity move the number.

Here’s an illustrative worked example (illustrative — not a quote) for a 200-employee company at that representative rate:

  • 200 employees × $8/user/month × 12 months = about $19,200 per year
  • Five years of training at that rate: roughly $96,000

Now hold that against what a single serious phishing incident costs. IBM’s averages are in the millions, but you don’t need the average to make the case: even a modest business-email-compromise wire fraud routinely lands in six figures, and ransomware downtime alone can exceed five years of training spend in a week. If training prevents even one serious incident over five years, it has paid for itself — comfortably. That’s the honest version of the ROI argument, and it doesn’t need an invented percentage to work.

If you’re weighing this against the rest of your security spend, our cybersecurity budget reality check covers where the money actually goes.

What results look like (modelled on published industry benchmarks)

We’re not going to show you named “customer results” with five-digit ROI percentages — you’ve seen those pages elsewhere, and you were right not to trust them.

What we can show you is the pattern published industry benchmarks consistently report: untrained organisations typically start with baseline simulation click rates around one in three users, and sustained simulation programs drive that into the single digits within about a year, while reporting rates climb.

An illustrative example (modelled on those benchmarks, not a client): a 200-person company starts at a 30% baseline click rate. After a few months of regular simulations with on-click microlearning, clicks fall by half and the first wave of employees starts forwarding suspicious emails to IT instead of opening them. By month twelve, the click rate sits in the single digits, the security team gets a steady feed of user-reported phish — some of them real — and the riskiest departments are visible on a dashboard instead of in a post-incident report.

That trajectory, not a magic percentage, is what you’re buying.

FAQ

How much does phishing training cost per employee?

Per-user monthly pricing is standard across the industry. As a representative figure, ThinSky plans start around $8 per user per month, with a lower-rate maintenance tier once your team graduates from the intensive program — request a quote for your actual number. Enterprise awareness platforms are typically quoted in the five figures annually for mid-sized organisations.

How often should employees get phishing simulations?

More often than annually, less often than weekly. Most effective programs land on one to two simulations per user per month, at randomised times so people can’t pattern-match “first Monday of the month is phishing-test day.” Frequency should also adapt: users who keep clicking benefit from more practice, while consistently vigilant users can be tested less often.

Does security awareness training actually reduce breaches?

Honestly: it reduces risk, not to zero. Published benchmarks consistently show simulation-based training cutting click rates from roughly a third of users to single digits over a year, and a lower click rate plus a higher reporting rate means fewer footholds and faster detection. No training program makes an organisation phish-proof — which is why training belongs alongside technical controls like MFA and monitoring, not instead of them.

What happens when our team stops clicking?

You graduate. Under ThinSky’s graduate-out program, once your organisation reaches and holds a strong detection rate over consecutive months, you move to a reduced-frequency maintenance program at a lower per-user rate — or pause entirely and return for periodic refreshers. You shouldn’t pay intensive-program prices for a team that has already built the habit.


Ready to find out where your team actually stands? Start with a pilot of ThinSky’s phishing training — 30 days with a small team, no commitment, and you get the report either way. Want the outside view first? Run a free external security audit to see what attackers see, or email sales@thinsky.com and request a quote. Because Karen’s banana bread is great, but preventing ransomware is even better.