How to Calculate ROI on Security Awareness Training
A defensible model for the business case, including the assumptions that make most vendor ROI calculators worthless and how to present the number without overclaiming.
ClickSafe Team
Security awareness · ClickSafe ·
Most security awareness ROI calculators produce an enormous number by multiplying the average cost of a breach by a made-up risk reduction percentage. Any finance director worth their salary will dismantle that in one meeting, and they will be right to.
Here is a model that survives scrutiny, partly because it is honest about what it cannot prove.
Start with what you can actually measure
Four inputs, all observable in your own environment within a quarter:
- Baseline click rate. From a simulation run before any training. Not a vendor benchmark, yours.
- Post-training click rate. Measured after at least ninety days, so you are seeing retention rather than recency.
- Report rate, before and after. The proportion of recipients who actively flagged the message.
- Mean time to report. How long from delivery to the first report. This is what determines whether a real incident is contained or investigated after the fact.
If a vendor's business case does not require you to measure your own baseline, it is not a business case.
The costs are the easy half
Direct: licence cost per user per year, plus any implementation or professional services.
Indirect, and usually larger: employee time. Compute it honestly: twelve minutes a quarter across two thousand people at a blended hourly rate is a real number, and leaving it out is the fastest way to lose credibility with finance.
Administrative: the programme owner's time, typically a few hours a month once running, more during rollout.
The benefit side, without inventing numbers
This is where most models break. Three approaches, in descending order of defensibility.
1. Avoided incident handling (defensible)
You know roughly what a reported phishing incident costs to triage: analyst time, mailbox searches, credential resets, comms. You know how many you handle. A programme that raises report rate increases reported volume in the short term but reduces the proportion that escalate into an actual investigation.
Model the change in escalations, not the change in reports. This is grounded entirely in your own operational data, which makes it the strongest part of the case.
2. Reduced probability of a material incident (honest, ranged)
Do not claim a point estimate. Present a range with the reasoning attached:
Our baseline click rate was 24%. After two quarters it is 9%. We cannot claim a proportional reduction in breach probability, because a single successful click is sufficient. What we can claim is that the population of employees likely to click has narrowed substantially, and that mean time to report has fallen from 4 hours to 35 minutes, which materially improves the chance of containing an incident before data leaves.
That paragraph is more persuasive to a competent executive than any calculator output, precisely because it declines to overclaim.
3. Compliance and insurance cost avoidance (concrete, often overlooked)
Frequently the easiest win to evidence. Documented, current training is required by SOC 2, ISO 27001, HIPAA, and most cyber insurance underwriting. Quantify the audit preparation hours removed, and ask your broker directly whether documented programme evidence affects your premium. Get that in writing and it goes straight into the model as a hard number.
Presenting it
Executives discount any single dramatic figure. Present three scenarios instead:
| Scenario | Assumption | Net position |
|---|---|---|
| Conservative | No breach avoided; only incident-handling and audit savings count | Break-even or modest positive |
| Expected | Above, plus reduced escalations at observed rates | Clear positive |
| Avoided incident | One material incident prevented over three years | Large positive |
Lead with the conservative case. If the programme justifies itself on operational savings alone, the risk reduction becomes upside rather than the entire argument, and the whole case stops depending on a probability nobody can verify.
Metrics to report quarterly
- Click rate, by team, trending
- Report rate and mean time to report, the two that predict real-world outcomes
- Repeat clickers, as a count of people needing targeted follow-up
- Completion, only as a compliance artefact
- Escalations avoided, versus your own historical baseline
Report at team level. Individual results in an executive pack destroy the reporting culture the programme depends on, and once people learn that clicking gets them named, the numbers stop being real.
Related: why annual compliance training fails covers the programme structure these numbers assume.


