The comparison lands on the same desk in the same week: a staff member clicked a fake invoice, and a security awareness platform quote comes in at roughly the cost of cleaning that up. The question is whether training genuinely changes what people do, or whether it is an expense that makes everyone feel diligent while the real defences live somewhere else in the budget.
TL;DR
- For most teams of five or more that live in email, payments or customer data, yes — one avoided incident typically pays for several years of training.
- Training does not stop attacks on its own. It lowers the odds that a person opens the door when a technical control misses.
- The value is measurable: phishing click rates, reporting rates and completion records, tracked quarter over quarter.
- Platforms price per seat, so compare tracking and reporting capability, not the size of the video library.
- The bigger risk of skipping it is not one bad click — it is arriving at an insurance renewal or audit with no evidence at all.
Why this matters in 2026
The Australian Signals Directorate's Annual Cyber Threat Report keeps landing on the same conclusion year after year: small businesses file more cybercrime reports than almost any other category, and the entry point in most cases is not exotic. It is a phish, a compromised email account or a scam that a person interacted with. The ASD publishes those numbers on its reports and statistics page, and the trend line has pointed up for a decade.
At the same time, the people who price your risk have changed the question. Cyber insurers increasingly want evidence of staff training at renewal, not a promise that someone watched a video once. Auditors working against ISO 27001 or ASD's Essential Eight want completion records and repeat testing. That quietly moves training from nice-to-have to evidential: a program either produces records you can hand over, or it does not count at all.
What training actually changes
Good security awareness training does three things, and it is worth separating them because vendors blur them together.
First, it builds recognition. Staff learn what a credential-harvesting page looks like, why a payment-detail change request arriving by email deserves a phone call, and what a fake calendar invite or shared-document notification feels like. Recognition is the part most people think of when they picture training, and it is the easiest part to deliver.
Second, it builds the reporting habit. A team that forwards a suspicious email to IT within minutes turns every staff member into a sensor. A team that silently deletes the same email leaves you blind. The reporting habit is worth more than perfect recognition, because even a click that gets reported is a contained incident instead of a discoverable one.
Third, it creates the paper trail. Completion records, simulation history and repeat testing are what an insurer or auditor actually inspects. A structured program documented through something like Cyber Aware's training portal produces that trail as a by-product; a once-a-year lunchroom session produces a memory.
Where training fails
Most disappointment with security awareness training traces back to three patterns, none of which are the content itself.
The one-off session. A single annual course produces a brief bump in attention that fades within weeks. Attackers do not run annual campaigns; they run continuous ones. The fix is cadence — short, repeated touchpoints through the year rather than one long session.
The generic program. Content built for a generic office worker lands flat when your team handles invoices, tenders or patient data. The emails your staff actually need to survive are the ones pretending to be your bookkeeper, your biggest client and your own domain.
The punishment model. When failing a simulated phish means a meeting with HR, people learn to hide clicks, not to report them. Programs that measure only failure rates tend to get exactly that: quiet failures. The metrics that matter, and how to present them to a board or an insurer, are covered in human risk reporting.
How to tell whether yours is working
A training program either shows up in numbers or it does not. The four that matter:
- Click rate trend — the share of staff who click a simulated phishing email, tracked across consecutive campaigns. One campaign tells you almost nothing; the direction across four or five tells you everything.
- Reporting rate — how many suspicious emails get reported, which is the habit that actually saves you.
- Time to report — minutes from delivery to report. Faster reporting means smaller incidents.
- Completion coverage — who has completed what, including contractors and new starters.
If nobody in the business can answer what the click rate was last quarter, the program is not measurable, and what cannot be measured will not survive its first renewal conversation. A gap assessment is the quickest way to find out where the program stands today.
What it should cost
Awareness platforms price per seat, usually on an annual subscription. Exact numbers vary by vendor and features, so it is not honest to quote a figure here — but the comparison that matters is not price per seat in isolation. It is what you get for it: phishing simulation, tracking, reporting you could forward to an insurer, and content your team will actually finish. A side-by-side of how platforms differ on exactly those points is in the Cyber Aware comparison.
Two free baselines are worth doing regardless of what you buy. Cyber Wardens offers free, self-paced modules built for Australian small business owners at cyberwardens.com.au, and the ASD maintains practical guidance in its small business cyber security guide that any program should be read against. Free material covers awareness; it is the tracking and evidence layer that paid platforms add.
When it is not worth it
Honesty requires the exceptions. A sole trader with strong basics — multi-factor authentication everywhere, long passphrases, tested backups — gets limited marginal value from a formal awareness program, and the ASD's own individual guidance covers more of their risk than a corporate course would. A two-person team that already runs phishing simulations informally may be overspending on a platform.
The other honest exception: a business that will not commit to cadence. One session a year, no simulations, no follow-up, is close to throwing the money away. If the organisation cannot fund or schedule a quarterly rhythm, it is better to spend less on free government resources now and build the program properly later than to buy an annual checkbox.
FAQ
How long before training shows measurable results? Recognition improves within the first few weeks. Behavioural metrics — click rate and reporting rate — usually need two to four campaigns over several months before a trend is visible.
Is annual training enough? No. One session a year fades long before the attackers take a day off. Quarterly touchpoints with short refreshers hold the habit.
Does awareness training help with cyber insurance? It increasingly does. Insurers at renewal increasingly ask for training completion records and evidence of repeat testing, which a tracked platform produces automatically and a one-off session cannot.
What should we do about the staff member who keeps clicking? Treat repeat clickers as a coaching case, not a disciplinary one. Extra targeted training and a check of their email security settings beats a conversation that teaches the rest of the team to stay quiet.
Can we just use free training? Free programs like Cyber Wardens and the ASD's guides are a genuine starting point. What they do not give you is completion tracking and simulation history — the parts an auditor or insurer inspects.
Does training replace technical controls? No, and nothing should be sold as if it does. Multi-factor authentication, patched systems and tested backups stop most attacks outright; training covers the human layer those controls miss.
One last thing
The businesses that regret spending on awareness training are almost never the ones that got phished anyway. They are the ones that ran it once, measured nothing, and concluded it did not work. The program is the point, not the purchase.