Every year, the same line item shows up in the same budget conversation, and every year it is one of the first things questioned. Security awareness training gets treated as a compliance checkbox, a video employees click through once a year to satisfy an auditor, and when budgets tighten, it is an easy target because almost nobody in the room can point to a hard number showing what it actually returns. That is not because the return does not exist. It is because only 33 percent of organizations currently bother to calculate it. The other 67 percent are defending a line item with adjectives instead of arithmetic, which is precisely why it keeps losing budget fights it should win easily.
The organizations that do calculate security awareness training ROI report returns that make almost every other line item in the security budget look weak by comparison, with industry averages ranging from 3.5 times to 6.5 times the program cost, and the widely cited Ponemon Institute study on anti-phishing training found an average one-year return of 37 times program cost, even after accounting for the productivity loss during training itself. Here is exactly how that number gets calculated, what separates a program that actually earns it from one that does not, and the formula to bring into your own next budget conversation.
The formula, in plain terms
Security awareness training ROI follows the same basic formula as any other return-on-investment calculation, substituting avoided costs for received revenue: ROI equals incidents avoided multiplied by the average cost per incident, minus the cost of the training program, all divided by the training cost. The three inputs required are the training cost itself, a measurable behavioral outcome from the program, and the financial value of that outcome.
Training cost is the easy part. It shows up in vendor invoices and budgets with reasonable accuracy: platform licensing, content, staff time to administer the program, and employee time spent completing it. The harder, more valuable part is establishing the behavioral outcome, most commonly the reduction in phishing click rate, and translating that reduction into an avoided cost using either your own organization’s incident history or industry-standard figures for the average cost of a phishing-originated breach.
A worked example, at a realistic small business scale
Here is the calculation at a scale that actually applies to most Orange County businesses, not a Fortune 500 hypothetical. A typical small or mid-size business runs a security awareness program costing $5,000 to $10,000 per year. Before training, a realistic baseline phishing click rate sits between 25 and 35 percent, consistent with industry-wide simulation data. A well-designed program combining regular simulations with immediate, contextual training delivered at the moment of a failed test, rather than a single annual video, brings that click rate down to somewhere between 5 and 8 percent within six to twelve months, a reduction in the range of 60 to 80 percent.
Apply that reduction against the average cost of a phishing-originated incident for a business your size, using either your own recent incident history or an industry benchmark like the Verizon Data Breach Investigations Report, and multiply by how many such incidents you would realistically expect in a year without training. If a $30,000 annual training program prevents even one incident that would have otherwise cost $200,000 in response, legal, and notification expenses, the resulting return exceeds 500 percent, and that is a conservative, single-incident scenario. Businesses running genuinely effective programs commonly report 60 to 70 percent reductions in phishing-related incidents within the first year, which means the realistic return is usually well above that single-incident floor.
Why most programs never earn the number they should
The SANS 2025 Security Awareness Report, surveying more than 2,700 security professionals across 70 countries, identified a persistent maturity gap: most organizations’ programs still sit at the compliance-focused or basic awareness tier, rather than the behavior-change tier where the largest, most defensible risk reductions actually occur. Awareness alone does not reliably translate into behavior. People who know, in the abstract, that they should not click a suspicious link still do it, especially under time pressure or when a phishing lure has been personalized against their current work context.
Two structural problems drive this gap in most organizations. First, chronic under-investment: programs run at less than one full-time equivalent of dedicated attention rarely move past the compliance tier no matter how much is spent on the platform itself. Second, a real disconnect between what security teams assume works and what the data actually shows works. High-volume phishing simulations run without any follow-up training produce only marginal, short-lived improvement. Programs that pair simulations with immediate, contextual micro-training delivered within 24 hours of a failed test, when the mistake is still fresh, produce sustained reductions of 60 to 80 percent over twelve months, because in-the-moment feedback drives far stronger behavioral retention than a scheduled annual refresher ever does.
| Program design element | Low-ROI approach | High-ROI approach |
|---|---|---|
| Training cadence | One annual video to satisfy a compliance requirement | Monthly touchpoints, shown to produce roughly 50% lower click rates than annual-only programs |
| Response to failed simulations | No follow-up, or a generic reminder weeks later | Contextual micro-training within 24 hours of the failed test |
| Content targeting | Identical content for every employee regardless of role or risk | Role-based simulations with targeted coaching for repeat, high-risk offenders |
| Measurement | Completion rate only | Click rate, report rate, and time-to-report tracked over time |
| Realistic 12-month outcome | Click rates stuck at 15 to 25%, unchanged year over year | Click rates under 5 to 8%, a 60 to 80% reduction from baseline |
The AI complication that most ROI models have not caught up to
Every ROI figure cited above assumes a training program is being measured against a threat landscape that has not fundamentally changed the rules. That assumption is getting shakier by the month. AI-generated phishing emails now achieve click rates as high as 54 percent in independent testing, compared to a baseline of roughly 2.7 percent for conventional phishing, matching or exceeding the effectiveness of skilled human attackers at a fraction of the cost to produce. AI-generated voice and video deepfakes are climbing fast in the attacker toolkit as well, which means training content built around yesterday’s obvious phishing red flags is training employees to recognize a threat that increasingly does not look like that anymore.
This does not invalidate the ROI case for training. It raises the bar for what a program actually needs to teach. A program measuring its success purely against static, years-old simulation templates is very likely overstating its real-world protection, since the threat those simulations represent has already moved. The highest-ROI programs in 2026 pair behavior-focused training with technical controls like enforced MFA and out-of-band verification for financial requests, precisely because AI-driven attacks now succeed often enough that training alone, however well designed, should not be the only layer standing between an employee and a costly mistake.
How to actually calculate your own number
- Establish your baseline click rate through an initial phishing simulation before any new training begins, since you cannot demonstrate improvement without a starting point.
- Track click rate, report rate, and time-to-report on an ongoing basis, not just completion percentages, since those three behavioral metrics are what actually drive the financial outcome.
- Use your own incident history where you have it, and industry benchmarks like the Verizon DBIR where you do not, to establish a realistic average cost per phishing-originated incident for a business your size.
- Apply the formula directly: multiply your estimated incidents avoided by that average cost, subtract your total training program cost, and divide by the training cost to get your ROI multiple.
- Bring the number, not the adjective, to your next budget conversation. A CFO presented with “peer organizations achieve 4.5x ROI, and our one credential compromise last quarter cost $68,000 in direct response costs” is working with something concrete to approve, not a vague assurance that training is important.
The honest version
Security awareness training has one of the strongest, most independently verified ROI profiles of any investment in a typical security budget, and it keeps losing budget arguments anyway, almost entirely because so few organizations actually measure it. The 67 percent of businesses that never calculate their own number are defending the line item with hope. The 33 percent that do measure it are walking into budget conversations with returns most other departments could only dream of showing their own leadership.
Building the case is not complicated. It requires a baseline, ongoing measurement of the behaviors that actually matter, and the same simple formula used to justify any other business investment. What it does not require is faith. The numbers, done honestly, already make the case on their own.
Intelecis runs behavior-focused security awareness training for Orange County businesses, with role-based simulations, immediate contextual coaching after failed tests, and ongoing tracking of click rate, report rate, and time-to-report, the metrics that actually let you calculate a real ROI number for your board or your CFO. NSA-Accredited, with documented experience across healthcare, defense, legal, and accounting environments. Book a free security assessment and we will show you where your current program actually stands.
Get Your Free Security Assessment →
📞 949-266-2088 · Fullerton, CA · NSA-Accredited · Serving OC since 2010
Related reading:
Cybersecurity Services for OC Businesses ·
Security Awareness Training ·
The 3 IT Decisions CEOs Make That Their CFOs End Up Paying For ·
Ransomware as a Service: Why Cybercrime Is Now a Subscription Business ·
Schedule Your Free Security Assessment

