The ROI of security awareness training is measured by two behavioural numbers, not a revenue line: the phishing click rate falling and the report rate rising, quarter over quarter. A programme is working when the share of staff who take the bait drops — the industry benchmark moves from 33.1% before training to 4.1% after twelve months — and when staff hand suspicious messages to IT faster. Those two trends are the measurable proxy for the incidents that never became breaches.
TL;DR
- The industry phishing benchmark falls from 33.1% before training to 4.1% after 12 months (KnowBe4, 14.5 million users measured).
- The average breach cost USD 4.44 million globally and USD 2.55 million in Australia in 2025 (IBM Cost of a Data Breach Report).
- The human element sits in about 60% of breaches (Verizon 2025 DBIR) — that is the share of risk training addresses.
- Measure five numbers: click rate, report rate, repeat clickers, completion rate and time-to-report.
- Cyber Aware's benchmark: an average 80% reduction in clicked links by month eight on monthly programmes.
How to measure the ROI of security awareness training
Track behaviour, price the avoided incidents, and report the trend — not a made-up dollar return. The trap with training ROI is trying to attach revenue to a control that produces absence: breaches that never started, credentials that never left, payments that never redirected. The credible measurement is (1) proof that the human layer is improving, and (2) the cost of the incidents you are pricing against.
The five metrics that matter
| Metric | What it tells you | Good trend |
|---|---|---|
| Phishing click rate | How many staff take the bait in simulations | Falls from ~33% baseline toward single digits over 12 months |
| Report rate | How many staff raise the alarm on suspicious messages | Rises month over month; the culture metric |
| Repeat clickers | Who keeps failing — the targeted-coaching list | Shrinks toward zero |
| Completion rate | Whether the programme is actually running | Holds above 90% |
| Time-to-report | How fast a real or simulated phish gets reported | Falls from days to minutes |
Click rate alone is not ROI — a team can click less and report nothing, which means the next real attack still arrives unannounced. The report rate is the earliest signal the culture is working, and it is usually visible from month two of a monthly programme.
The benchmark data to measure against
KnowBe4's 2025 Phishing by Industry Benchmarking Report — 67.7 million simulated phishing tests across 14.5 million users — measured the average organisation's phish-prone rate at 33.1% before training, dropping about 40% within 90 days and to 4.1% after 12 months. That is an 86% reduction in susceptibility to the attack type behind most breaches, and it is the shape your own numbers should follow: a steep first-90-days drop, then a slow grind toward low single digits.
Cyber Aware's own benchmark on monthly programmes is an average 80% reduction in clicked links by month eight, with report rates climbing past 50%. If your click curve is flat after three months, the problem is cadence or content difficulty — not the concept.
Pricing what you are avoiding
The return side of the equation is the incident cost training reduces the probability of:
- USD 4.44 million — IBM's 2025 global average breach cost, the first decline in five years.
- USD 2.55 million — the same report's average for Australian organisations.
- USD 1.53 million — average ransomware recovery excluding the ransom (Sophos State of Ransomware 2025).
- 60% — the share of breaches involving the human element (Verizon 2025 DBIR), the slice of risk that training actually touches.
For an Australian small business the honest benchmark is smaller still — the ASD's 2024-25 report puts the average self-reported cybercrime loss for small business at $56,600 — but it lands against the same logic: a year of training for a 50-person team costs orders of magnitude less than even one contained incident.
How to build the ROI report
- Baseline before you start. Run one phishing simulation before the programme launches. That number is your 33%-style starting point, and without it nothing after it can prove improvement.
- Pull the monthly trend. Click rate, report rate and completion per month. Human risk reporting turns them into per-learner scores and branded PDFs a director can read without translation.
- Price the avoided risk. Multiply your exposure — the IBM or ASD benchmark scaled to your size — by the human-element share. That is the risk pool the programme addresses.
- Subtract the programme cost. Platform licences plus staff minutes. The comparison is lopsided on purpose.
- Report quarterly. Two slides: the behaviour trend and the avoided-cost context. Falling clicks and rising reports are the evidence; the breach averages are the stakes.
What ROI measurement gets wrong
- Counting completions as outcomes. Attendance is not behaviour. A 100% completion rate with a flat click rate is a programme that runs and does nothing.
- Judging on one campaign. A single hard simulation dips the numbers; the six-month line is the verdict.
- Claiming training stops all breaches. Exploited vulnerabilities led technical root causes at 32% in Sophos' 2025 survey — training does not patch servers. The claim is the human slice, which is the majority slice.
- No reporting channel. If staff have nowhere to report, the report rate metric measures nothing. Set the channel before measuring the culture.
Awareness training covers the monthly cadence and auto-enrolment end of this; a security gap assessment sizes the technical gaps that sit outside training's reach. If you are comparing platforms on reporting depth, the comparison page breaks down how the measurement stacks up.
FAQ
How to measure the ROI of security awareness training? Track phishing click rate, report rate, repeat clickers, completion and time-to-report monthly; price the avoided incident against the USD 2.55 million Australian breach average (IBM 2025) and report the trend quarterly.
What click rate reduction should we expect? The industry benchmark falls from 33.1% before training to 4.1% after 12 months (KnowBe4 2025); Cyber Aware's monthly-programme benchmark is an average 80% reduction in clicked links by month eight.
Which single metric proves the programme is working? The report rate. Rising reports with falling clicks is the signature of a workforce that spots attacks; falling clicks alone can hide a silent workforce.
How long before we can show ROI? Behaviour moves within two to three monthly campaigns; the benchmark reduction is measured at month eight to twelve. Present the trend from month one.
Does training ROI show up in fewer breaches? It shows up in the human-failure slice — about 60% of breaches involve a human element (Verizon 2025 DBIR). Stopped phishes and caught fraud attempts are the incidents that never entered your numbers; count and report them.
One last thing
Count the incidents that did not happen. Every phish reported, every fake invoice caught, every suspicious MFA prompt denied is a breach that never reached your ledger. Log them through the year and put the total in the annual summary — it is the only line where the return on training is visible, because the costs it prevented were never invoiced.