HireACISO

Security awareness training that works

Awareness training costs $15 to $45 CAD per person per year and is the cheapest line in a security budget. It is also the one most often bought to satisfy an auditor and then measured in a way that guarantees it changes nothing. The fix is not more content, it is measuring whether people report rather than whether they click.

Last reviewed 2026-09-01Written by Jacob Masse, TrazTech Inc.

Security awareness training in Canada runs $15 to $45 CAD per person per year for a platform with phishing simulation included, which is $3,000 to $12,000 CAD a year for a company of 200 to 300 people. Almost every framework expects it, so the question is what to buy and how to measure it. Most companies get the second part wrong.

$15 to $45 Per seat per year, CAD

Above 30% Phishing report rate worth targeting

Under 10 min Median time to first report

Stop measuring click rate

Click rate is the standard metric and it is close to useless on its own. It falls as people learn what a simulation looks like rather than what a phish looks like, and it can be driven to near zero by sending easy simulations. Zero would not help you: a determined attacker needs one person on one bad day. What you need from your workforce is speed of warning.

Awareness metrics and what each one really tells you
MetricTells youUse it?
Training completion That people clicked through slides. Required evidence for an auditor and nothing more For the audit file, not the board pack
Click rate Partly awareness, mostly the difficulty of the simulation you chose Only alongside report rate, and never as a target
Report rate Whether people help when something looks wrong. The number that matters Yes. Target above 30 per cent and rising
Median time to first report How fast you would learn about a real campaign Yes. Under ten minutes is achievable and genuinely useful
Repeat clickers Where targeted coaching goes Yes, quietly and without naming people in public
Reports of real phishing that was not a simulation That the reporting habit generalised beyond the game Yes. This is the outcome you were buying

The report button is worth more than the course

If you do one thing, put a one-click report button in the mail client, route it somewhere a human reads, and acknowledge every report including the wrong ones. A company where reporting is easy and appreciated finds out about a campaign within minutes. A company where reporting means forwarding to a shared mailbox and hearing nothing back finds out from a customer. The difference costs almost nothing and outperforms any amount of additional content.

What to buy at each size

Awareness training spend by company size, Canada, CAD per year
SizeAnnual costWhat to buy
Under 50 $750 to $2,200 A basic platform with simulation, quarterly. Skip the custom content entirely
50 to 250 $2,200 to $9,000 Platform plus role-based modules for finance and engineering, and a real onboarding module
250 to 1,000 $9,000 to $30,000 The above plus targeted coaching for repeat clickers and a separate executive briefing
Bilingual or Quebec-based Add 10 to 25% French content that was written in French rather than machine translated. Test it with an actual francophone employee before you buy

The bilingual row is a Canadian problem international vendors handle unevenly. Under Law 25 and Quebec language obligations, training your Quebec staff in awkward translated French is both a compliance issue and a credibility issue, since the content is asking people to notice when something reads wrong. Ask for sample French modules in the trial and have someone read them.

Comparing firms for this? Tell us what you need and it goes to the ones in the directory that do this work. No charge, and no phone number required.

What actually changes behaviour

  1. Short and frequent beats annual and long. Five minutes every month or two outperforms a 45 minute annual course, which is remembered as an inconvenience rather than as content.
  2. Role-specific for the two roles that matter. Finance needs payment verification and business email compromise. Engineering needs secrets handling, dependency risk and cloud configuration. Everyone else needs phishing and passwords, and giving them more is how you lose their attention.
  3. Coach repeat clickers privately. Public naming produces concealment, which is the exact opposite of the reporting behaviour you are trying to build.
  4. Simulate at realistic difficulty. An internal-looking message about payroll or benefits is what an attacker sends. A prince and a bad logo teaches nothing and inflates your numbers.
  5. Brief the executives separately. Executives are targeted differently, skip group training most often, and are the ones a fraudulent payment request will impersonate. Thirty minutes, once a year, with the CFO in the room.
  6. Close the loop publicly. When a real phish is reported and stopped, say so internally. One story like that does more than a quarter of modules.

What the frameworks actually require

SOC 2
The common criteria expect communication of security responsibilities to personnel. Auditors typically accept an annual training record with completion evidence and a policy acknowledgement.
ISO 27001
Clause 7.2 on competence and 7.3 on awareness, plus the information security awareness, education and training control in Annex A. Evidence means records, not intentions.
PIPEDA
The accountability principle requires an organisation to implement policies and practices including staff training on protecting personal information. It is not optional, and it is a duty of the organisation rather than of the training vendor.
Law 25
Quebec expects governance policies for protecting personal information and the training that supports them, in French where French is the language of work.
Cyber insurance
Not a framework, but increasingly the strictest reader. Applications routinely ask about training frequency and phishing simulation, and answering yes to something you cannot evidence is a claims problem later.

What goes wrong

  • Buying the platform and never configuring it. A subscription with no simulation schedule and no report button is a line item producing an audit artifact.
  • Chasing 100 per cent completion. The last 5 per cent costs more chasing than the first 95 cost delivering, and completion was never the outcome you wanted.
  • Making the simulation a disciplinary matter. The moment clicking has consequences, reporting stops, because reporting means admitting you nearly clicked.
  • Reporting completion to the board. It cannot get worse, so it says nothing. Report the report rate and the time to report instead, as set out on security metrics and KPIs.
  • Leaving contractors and offshore staff out. They frequently have the same access and are outside the HR system that drives enrolment, which is a gap that also shows up in vendor risk management.

Who runs it

This does not need a security executive at $300 an hour. Selecting the platform, setting the simulation difficulty and interpreting the results is a few hours of senior judgement a year. Running the enrolment, chasing completion and scheduling the sends is administrative work an operations or people team can carry, and moving it there is one of the clearer savings when you are scoping a retainer. What to keep internal is covered on vCISO pricing, and the standalone deliverable view is on fractional CISO services.

Get the program scoped properly

Training is cheap and easy to buy badly. Tell us your size, your languages and your framework obligations and we will get it scoped by Canadian providers.

Get matched

Common questions

How much does security awareness training cost in Canada?

$15 to $45 CAD per person per year for a platform including phishing simulation, so about $3,000 to $12,000 a year for 200 to 300 staff. Add 10 to 25 per cent for genuinely bilingual content. It is usually the cheapest line in a security budget and one of the few that changes what people do.

Is phishing simulation worth doing?

Yes, if you measure report rate and time to report rather than click rate, and if clicking carries no punishment. Simulation run as a test people can fail teaches concealment, and concealment is what turns a five minute incident into a five day one. Run at realistic difficulty, coach repeat clickers privately, and celebrate reports including the mistaken ones.

How often should staff do security training?

Short sessions every one to two months, plus a module at onboarding and a separate annual executive briefing. The annual 45 minute course exists to produce an audit record and is remembered as an interruption. Frequency matters more than duration, and total time per person per year can stay under an hour.

What report rate should we aim for?

Above 30 per cent of a simulated phish reported, with a median time to first report under ten minutes, and both trending upward. High performing organisations exceed 50 per cent. The absolute number matters less than the direction and than whether people also report real phishing that was not part of a simulation, which is the behaviour you were actually buying.

Do contractors need the training too?

Yes, if they have access to your systems or data, and they are the group most often missed because enrolment is usually driven by the HR system they are not in. Auditors ask about it, and an attacker does not care about employment status. Add contractor enrolment to your onboarding checklist rather than relying on the platform to notice them.