A phishing simulation pilot before a full rollout costs nothing beyond staff time at a free or trial tier, a few hundred dollars at a paid per-seat tier for a 25-to-50-person team, or a few weeks of an administrator's time if you self-host. The two costs that surprise people are not the software: it is the time someone spends running the pilot, and the coaching work that follows every click.
Most "how much does it cost" answers skip the pilot stage entirely and quote annual platform pricing. That skips the decision most small businesses actually face. You do not want to sign a 12-month contract to find out whether simulated phishing changes anything for your team. A pilot answers that question for the cost of a few weeks of one person's time.
TL;DR
- Free tiers and trials exist across the category, so a pilot can cost $0 beyond staff time.
- At a per-seat platform, a 25-to-50-seat pilot for two to four weeks costs a few hundred dollars at most - the arithmetic is simply seats x monthly rate x weeks.
- The real pilot budget line is internal time: someone has to launch the campaign, watch the results and run the debrief.
- Clicks should trigger coaching, not just a spreadsheet row - factor that into the plan.
- Do not sign an annual contract before a pilot proves the cadence sticks.
Why pilot cost matters more than platform pricing
Pricing pages quote annual figures. Annual figures answer the wrong question at the pilot stage: you are not yet deciding whether to buy a platform, you are deciding whether simulated phishing changes behaviour in your team.
A pilot is a bounded experiment: one campaign, a defined group of learners, one clear question. Whether that question is "do our people click this phish?" or "will our managers actually report it?", the cost question is the same: what does it cost to run the experiment before committing to a full year?
The word "pilot" carries three different costs depending on the route you choose, so this article prices each of the three in turn: a free or trial route, a paid per-seat route, and a self-hosted or managed route that sits outside standard software pricing.
Option 1: free tier or trial - $0 out of pocket
Several phishing simulation platforms offer a free tier or trial period. On a free tier you can typically launch a small campaign, select a subset of learners, and watch click and report data come back. A trial usually unlocks the full platform for a fixed number of days, then expires.
Where a free route genuinely works for a pilot:
- A single campaign to a small group is enough to answer "do our people click this?" - you do not need a full year of cadence to learn that.
- Trial windows typically span two to four weeks, which matches the length of a well-scoped pilot.
- No procurement friction: no purchase order, no contract review, no credit card.
Where a free route falls short:
- No coaching loop. A click on a bare-bones tier is usually just a data point. There is no automatic lesson assigned to the person who clicked, and the coaching after the click is the part that actually reduces risk over time. Cyber Aware's phishing simulations build coaching into the click itself, which is why a pilot on a platform that includes coaching tells you more than a raw click count.
- No baseline you can reuse. Without click and report rates recorded in the platform, you have no "before" number to compare the full rollout against later.
- Limited template variety. Free tiers usually expose a handful of templates, which means one round of learning rather than a graduated difficulty ramp.
- No formal reporting. You will not get a report a manager can take to a meeting, which matters if the pilot's whole purpose is to make a case to a decision-maker.
The free route is the right pilot when the question is diagnostic: does our team click obvious phishes? It is the wrong route when the question is whether a monthly phishing cadence will reduce risk over six months, because a cadence needs coaching, tracking and reporting to be meaningful.
Option 2: paid per-seat tier - a few hundred dollars for a typical SMB pilot
Most platforms in this category price per seat - per learner enrolled - billed monthly or annually. That makes pilot pricing simple arithmetic, not a separate product: the pilot is the same per-seat rate applied to a smaller group over a shorter window.
As an illustration only: if a platform charges $3 per learner per month, a 25-person pilot costs $75 for one month or $150 for two. At $5 per learner per month, a 50-person four-week pilot lands around $250. The exact rate varies by vendor, tier and region, so treat those figures as worked examples of the arithmetic, not market quotes - the fastest way to get a real number is a quote based on your headcount.
What the extra spend buys over a bare-bones trial:
- Coaching on click. Anyone who clicks lands on a branded explainer and is enrolled into a short remediation lesson, so the click becomes training rather than just a statistic.
- Reporting the pilot was for. Who clicked, who reported, and how the numbers trend - the artefact that makes the findings visible to a manager, an insurer or a board.
- Template variety and a difficulty ramp. Access to a large template library - Cyber Aware ships more than 100 - so you can start with easy-to-spot phishes and escalate across the pilot window.
- A baseline you can reuse. Pilot click and report rates recorded in the platform become the "before" numbers for the full rollout, so the rollout's early months can be compared against them.
Option 3: self-hosted or managed-service pilots - the real cost is in hours
Two pilot routes sit outside standard per-seat pricing, and their cost is dominated by staff hours rather than software fees.
Self-hosted. Running simulations on infrastructure you control means hosting the campaign server, building templates, and handling your own reporting. Software fees drop, but the pilot now costs the time of whoever runs it - realistically several hours to set up and a few more to analyse results. For a small business without a dedicated security person, this is usually the most expensive option in real terms.
Managed service on top of a platform. Some providers will design and run the campaign for you. That removes your internal time cost but adds a service fee on top of the platform. It suits businesses that want a pilot done but have nobody internally to run it.
What drives the cost up or down
- Headcount. The single biggest driver at per-seat platforms - 25 seats costs half of 50 at the same rate.
- Campaign length. A two-week pilot costs roughly half of a four-week one at the same seat count.
- Route. Free trial, paid tier, self-hosted, or managed service differ by an order of magnitude in real cost.
- What happens after the click. Platforms that assign coaching automatically carry that content in the seat price; platforms that do not leave you to write the coaching yourself - unpaid hours that usually get forgotten.
What a phishing simulation pilot should actually test
A pilot that only measures "did people click?" wastes whatever it cost. Three questions are worth the spend:
- Do our people click the obvious phishes? A realistic baseline click rate against templates in the easy-to-spot range.
- Do our people report what they suspect? Report rate matters more than click rate - a report is the behaviour that stops a real breach, because it starts an investigation.
- Does one coaching intervention move the number? Run a second small campaign two weeks after the first, with coaching between, and see whether the click rate falls.
A pilot that answers all three gives you a baseline click rate, a baseline report rate, and a data point on whether coaching works. With those three numbers, the full-rollout decision is trivial, because the rollout is just the same cadence applied to everyone instead of a test group - and human risk reporting is what turns the trend into something an owner can act on monthly.
Common mistakes when running a phishing pilot
- Running it with no baseline. Record the click rate from the first campaign before you change anything, so later campaigns have something to be compared against.
- Choosing templates that are too hard. A first campaign full of sophisticated spear-phishing produces a discouraging click rate that tells you nothing about your team's actual risk level.
- Skipping the debrief. A pilot whose findings are never written down or presented cannot justify the rollout - which was the point.
- Signing the annual contract the day the pilot ends. Wait a week. The pilot data deserves a look before the invoice does.
- Treating clicks as failure. Clicks are information. A pilot that embarrasses clickers produces under-reporting next time, which is worse than the click itself.
FAQ
Can I run a phishing simulation pilot for free? Yes. Several platforms, including trials and free tiers across the category, support a small pilot campaign without payment. What you give up is usually coaching, reporting depth and template variety.
How many staff should be in a pilot group? Small enough to manage, large enough to learn from: 10 to 50 staff is the typical range, with finance and other high-risk roles included deliberately.
How long should a pilot run? Two to four weeks is enough for one baseline campaign plus one follow-up campaign that tests whether coaching moved the number.
Does pilot pricing differ from a full rollout? Not structurally at per-seat platforms: it is the same rate applied to fewer seats over fewer weeks. Managed-service pilots add a separate service fee.
Is a pilot worth it before signing an annual contract? Yes. A pilot proves the cadence and the coaching work in your team before you commit to a year of spend - which is exactly the failure mode annual contracts create.