Security awareness training that works
Awareness training costs $15 to $45 CAD per person per year and is the cheapest line in a security budget. It is also the one most often bought to satisfy an auditor and then measured in a way that guarantees it changes nothing. The fix is not more content, it is measuring whether people report rather than whether they click.
Security awareness training in Canada runs $15 to $45 CAD per person per year for a platform with phishing simulation included, which is $3,000 to $12,000 CAD a year for a company of 200 to 300 people. Almost every framework expects it, so the question is what to buy and how to measure it. Most companies get the second part wrong.
$15 to $45 Per seat per year, CAD
Above 30% Phishing report rate worth targeting
Under 10 min Median time to first report
Stop measuring click rate
Click rate is the standard metric and it is close to useless on its own. It falls as people learn what a simulation looks like rather than what a phish looks like, and it can be driven to near zero by sending easy simulations. Zero would not help you: a determined attacker needs one person on one bad day. What you need from your workforce is speed of warning.
| Metric | Tells you | Use it? |
|---|---|---|
| Training completion | That people clicked through slides. Required evidence for an auditor and nothing more | For the audit file, not the board pack |
| Click rate | Partly awareness, mostly the difficulty of the simulation you chose | Only alongside report rate, and never as a target |
| Report rate | Whether people help when something looks wrong. The number that matters | Yes. Target above 30 per cent and rising |
| Median time to first report | How fast you would learn about a real campaign | Yes. Under ten minutes is achievable and genuinely useful |
| Repeat clickers | Where targeted coaching goes | Yes, quietly and without naming people in public |
| Reports of real phishing that was not a simulation | That the reporting habit generalised beyond the game | Yes. This is the outcome you were buying |
The report button is worth more than the course
If you do one thing, put a one-click report button in the mail client, route it somewhere a human reads, and acknowledge every report including the wrong ones. A company where reporting is easy and appreciated finds out about a campaign within minutes. A company where reporting means forwarding to a shared mailbox and hearing nothing back finds out from a customer. The difference costs almost nothing and outperforms any amount of additional content.
What to buy at each size
| Size | Annual cost | What to buy |
|---|---|---|
| Under 50 | $750 to $2,200 | A basic platform with simulation, quarterly. Skip the custom content entirely |
| 50 to 250 | $2,200 to $9,000 | Platform plus role-based modules for finance and engineering, and a real onboarding module |
| 250 to 1,000 | $9,000 to $30,000 | The above plus targeted coaching for repeat clickers and a separate executive briefing |
| Bilingual or Quebec-based | Add 10 to 25% | French content that was written in French rather than machine translated. Test it with an actual francophone employee before you buy |
The bilingual row is a Canadian problem international vendors handle unevenly. Under Law 25 and Quebec language obligations, training your Quebec staff in awkward translated French is both a compliance issue and a credibility issue, since the content is asking people to notice when something reads wrong. Ask for sample French modules in the trial and have someone read them.
Comparing firms for this? Tell us what you need and it goes to the ones in the directory that do this work. No charge, and no phone number required.
What actually changes behaviour
- Short and frequent beats annual and long. Five minutes every month or two outperforms a 45 minute annual course, which is remembered as an inconvenience rather than as content.
- Role-specific for the two roles that matter. Finance needs payment verification and business email compromise. Engineering needs secrets handling, dependency risk and cloud configuration. Everyone else needs phishing and passwords, and giving them more is how you lose their attention.
- Coach repeat clickers privately. Public naming produces concealment, which is the exact opposite of the reporting behaviour you are trying to build.
- Simulate at realistic difficulty. An internal-looking message about payroll or benefits is what an attacker sends. A prince and a bad logo teaches nothing and inflates your numbers.
- Brief the executives separately. Executives are targeted differently, skip group training most often, and are the ones a fraudulent payment request will impersonate. Thirty minutes, once a year, with the CFO in the room.
- Close the loop publicly. When a real phish is reported and stopped, say so internally. One story like that does more than a quarter of modules.
What the frameworks actually require
- SOC 2
- The common criteria expect communication of security responsibilities to personnel. Auditors typically accept an annual training record with completion evidence and a policy acknowledgement.
- ISO 27001
- Clause 7.2 on competence and 7.3 on awareness, plus the information security awareness, education and training control in Annex A. Evidence means records, not intentions.
- PIPEDA
- The accountability principle requires an organisation to implement policies and practices including staff training on protecting personal information. It is not optional, and it is a duty of the organisation rather than of the training vendor.
- Law 25
- Quebec expects governance policies for protecting personal information and the training that supports them, in French where French is the language of work.
- Cyber insurance
- Not a framework, but increasingly the strictest reader. Applications routinely ask about training frequency and phishing simulation, and answering yes to something you cannot evidence is a claims problem later.
What goes wrong
- Buying the platform and never configuring it. A subscription with no simulation schedule and no report button is a line item producing an audit artifact.
- Chasing 100 per cent completion. The last 5 per cent costs more chasing than the first 95 cost delivering, and completion was never the outcome you wanted.
- Making the simulation a disciplinary matter. The moment clicking has consequences, reporting stops, because reporting means admitting you nearly clicked.
- Reporting completion to the board. It cannot get worse, so it says nothing. Report the report rate and the time to report instead, as set out on security metrics and KPIs.
- Leaving contractors and offshore staff out. They frequently have the same access and are outside the HR system that drives enrolment, which is a gap that also shows up in vendor risk management.
Who runs it
This does not need a security executive at $300 an hour. Selecting the platform, setting the simulation difficulty and interpreting the results is a few hours of senior judgement a year. Running the enrolment, chasing completion and scheduling the sends is administrative work an operations or people team can carry, and moving it there is one of the clearer savings when you are scoping a retainer. What to keep internal is covered on vCISO pricing, and the standalone deliverable view is on fractional CISO services.
Get the program scoped properly
Training is cheap and easy to buy badly. Tell us your size, your languages and your framework obligations and we will get it scoped by Canadian providers.
Get matchedCommon questions
How much does security awareness training cost in Canada?
$15 to $45 CAD per person per year for a platform including phishing simulation, so about $3,000 to $12,000 a year for 200 to 300 staff. Add 10 to 25 per cent for genuinely bilingual content. It is usually the cheapest line in a security budget and one of the few that changes what people do.
Is phishing simulation worth doing?
Yes, if you measure report rate and time to report rather than click rate, and if clicking carries no punishment. Simulation run as a test people can fail teaches concealment, and concealment is what turns a five minute incident into a five day one. Run at realistic difficulty, coach repeat clickers privately, and celebrate reports including the mistaken ones.
How often should staff do security training?
Short sessions every one to two months, plus a module at onboarding and a separate annual executive briefing. The annual 45 minute course exists to produce an audit record and is remembered as an interruption. Frequency matters more than duration, and total time per person per year can stay under an hour.
What report rate should we aim for?
Above 30 per cent of a simulated phish reported, with a median time to first report under ten minutes, and both trending upward. High performing organisations exceed 50 per cent. The absolute number matters less than the direction and than whether people also report real phishing that was not part of a simulation, which is the behaviour you were actually buying.
Do contractors need the training too?
Yes, if they have access to your systems or data, and they are the group most often missed because enrolment is usually driven by the HR system they are not in. Auditors ask about it, and an attacker does not care about employment status. Add contractor enrolment to your onboarding checklist rather than relying on the platform to notice them.