How to choose a security awareness platform for your small business

Choose a security awareness platform by six criteria: monthly cadence, per-person reporting, simulation safety, framework mapping, automation and price. 2026 checklist.

A security awareness platform combines three jobs in one subscription: it teaches staff through short monthly lessons, tests them with phishing simulations, and reports the results as evidence. Choose one by six criteria — monthly cadence, per-person reporting, simulation realism and safety, framework mapping, automation, and per-employee price (the 2026 market runs from about $10 to $72 per employee per year) — and score every vendor against the same checklist before you sign. This guide is that checklist.

What a security awareness platform actually does

The three jobs are separable, and vendors differ in which ones they actually do:

JobWhat it looks likeWhy it matters
Teach5-10 minute monthly lessons, role-based extras for finance, reception and executivesBuilds the reflexes that stop an attack
TestMonthly phishing simulations with immediate, blame-free coachingMeasures whether the lessons stuck
ReportClick rate, report rate and completion per person, trended over timeEvidence for insurers, clients and auditors

A platform that only teaches is an online course. A platform that only tests is a measurement tool. The reporting job is the one that turns the subscription into something a third party will accept — and it is the job most often missing from the cheapest options.

The six criteria that actually matter

1. Cadence, not catalogue. The benchmark reductions the industry quotes — roughly a third of untrained staff clicking a simulated phish, falling to 4-5% after twelve months of monthly training — are measured on a monthly cadence. A library of 500 courses delivered quarterly will not reproduce them. Ask what the default delivery rhythm is, not how big the library is.

2. Per-person reporting. Company-wide averages hide the handful of people who carry most of the risk. Look for click and report history per person and a risk view that ranks who needs coaching — the core of human risk reporting.

3. Simulation realism and safety. Lures should mirror the emails your staff actually receive: invoice and payment-change requests, fake Microsoft 365 login pages, MFA approval prompts. And the landing pages should collect nothing — ask directly what happens if someone types real credentials into a simulated page.

4. Framework mapping. If your obligations reference the Essential Eight — ASD's eight essential mitigation strategies — or SMB1001, reports should map your training and simulation evidence to those controls, not export generic spreadsheets you then have to translate yourself.

5. How much runs itself. Auto-enrolment of new starters, scheduled simulation campaigns, automated reminders, a one-click report button deployed to every mailbox. Automation is the difference between a programme that still runs in month nine and one that decayed after the launch push.

6. Price that matches your headcount. Per-employee-per-year, with simulations included rather than bolted on.

What it should cost in 2026

Team sizeTypical annual costWhat that buys
10-20 staff$100-$1,400Monthly lessons and simulations for the whole team
50 staff$900-$1,800The published benchmark band for a 50-person business
100+ staff$1,000-$7,200+Volume tiers; negotiate simulations and reporting in

Published 2026 price bands run from about $10 to $72 per employee per year, and a 50-person business typically lands between $900 and $1,800 annually. Two traps to price in: simulation add-ons charged separately from training, and setup or onboarding fees that double the first-year bill. A pilot at a free or trial tier should cost nothing but staff time before you commit to a full rollout.

Red flags on a vendor's pricing page

Questions to ask before you sign

  1. What is the default cadence for lessons and simulations, and can we change it?
  2. Show me click rate and report rate for one person, over six months.
  3. What happens on the landing page if someone enters credentials?
  4. Can the reports be mapped to the Essential Eight or SMB1001 evidence an auditor asks for?
  5. What is set up automatically — enrolment, campaigns, reminders, the report button?
  6. What does year two cost, and what is excluded from the headline price?
  7. How do you handle a staff member who clicks three months in a row?

Vendor answers to questions 2 and 4 are where most products in this market separate themselves: the ones with evidence-grade reporting answer in a screenshot, the ones without answer in a brochure.

The 30-day evaluation plan

  1. Week 1 — baseline. Run one unannounced simulation across the whole team. Do not coach first; you need the true starting click rate.
  2. Week 1 — deploy the report button. One-click reporting in every mailbox, so reports can be credited from day one.
  3. Week 2 — first lesson. Ten minutes, phishing-focused, completed by everyone.
  4. Week 3 — second simulation. Different lure, same audience.
  5. Week 4 — read the evidence. Export or screenshot what the platform would show an insurer or auditor. If the evidence pack is thin or generic, that is your answer.

Two data points — the baseline and the week-3 simulation — already show the trend that decides it: click rate falling, report rate rising. If neither moves in 30 days, the problem is the platform, not the staff.

FAQ

How much should a small business spend on a security awareness platform?

About $10-$72 per employee per year in 2026; a 50-person business typically pays $900-$1,800 annually. Anything above that needs a specific justification — enterprise reporting or managed delivery.

Is a platform necessary, or can we run training ourselves?

You can run lessons yourself, but simulations and per-person reporting are impractical without tooling, and the reporting is the part insurers and auditors ask to see.

What is the single most important feature?

Per-person reporting. Company averages hide the risk; the named handful who need coaching is what makes the programme work.

Do we need a platform that maps to the Essential Eight?

If any of your obligations or contracts reference it, yes — mapped reports save days of manual collation at renewal or audit time.

Should simulations be managed by the vendor or run in-house?

Either works; what matters is that campaigns actually happen monthly. Choose managed delivery if nobody internal owns the calendar.

How long before a platform shows results?

Click rates fall measurably within the first quarter of monthly simulations; the benchmark 4-5% level takes about twelve months of consistent cadence.

Can we trial a platform before committing?

Yes — insist on it. A baseline simulation plus one lesson inside a 30-day trial tells you more than any demo.

Related guides

Ready to deploy

Same playbook.
Your brand.

Cyber Aware's Human Risk Score works the same way for every MSP partner - under your brand, on your cadence.