Yes for most teams — a five-person business loses as much from one phishing incident as a fifty-person one, and per-seat pricing with no seat minimum means you only pay for five. Cyber Aware prices per seat with no minimums, so the economics that make simulations obvious for large companies scale all the way down: five seats at the same per-seat rate, one admin, and a year of campaigns scheduled from a single setup.
Key takeaways
- The cost asymmetry decides it. A single successful invoice-fraud phish can cost a five-person business more than a year of simulation training — the ACSC consistently ranks business email compromise among the most damaging scam types for small Australian businesses.
- No seat minimum means no penalty for being small. Cyber Aware charges per seat with no minimums, so a five-person team pays for exactly five.
- Small teams run simulations faster than big ones. One sending group, one directory sync, a 12-month campaign calendar from one chatbot conversation.
- The evidence is the same at any size. Who clicked, who reported, and a branded PDF report after every campaign — plus an average 80% reduction in clicked links within eight months on monthly cadence.
Is phishing simulation worth it for a five person team?
Weighing the two sides honestly:
| Factor | For a five-person team | Reality check |
|---|---|---|
| Cost | Per-seat with no seat minimums — five seats, no waste | Pricing is quoted, so you confirm the rate with sales first |
| Risk exposure | Every staff member handles money, clients or both — no one to hide behind a department | Small teams often have broader access per person, so one click costs more |
| Setup effort | Under a week: sync staff, schedule 12 months, done | Still one decision to make: how clickers get coached, not punished |
| Evidence | Click, report and completion rates per person, PDF after each campaign | Useful for insurers and client security questions, not just internal |
| Expected payoff | Average 80% reduction in clicked links within eight months on monthly cadence | Assumes monthly runs — one annual test does not move the number |
Why small teams arguably need it more
Large companies buy phishing simulations to cover thousands of staff. A five-person business has a different problem: there is no redundancy.
- No IT department between you and the attack. In a five-person company, whoever opens the malicious attachment is also whoever can authorise the payment. There is no security team catching it downstream.
- Everyone is a high-value target. In small businesses the owner's and bookkeeper's inboxes are the prize — exactly who invoice-fraud and CEO-fraud emails target.
- One compromise can be existential. The Australian Cyber Security Centre's small-business guidance treats a single business email compromise as a serious incident, not a rounding error; for a team of five, the money and the trust both sit in one place.
- Compliance questions reach you directly. Clients, insurers and cyber-insurance renewals increasingly ask for evidence of security awareness training. A per-campaign report is a one-page answer.
What makes it work at this size
The mechanics matter more for small teams, because there is no admin to babysit the programme:
- Enrolment is a sync, not a task. Staff arrive via Microsoft 365 or Google Workspace sync, a CSV upload, or a signup link — with a welcome email on arrival.
- The calendar builds itself. Cyber Aware's setup chatbot asks which services the company uses, then schedules 12 months of varied phishing campaigns from that one conversation.
- Clicks convert to training automatically. Anyone who clicks is auto-enrolled into a failed-phishing course — no awkward follow-up email, no manual assignment.
- No credential harvesting. Simulations record who clicked and who reported, never passwords — so running the programme creates no new risk to your own systems.
- Reports arrive without a chase. A branded PDF of who clicked and who reported auto-sends to admins when each campaign completes.
When five-person teams skip it
Honest answer: it is not for everyone, yet.
- Zero budget today. If there is no room at all, CyberWardens — the government-backed program run through COSBOA — offers free education content as a first step, without click-rate tracking.
- No email domain of your own. Teams running entirely off a single shared webmail address get less from simulation cadence.
- Already covered in an MSP retainer. If your managed service provider runs training and simulations for clients under its own platform, ask before buying twice — the reporting may already exist.
How to run it as a team of five
- Sync or upload the five staff, and let new starters auto-enrol on arrival.
- Schedule the 12-month calendar in one setup — monthly cadence is what produces the improvement curve.
- Start with easy-spot templates and ramp difficulty as report rates climb.
- Decide before launch that a click gets a 3-minute lesson, not a lecture.
- Read the first campaign as a baseline; judge the trend from month two onward, targeting the 80%-reduction benchmark by month eight.
From there the programme runs itself, and the Human Risk Score shows each month who is on track and who needs a nudge — one number per person, lower is better.
FAQ
Is phishing simulation worth it for a five person team? Yes, for most. Per-seat pricing with no seat minimum means five seats cost exactly five seats' worth, and a single successful phish in a small business routinely costs more than a full year of the programme.
How much does it cost for five people? Pricing is quoted per seat with no minimums — you pay for five seats at the same per-seat rate larger teams pay. Ask for the quote; there is no published self-serve calculator.
Isn't this overkill for such a small team? The opposite, in one sense: with no IT department, every person is both the first and the last line of defence. The programme replaces the security function a larger company has.
How long until a small team sees results? The first campaign is a baseline — click rates are usually highest there. On monthly cadence the published benchmark is an average 80% reduction in clicked links within eight months.