Cybersecurity
Guide

Security Awareness Training: What It Costs and Includes

A real security awareness programme is more than an annual e-learning video. This guide covers what a working programme actually consists of, what it costs in the Netherlands, and how to measure whether it's changing behaviour.

Aug 15, 2026
8 min read
Security Awareness Training: What It Costs and Includes

Most Dutch SMEs now have decent technical defences: a firewall, endpoint protection, MFA on their Microsoft 365 tenant. The gap that keeps causing incidents is the one technology can't close on its own — a colleague clicking a convincing invoice email, or approving a payment change requested "urgently" by someone impersonating the CEO. Security awareness training is the discipline of closing that gap systematically, rather than hoping one annual e-learning video does the job.

This guide covers what a real programme actually consists of, what it costs in the Netherlands, how you measure whether it's working, and where it fits under NIS2.

Why an annual e-learning video isn't a programme

Most SMEs that say they "do" security awareness mean one thing: employees click through a 20-minute e-learning module once a year, tick a compliance box, and forget the content within weeks. That approach produces a certificate, not behaviour change.

A real programme has four parts that reinforce each other:

  • A baseline measurement. Before you train anyone, you test where the organisation actually stands — typically with an unannounced phishing simulation — so you have a number to improve against, not a guess.
  • Structured, role-based content. Finance and HR face different risks (payment fraud, CV-attachment malware) than a developer or a warehouse worker. Generic "don't click suspicious links" content gets ignored; content tied to a person's actual job gets remembered.
  • Ongoing phishing simulations, not a one-off test. Behaviour decays without repetition, which is why a single yearly test does almost nothing on its own.
  • An easy way to report, ideally a one-click "report phishing" button in Outlook or Gmail. This is the part most SMEs skip, and it's arguably the most valuable: a colleague who forwards a suspicious email to the security team in time can stop an attack before it spreads, even if three other colleagues already clicked it.

What a programme looks like in practice, step by step

  • 1. Measure the starting point. Run an unannounced phishing simulation before you announce the programme, so the baseline reflects real behaviour, not people on their best behaviour because they know they're being tested.
  • 2. Segment by role and risk. Finance, HR and anyone with access to payment systems need targeted modules on invoice fraud and CEO fraud specifically, not the generic company-wide course.
  • 3. Run simulations on a fixed cadence. A realistic minimum is four to six simulated phishing campaigns per year, varying in difficulty and format (email, and increasingly SMS and voice/deepfake-style pretexts).
  • 4. Coach, don't punish, people who click. Anyone who clicks a simulation gets a short, specific explainer on what gave the email away, delivered within minutes, not a lecture from their manager. Punishing clickers is the single fastest way to make people stop reporting real suspicious emails, because they're afraid of looking foolish.
  • 5. Make reporting effortless. A visible "report phishing" button beats an instruction buried in a policy document that nobody rereads.
  • 6. Report the trend to management, not just a completion percentage. Click rate, report rate and repeat offenders over time tell you whether the organisation's risk is actually going down.

What it costs in the Netherlands

What drives the price

A quote for security awareness training isn't a single number — it moves with a handful of factors:

  • Headcount. Most providers price per employee, so the total scales directly with how many people you train.
  • Scope. A phishing-only baseline costs less than a programme that also covers password hygiene, safe remote working and social engineering by phone.
  • Simulation frequency and format. Running simulations quarterly costs less than running them monthly across multiple channels (email, SMS, voice).
  • Coaching and reporting. A programme that includes a report-phishing button, individual coaching for repeat clickers and management reporting takes more to deliver than a self-service e-learning subscription.
  • Whether it's bundled. Awareness training bought as part of a broader managed IT or security contract is usually priced differently than a standalone subscription.

Within that range, published figures give a sense of scale. One Dutch provider quotes a broad range of EUR 500 to EUR 2,500 per year for a small-to-medium organisation, depending on scope (Cyberon). At the low end, per-employee e-learning subscriptions are advertised from around EUR 0.65 per employee per month as an introductory rate (AVGtrainingen) — useful as a floor, though a genuinely managed programme with simulations, coaching and reporting typically costs more than a self-service e-learning subscription alone.

TierWhat's includedRough indication
E-learning onlyAnnual or quarterly modules, no simulationsLowest cost, closer to a compliance checkbox than a working programme
Awareness + simulationsRole-based content, quarterly phishing simulations, basic reportingMid-range, the realistic minimum for most SMEs
Managed programmeEverything above, plus a report-phishing button, coaching workflow and management reporting, often bundled into a broader security serviceHigher cost, but the only tier that reliably changes behaviour over time

Treat any quote as a range: ask exactly which of the building blocks above are included before comparing two prices, because "security awareness training" means very different things depending on the vendor.

How to measure whether it's actually working

Completion percentage is the easiest metric to report and the least useful one. It tells you people opened the training, not that they'd recognise a real attack. Track these instead:

  • Click rate on simulations. One widely referenced Benelux benchmark found that roughly four in ten employees click a simulated phishing link the first time they're tested ([Emerce](https://www.emerce.nl/wire/vier-tien-medewerkers-klikken-phishinglink-bijna-niemand-meldt)). A mature programme should bring that down over time; under 5% is generally considered a healthy level for an organisation running simulations regularly ([Kymatio](https://kymatio.com/blog/2026-phishing-benchmarks-industry-click-rates)).
  • Report rate, not just click rate. A colleague who reports a real phishing email — even after almost clicking it — is more valuable to your security posture than one who simply never gets tested. Rising report rates alongside falling click rates is the sign a programme is actually working, not just running.
  • Time-to-report. How fast does a suspicious email reach your security team or MSP after landing in an inbox? Minutes matter, because that's your real window to contain a live phishing campaign before others click it too.
  • Repeat clickers. A small group of employees who click every simulation is a bigger risk than the overall average suggests, and they're exactly who targeted coaching should focus on.

Run simulations often enough to see a trend, not a snapshot: a realistic minimum is four to six per year, more for higher-risk roles (Kymatio).

Where this sits under NIS2

If your organisation falls under NIS2 (directly, or as a supplier to an organisation that does), cybersecurity awareness and training is one of the explicit organisational measures the directive expects under Articles 20 and 21 — not just for IT staff, but across the whole organisation, including management (AVGtrainingen). NIS2 doesn't prescribe a specific tool or a fixed number of phishing simulations, but "we did one e-learning module three years ago" will not hold up as evidence of an ongoing programme if you're ever asked to demonstrate compliance. If you haven't mapped where you stand against the directive yet, our NIS2 checklist for SMEs is a useful starting point before you scope a training programme.

Common mistakes

  • Treating it as a one-off, not a programme. A single annual module produces a completion certificate, not lasting behaviour change; the effect fades within weeks without repetition.
  • Punishing people who click. This is the fastest way to destroy your report rate — people stop flagging suspicious emails because they're afraid of being singled out, and your most useful signal disappears.
  • Generic content for everyone. Finance doesn't face the same risks as a warehouse team. Content that isn't relevant to someone's actual job gets ignored.
  • No reporting mechanism. Training without an easy way to act on what you learned just produces frustration the first time someone spots something real and doesn't know what to do with it.
  • No metrics to management. Without a trend line on click rate, report rate and repeat offenders, nobody can tell whether the budget is doing anything.

FAQ

What does security awareness training cost for an SME? In the Netherlands, budget roughly EUR 500 to EUR 2,500 per year for a small-to-medium organisation, depending on how many employees and modules are included, with entry-level e-learning subscriptions advertised from around EUR 0.65 per employee per month. A managed programme with simulations, coaching and reporting typically costs more than e-learning alone.

Is security awareness training mandatory under NIS2? NIS2 requires organisations in scope to take appropriate cybersecurity awareness and training measures under Articles 20 and 21, covering all staff, not only IT. It doesn't mandate a specific product or a fixed number of simulations, but a one-off training session is unlikely to satisfy an ongoing-measure requirement.

How often should you run phishing simulations? A realistic minimum is four to six simulations per year, varying format and difficulty, with more frequent testing for higher-risk roles like finance and HR.

What's a good click rate to aim for? Many organisations start around four in ten employees clicking a first simulation. With a running programme, under 5% is generally considered a healthy level — though report rate matters as much as click rate.

Should we punish employees who keep clicking simulations? No. Coach repeat clickers individually instead. Punishment reliably reduces reporting of real suspicious emails across the whole organisation, which is a worse outcome than one person clicking a simulation.

Build a programme that actually changes behaviour

Want a security awareness programme built around your organisation's real risk, not a generic module library? Our Cybersecurity & Identity team designs and runs training, phishing simulations and reporting workflows, often as part of a broader Managed IT & Support contract. Read our NIS2 checklist for SMEs if you also need to map where you stand against the directive.

Cybersecurity
Security Awareness
Phishing
NIS2

Related Articles

Cybersecurity

AI-Powered Cybersecurity: How Machine Learning Is Transforming Threat Detection

Cyberattacks are growing in volume and sophistication. AI-powered security tools are shifting the balance back to defenders. This article examines how Dutch organisations are using ML-driven SIEM, EDR, and threat intelligence to stay ahead.

Read More
Cybersecurity

NIS2 for SMBs: What the Law Means and What You Must Arrange

The Dutch Cyberbeveiligingswet (NIS2) lands in 2026 and brings duty of care, a 24-hour reporting duty and personal director liability. Here is who is in scope, what you must arrange, and a practical step-by-step plan for SMBs.

Read More
Cybersecurity

Preventing Ransomware in the SMB: 8 Measures That Actually Work

SMBs are now the primary target for ransomware precisely because attackers assume their defences are weak. The good news: a handful of well-implemented measures stop the vast majority of attacks. Here are the 8 that deliver the most protection per euro.

Read More

Need Help with Your IT Infrastructure?

Let's discuss how we can help transform your IT operations with modern solutions.