Run it on your numbers
Defaults are a mid-sized organisation already doing better than the published average. Replace them with yours — the two that move the answer most are the share of your people who click in a year and how often a click actually turns into something material.
People who receive email in your organisation.
People, not emails — the share of your workforce that falls for at least one phishing link over twelve months. This is the same quantity as a phish-prone rate, so KnowBe4's 33.2% baseline drops straight in. The default of 12% assumes an organisation already doing better than that average.
Most clicks cost nothing — credentials are not reused, MFA holds, the payload fails. This is the most uncertain input on the page and it scales the answer linearly, so move it and see how much of your result rests on it.
Response, downtime, legal and notification. Your cyber-insurance broker can give you a sector figure; the default is deliberately well below published average breach costs.
Licence plus the internal time to run it. Include the hours, not just the invoice.
Everything above is arithmetic on your own figures. This one number is a claim about the world, and it decides the entire answer. Move it and watch the result cross zero.
Vendor benchmarks sit high — KnowBe4 reports 33.2% falling to 4.2% over twelve months of combined training and simulation. The largest independent trial puts the honest floor at zero for annual compliance training. Both scenarios below use your inputs; they differ only in this number.
Assumes the programme cuts the click rate by 40% — the figure you set above.
- Loss avoided
- $96,000
- Programme cost
- − $12,500
Assumes a 0% fall in click rate. This is not pessimism: it is what the largest independent trial measured for the format most organisations actually run.
- Loss avoided
- $0
- Programme cost
- − $12,500
A negative result is a real output of this model, not an error. If this is your organisation’s situation, the programme as described does not pay for itself.
Nothing here is sent anywhere. The calculation runs in your browser, there is no form to fill in, and we do not see your inputs.
The model, written out
If you cannot check the arithmetic, the number is worthless. Here it is in full.
clicks = employees × share who click in a year
material incidents = clicks × chance a click turns material
expected annual loss = material incidents × cost of one incident
loss avoided = expected annual loss × relative fall in click rate
net, first year = loss avoided − (employees × programme cost per person)
Four of those five lines are arithmetic on figures you supply. Only one — the relative fall in click rate — is a claim about the world, and it is the line that decides whether the answer is positive or negative. That is why it has its own control and its own slider rather than being buried in a coefficient.
Note what is deliberately not in the model: a count of inbound phishing emails. A click rate is a share of people, and multiplying a share of people by a number of messages is a unit error that silently inflates every figure downstream. Combining the two honestly would need per-person repeat-exposure modelling, which this tool does not do — so it does not pretend to.
Where the numbers come from
Two published sources sit behind the two scenarios. Neither of them is us.
The gap between those two findings is not a contradiction. One measured annual compliance modules; the other measured continuous testing paired with training. They are different interventions that share a name, which is exactly why a single industry-average ROI figure is meaningless and this tool refuses to print one.
What this tool will not do
Questions
What people ask before they trust a vendor's calculator.