Security Awareness Training ROI: What the Evidence Actually Shows
Does security awareness training pay off? A hype-free look at the ROI evidence — peer-reviewed studies, benchmark data, and a model you can run yourself.

Every CISO eventually faces the same budget-meeting question: "We spend all this money on awareness training — what are we actually getting for it?"
It is a fair question, and the honest answer is more interesting than either the vendor pitch ("training slashes risk by 90%!") or the cynic's take ("training is compliance theater"). The evidence, read carefully, says both outcomes are real — and which one you get depends on how the program is designed, delivered, and measured.
This post walks through what the research actually shows, where the ROI comes from, and how to build a defensible ROI case for your own organization.
Why the ROI question is hard
Security awareness training is bought like an insurance product but measured like an e-learning course. Completion rates, quiz scores, and satisfaction surveys are easy to report and nearly useless as evidence of risk reduction. What matters is behavior change: do fewer people click, disclose, approve, and pay — and do more people report?
The cost side of the equation, at least, is well documented. The Verizon 2026 Data Breach Investigations Report attributes 62% of breaches to the human element — social engineering, errors, and misused credentials. IBM's Cost of a Data Breach 2026 puts the global average breach at $4.99 million, and the FBI's IC3 logged $20.9 billion in reported cybercrime losses in its 2025 Internet Crime Report — with business email compromise alone accounting for roughly $3 billion.
So the exposure is enormous and predominantly human. The open question is whether training measurably reduces it.
What the evidence actually shows
Three rigorous data points, spanning academic and industry research, frame the honest answer:
| Study | Design | Key finding |
|---|---|---|
| Ho et al., IEEE S&P 2025 (UCSD Health, 19,500 employees, 8 months) | Observational, real phishing simulations | No significant relationship between recency of annual compliance training and simulation failure; embedded post-click training reduced failure by only ~2 percentage points — and 75% of employees closed the training page within one minute |
| Reinheimer et al., SOUPS 2020 (longitudinal lab study) | Controlled, within-subjects | Phishing detection ability (d′) jumped from 1.11 to 2.13 immediately after interactive training; still significantly elevated at 4 months; no longer significant at 6 months — knowledge decays without reinforcement |
| KnowBe4 2026 benchmark (millions of users, continuous programs) | Industry benchmark | Average phish-prone percentage falls from 33.2% at baseline to 20.1% after 90 days and 4.2% after 12 months of combined simulation + training |
Read together, these are not contradictory. They describe a dose-response curve:
- Annual, passive, compliance-style training produces roughly nothing. That is the format Ho et al. tested, and their null result should end the practice of buying training to satisfy an auditor and calling it risk reduction.
- Interactive training produces a large immediate effect that decays within four to six months unless refreshed.
- Continuous, simulation-driven programs — where employees are tested regularly and trained at the moment of failure — sustain an order-of-magnitude reduction in failure rates over a year.
Training doesn't fail because employees can't learn. It fails when it's designed to produce completion certificates instead of behavior change — and measured accordingly.
The ROI question, properly framed, is therefore not "does training work?" but "are we running the version that works?"
Where the ROI actually comes from
A well-run program generates returns through four channels, in descending order of size:
- Avoided incident costs. Fewer successful phishing, vishing, and business email compromise incidents. Given average breach costs near $5 million, even a modest reduction in annual incident probability dominates the ROI math for mid-sized and large organizations.
- Faster detection through reporting. Trained employees don't just click less — they report more. A phishing campaign reported in minutes gets contained before credentials are used; one discovered weeks later is a breach investigation. Report rate and time-to-report are leading indicators most programs still ignore.
- Reduced incident-response load. Every prevented compromise is hours of SOC triage, password resets, and forensics that never happen.
- Compliance and insurance leverage. Documented, measured training satisfies requirements in GDPR, ISO 27001, SOC 2, and most cyber-insurance questionnaires — and increasingly affects premiums.
How to build the ROI case: a worked example
Here is a defensible model you can adapt. Assume a 500-employee organization:
Step 1 — Establish the behavioral baseline. Run an unannounced phishing simulation before any training. Benchmark data suggests roughly a third of employees will fail. Record failure rate, report rate, and time-to-report.
Step 2 — Estimate baseline incident exposure. Suppose historical data and industry benchmarks suggest one material social-engineering incident every two years (annualized probability 50%) with an expected cost of $400,000 for an organization this size (well below the $4.99M global average, which skews toward large enterprises).
Expected annual loss: 0.5 × $400,000 = $200,000.
Step 3 — Apply an evidence-based reduction. A continuous program that moves failure rates from ~33% toward ~5% justifies assuming incident probability falls meaningfully. Even a conservative one-third reduction cuts expected annual loss by ~$66,000; a 60% reduction saves $120,000.
Step 4 — Compare against fully loaded program cost. Platform licensing plus employee time (say, 30 minutes per employee per quarter at an average loaded cost) typically lands at $25,000–$50,000 per year for this headcount. Against $66,000–$120,000 in avoided expected loss — before counting IR savings, insurance, and compliance value — the program clears its cost with room to spare.
Step 5 — Report behavior, not completions. Present the quarterly trend in failure rate, report rate, and a per-department human risk score — a single quantified metric makes the trend legible to a board in a way that raw simulation logs never will.
The honesty of this model matters: the assumptions are visible, conservative, and tied to published data. That is precisely what makes it survive CFO scrutiny — unlike a vendor's "562% ROI" headline with the workings hidden.
What separates programs that pay off from programs that don't
The research points to five design choices that determine which side of the evidence your program lands on:
- Simulate continuously, train at the moment of failure. The just-in-time teachable moment right after an employee clicks a simulated phish is worth more than an hour of scheduled e-learning — but only if the training is engaging enough that people don't close it in 45 seconds, as most did in the UCSD study.
- Refresh every four months, not every year. The decay curve is measured: significant at four months, gone by six. Calendar-annual training guarantees your workforce spends half the year back at baseline.
- Cover the channels attackers actually use. Email is now the minority of social engineering pressure — voice, SMS, and QR-code lures need simulation coverage too, as we detailed in our vishing and smishing guide.
- Measure individuals and teams, not averages. Aggregate click rates hide the fact that risk concentrates in a small population of repeat clickers and high-exposure roles. Quantifying risk per person is the core of human risk management.
- Close the loop with reporting culture. Celebrate reports, publish time-to-report, and never punish simulation failures — punishment measurably suppresses reporting, which destroys channel #2 of your ROI.
A modern security awareness training program is really a measurement system with training attached — the training is the intervention, but the simulations, scores, and trends are what prove the return.
The bottom line
The question "does security awareness training have ROI?" has a clear, evidence-backed answer: yes, if — and only if — it is continuous, simulation-driven, and measured on behavior. The same research that demolishes annual compliance training also documents order-of-magnitude improvements from programs built the right way. The difference between the two is not budget. It is design.
Frequently asked questions
What is a realistic ROI for security awareness training?
It depends almost entirely on program design. Benchmark data shows organizations that run continuous, simulation-driven programs cut phishing failure rates from roughly 33% to about 4% within a year, while peer-reviewed research shows that once-a-year compliance training produces no measurable behavior change at all. The ROI of a well-run program is driven by reduced incident probability against breach costs that average $4.99 million; the ROI of a box-ticking program is close to zero.
Why do some studies say phishing training doesn't work?
The most cited one — an eight-month study of 19,500 employees at UC San Diego Health published at IEEE S&P 2025 — tested a specific format: annual compliance training and post-click training pages that most employees closed within a minute. It found no significant link between annual training and failure rates. That is an indictment of low-engagement formats, not of training as such; studies of spaced, interactive training measure large and lasting improvements in phishing detection.
How often should security awareness training be refreshed?
The best longitudinal evidence suggests knowledge measurably decays after about four to six months. In the SOUPS 2020 study, phishing detection ability remained significantly improved four months after training but was no longer statistically distinguishable from baseline at six months. Short refreshers every four months — ideally triggered by simulation results rather than the calendar — beat annual cycles.
How do I measure the ROI of our awareness program?
Track a behavioral baseline first: simulated phishing failure rate, report rate, and time-to-report before the program starts. Then measure the same metrics quarterly, convert the failure-rate reduction into avoided-incident probability, and multiply by your expected incident cost. Presenting the trend per department alongside a quantified human risk score is far more persuasive to boards than completion percentages.
NOUSEC simulates attacks across 8 channels and turns the results into one number your board can read.
Book a demo