A security awareness training budget is easier for a board to approve when it connects money to business decisions, measurable risk and accountable owners. The goal is not to present a course catalogue. It is to show what the organisation needs people to do differently, how the program will practise those behaviours and what evidence leaders will receive in return.
This guide gives Australian organisations a board-ready way to build the budget without inventing a return-on-investment percentage or treating training as a replacement for technical controls.
TL;DR
- Start with the behaviours and business processes that need protection, not with a vendor price.
- Separate one-off setup, recurring delivery, internal time, measurement and contingency.
- Tie each budget line to an owner, an output and a decision the board can review.
- Use completion, overdue work, phishing clicks, phishing reports and time to report as a balanced evidence set.
- Present the investment as one layer of a wider security program, alongside identity, technical and response controls.
What the board is really approving
The board is not only approving access to an online course. It is approving a management system for human risk: who receives learning, which behaviours are practised, how suspicious activity is reported, who follows up exceptions and how leaders know whether the program is improving.
That distinction matters because training cannot block every attack. The Essential Eight describes eight mitigation strategies that make it harder for adversaries to compromise systems. Awareness helps people use those controls and respond safely, but it does not implement MFA, patch applications, restrict administrative privileges or recover an affected system.
Build the budget around that boundary. A credible proposal asks for the resources required to improve specific decisions, then names the technical or process owners who must address risks training cannot solve.
Step 1: write the risk case in business language
Begin with three questions:
- Which decisions could expose money, personal information, credentials or customer access?
- Which groups make those decisions most often?
- What would a safer response look like in the real workflow?
For finance, the behaviour may be verifying a supplier bank-detail change through a known channel. For HR, it may be checking a request for employee records before sharing them. For administrators, it may be refusing an unexpected MFA prompt and reporting it. For executives, it may be slowing down an urgent payment or data request that relies on impersonation.
The ACSC Annual Cyber Threat Report 2024–25 gives Australian organisations a national threat baseline, but it is not a budget by itself. Use its findings alongside internal incidents, helpdesk themes, phishing results, audit findings, customer requirements and planned business changes.
Write the case as: risk, affected process, target behaviour, proposed activity and evidence. This gives directors something better than a generic statement that staff are the weakest link.
Step 2: set the scope before requesting a quote
Record the population that the budget must support:
- Employees, contractors and temporary workers.
- New starters who need baseline learning during onboarding.
- Executives and board members who handle high-impact approvals.
- Privileged users and people with access to sensitive systems.
- Managers who must review overdue work and support remediation.
Then list the delivery requirements. Do you need short lessons, quizzes, role-based assignments, phishing simulations, automated reminders, identity synchronisation, white-labelling or reports for different clients? A smaller organisation may need a simple recurring program. An MSP may need separate client portals and evidence that can be shared under the partner’s brand.
The Cyber Aware training page describes the platform’s training approach. Use any vendor page as an input to scope, not as proof that the product will fit your workflow.
Step 3: divide the budget into five buckets
1. Program setup
Include discovery, risk mapping, audience design, policy alignment, identity integration, branding, baseline configuration and the first reporting template. Setup is often underestimated because it occurs before the first assignment.
Ask for a named deliverable for each item. For example: a role matrix, an approved reporting route, an onboarding assignment, a simulation plan and a board dashboard definition. If a setup activity has no owner or output, remove it or clarify it before approval.
2. Recurring platform and content
This bucket may include the subscription, learner seats, content access, phishing simulation capability, support and renewal terms. Confirm which users count as billable, how inactive accounts are handled, whether contractors need access and whether the price changes at renewal.
Do not compare subscriptions only by the number of courses. Compare the workflow: assignment, practice, reporting, remediation, evidence and administration. The Cyber Aware comparison page can be one input to that procurement review.
3. Internal program time
A platform does not write the organisation’s reporting policy, approve realistic scenarios or chase a manager who ignores an exception list. Estimate time for security, IT, HR, privacy, legal, communications, department owners and managers.
Separate launch time from steady-state time. A first-year budget may need more design and integration effort; later years may need less setup but still require content review, campaign administration and quarterly reporting.
4. Practice and measurement
Budget for simulations, role-based exercises, tabletop sessions, survey work and analysis. The Cyber Aware phishing page describes a way to practise suspicious-message decisions; your proposal should also explain the reporting route and the response after a person reports or clicks.
Include time to define metrics. NIST SP 800-55 Vol. 1, Measurement Guide for Information Security, published in December 2024, explains how organisations can identify and select measures that assess policies, procedures and controls. Use that principle to choose a small, stable set rather than filling the board pack with every available number.
5. Contingency and improvement
Reserve capacity for a new business process, material incident, acquisition, regulatory change, supplier issue or content refresh. Do not label an unexamined buffer as risk reduction. State what would trigger its use and who can approve the change.
Step 4: choose measures the board can understand
Use a balanced set of leading and outcome measures:
- Completion by due date: shows whether the program reaches the intended audience.
- Overdue rate: shows where management follow-up or enrolment needs attention.
- Simulation click rate: shows one unsafe decision in a controlled exercise.
- Simulation report rate: shows whether people use the reporting route.
- Time to report: shows how quickly the organisation can create an alert.
- Relevant incident or helpdesk patterns: shows whether the same process is creating repeated confusion.
Never present a 100% completion rate as proof that the organisation is safe. Never treat a falling click rate as success if the reporting route is broken or the audience has learned to ignore the test. Define the cohort, time window and calculation before the first campaign so that the comparison remains honest.
The human risk reporting view can help combine learning, quiz and phishing signals into an actionable picture. Use individual results to support people and improve processes, not to create public rankings.
Step 5: build the board paper
A board-ready proposal can fit into seven parts:
- Decision requested: the amount or budget range, approval period and accountable executive.
- Risk being addressed: the business processes and behaviours that need improvement.
- Program design: baseline learning, role-based content, simulations, reporting and review cadence.
- Cost structure: setup, recurring platform, internal time, measurement and contingency.
- Alternatives considered: do nothing, rely on annual training, build internally or procure a managed platform.
- Evidence plan: the metrics, owners, reporting dates and decision thresholds.
- Dependencies: technical controls, policy changes, reporting route and manager participation.
Give the board a clear no-action consequence without exaggeration. For example, if the program is not funded, state that the organisation will continue to have an unmeasured or inconsistently practised response in the named workflows. Do not claim that a specific dollar loss will occur unless internal evidence supports it.
Step 6: compare options on total operating effort
Use the same scorecard for every option:
- Can it enrol the right people and remove leavers?
- Can it support new starters and role changes?
- Can it practise realistic phishing and reporting?
- Can managers see the exceptions they must act on?
- Can the security team export evidence without manual spreadsheets?
- Can the provider support the required regions, languages and accessibility needs?
- Can the platform preserve client separation if an MSP will operate it?
- Are content, seats, support, integration and renewal terms clear?
A cheaper licence can become a more expensive program if the team spends every month reconciling users, chasing reports or rebuilding board evidence. Conversely, an expensive feature set is waste if the organisation will not use it. Score the operating model, not just the feature list.
Step 7: make the first 90 days specific
The budget becomes more credible when the first quarter is already designed:
- Days 1–30: confirm the audience, reporting route, baseline lesson, owners and measurement definitions.
- Days 31–60: run the first low-complexity simulation, review reports and resolve process confusion.
- Days 61–90: introduce a role-based scenario, assign targeted follow-up and present the first trend with its limitations.
NIST SP 800-50 Rev. 1, Building a Cybersecurity and Privacy Learning Program, published in September 2024, recommends a lifecycle approach that can be adapted as organisational needs change. Use the first 90 days to test whether the program is reaching the right people and changing the intended decision before scaling the calendar.
Common budget mistakes
Asking for a course library instead of a program
A library does not define the audience, reporting route, follow-up or board evidence. Budget for those operating pieces.
Hiding internal time
If security, HR or managers must run the program, their time is a real cost. Showing it improves the decision and makes ownership visible.
Promising a percentage reduction
There is no defensible universal reduction that applies to every organisation. Use the organisation’s own baseline and report movement across comparable campaigns.
Measuring only completion
Attendance shows reach, not safe decision-making. Pair it with practice and reporting measures.
Treating training as the whole control
Map each behaviour to the technical and process owner that must support it. Training cannot fix a missing MFA policy, unsafe payment process or excessive privilege on its own.
FAQ
How much should a board budget for security awareness training?
There is no responsible universal amount. Calculate the population, delivery model, recurring platform cost, internal program time, practice, measurement and contingency, then test the total against the organisation’s risk and operating model.
What should be included in a first-year budget?
Include setup, integration, content and seat costs, internal design and administration, simulations, reporting, manager follow-up and a defined improvement allowance. Separate one-off launch work from recurring annual work.
Should training be funded by security, HR or compliance?
Assign one accountable executive, then share the operating responsibility. Security may own risk and measurement, HR may own onboarding, IT may own integration and business leaders may own the decisions their teams make.
What should the board see each quarter?
Show the target cohort, completion and overdue rates, simulation clicks and reports, time to report, material incidents or themes and the actions that need leadership attention. Keep definitions and comparisons consistent.
Is phishing simulation worth budgeting for?
It can be useful when it rehearses the reporting route, produces comparable evidence and is followed by support or process improvement. A simulation without a clear purpose or response path creates noise.
How do you defend the budget during a cost review?
Show the business process, target behaviour, delivery activity, owner, cost and evidence for each line. Compare the proposed program with the cost and limitations of doing nothing, annual-only training or a manual alternative.
One last thing
The strongest board budget does not promise that training will prevent every incident. It promises something more credible: the organisation will practise defined responses, measure whether people can use them and give leaders a clear view of the remaining gaps.
Sources
- NIST SP 800-55 Vol. 1: Measurement Guide for Information Security, published December 2024.
- NIST SP 800-50 Rev. 1: Building a Cybersecurity and Privacy Learning Program, published September 2024.
- ASD Essential Eight, Australian baseline guidance.
- ASD Annual Cyber Threat Report 2024–25, published 14 October 2025.