Skip to main content
株式会社オブライト
Business DX2026-09-1110 min read

Phishing Training & Security Awareness Costs for SMBs

How much do phishing simulations and security training cost for SMBs? This guide breaks down pricing by method, company size, and free starting options.


Many small business owners put off employee security training simply because they have no sense of what it should cost. Here's the short answer: phishing simulation SaaS platforms typically run a few hundred yen per user per month, e-learning courses run roughly a few thousand yen per employee per year, a one-off phishing simulation exercise runs about JPY 100,000-500,000, and instructor-led group training runs about JPY 100,000-300,000 per session. A company with around 10 employees can put a basic training program in place for an annual budget in the tens of thousands to low hundred-thousands of yen, or even start entirely with free materials. Below, we break down the differences by method, the cost ranges involved, and how to keep the program going without overspending.

Why SMBs need security awareness training too

Cyberattacks tend to conjure images of sophisticated technical intrusions, but in practice the single biggest entry point for damage is people. Phishing emails that impersonate a business partner or a superior to lure someone to a fake site, business email compromise (BEC) scams that target accounting staff by faking a wire transfer destination, and the initial infection stage of ransomware that relies on an employee opening an attachment or clicking a link — all of these hinge on a single split-second decision by one employee. Technical safeguards like firewalls and antivirus software keep improving, but attackers refine their tactics for exploiting human inattention just as fast, so technology alone cannot fully close this gap. Small businesses rarely have a dedicated security staffer, which means each individual employee's vigilance translates directly into the organization's overall defense level. That is exactly why building a workforce that notices suspicious emails, refrains from clicking on its own judgment, and promptly reports what it sees is considered one of the most cost-effective security investments a company can make, requiring no major capital outlay.

Types of training and their characteristics

"Security awareness training" covers several distinct approaches, and both the cost and the way results show up differ significantly by method. The main options break down into four categories.

- Phishing simulation services: Send mock suspicious emails to employees and measure who opens, clicks, or reports them. Offered either as an ongoing SaaS subscription with continuously rotating scenarios, or as a one-off exercise run a few times a year; the former requires less day-to-day effort but tends to lock you into longer contracts
- E-learning: Teach security fundamentals — password hygiene, spotting phishing, social media caution, handling personal devices — via video and quizzes. An efficient, low-cost way to deliver the same content to every employee
- Group training / outside instructors: In-person or online sessions led by an external trainer. Allows live Q&A and examples tailored to your own business or past near-miss incidents, but requires scheduling and venue coordination
- Free materials from IPA and similar bodies: Japan's Information-technology Promotion Agency (IPA) publishes free materials, such as its "Five Basic Rules of Information Security" and SMB security guidelines, that can be folded directly into in-house training sessions or morning meetings at zero cost — a viable starting point even with no budget at all

Cost ranges by method

The figures below are general market ranges only, and vary by vendor, headcount, and how customized the scenarios are. These are not tied to any specific product, so get quotes from multiple vendors and align the underlying assumptions before comparing.

MethodTypical costNotes
Phishing simulation SaaSRoughly a few hundred yen per user/monthOngoing subscription covering delivery and reporting; usually contracted annually
One-off phishing exerciseRoughly JPY 100,000-500,000 per sessionVaries with headcount, number of scenarios, and reporting depth
E-learning (annual license)Roughly a few thousand yen per employee/yearCompany-wide contracts often bring the per-head price down
Group training / outside instructor (per session)Roughly JPY 100,000-300,000Varies with customization and in-person vs. online delivery
Bundled package with assessmentSeveral hundred thousand yen to over JPY 1,000,000Annual contract combining simulations, e-learning, and assessment

Annual budget guide by company size

Here is a rough sense of the annual budget to plan for at different company sizes. The range is wide depending on the mix and frequency chosen, and leaning more heavily on free materials can push it lower still; conversely, companies with large teams handling personal data or payment information tend to land at the higher end.

Company sizeAnnual budget guideTypical mix
About 10 employeesTens of thousands to roughly JPY 200,000Free materials plus partial e-learning, or one annual simulation
About 30 employeesRoughly JPY 200,000-600,000Company-wide e-learning plus 1-2 phishing simulations per year
About 100 employeesRoughly JPY 500,000-1,500,000Ongoing simulation SaaS plus group training plus department follow-ups

Starting for free or at low cost

Even with a tight budget, there is still something you can do. IPA's free "Five Basic Rules of Information Security" and its SMB-oriented security guidelines can be worked directly into morning meetings, office signage, or a simple in-house study session at no cost. Local chambers of commerce and municipal governments also sometimes run free or low-cost security seminars for small businesses, which can cost far less than bringing in an outside instructor on your own. A realistic path is to build baseline awareness through these free or low-cost channels first, then move to paid simulation services as the business grows or a client starts asking for it. Pairing this with technical checks like a vulnerability assessment covers both the human and system sides of risk. Combining it with the fundamentals in the SMB IT risk guide builds layered defenses rather than relying on training alone.

A checklist for choosing a vendor

- Can the mock email scenarios be customized to reflect your actual business context — vendors, internal systems, the kind of wording your staff normally sees?
- Does reporting track the "report rate" — the share of employees who noticed and reported a suspicious email — not just the open rate?
- Are results handled at the department or company level rather than singling out individuals by name?
- Is the e-learning content updated regularly to reflect current attack methods, such as BEC, SMS impersonation, and increasingly convincing AI-generated phishing emails?
- Is post-simulation follow-up — extra training, individual feedback, a comprehension check — included in the price, or billed separately?
- Can the plan flex as headcount, department assignments, or departures change?
- Does the vendor have a track record with companies of a similar size, ideally in your industry?
- Are the cancellation terms, contract renewal conditions, and data handling — how long simulation results are retained and how they're deleted — clearly spelled out?

In-house vs. outsourced

Whether to outsource security training or build it in-house comes down to size and available staff. For a company of 10-30 employees with no dedicated IT person, building mock emails and tallying results in-house usually isn't realistic, and using a phishing simulation SaaS or e-learning platform ends up cheaper in practice. For companies with over 100 employees and some HR or admin capacity, a hybrid approach also works: build your own internal materials around IPA's free resources and only outsource the e-learning component. If you do go in-house, decide upfront who owns keeping the materials current — a common failure is running it once in year one and letting it lapse afterward. If a client requires proof of your security posture, the training records themselves often become part of what you need to submit, so keep documentation of every session regardless of which approach you choose.

Running the program — an annual plan and the right metric

Security training holds up better as an ongoing annual program than as a one-time event. A common pattern: run company-wide e-learning at the start of the fiscal year to build baseline knowledge, run a phishing simulation roughly once a quarter, and follow up with targeted group training for departments that score poorly. New hires should get baseline training as part of onboarding so no one goes untrained for long. The metric you track matters just as much as the cadence. Chasing down the "open rate" or "click rate" alone tends to make employees fearful of failure, or triggers "training fatigue" where people only stay alert the moment they suspect it's a drill. What matters more is the report rate — the share of employees who noticed a suspicious email and promptly reported it to IT or a manager. Publicly calling out someone who clicked discourages honest self-reporting going forward, and that hesitation is exactly what can slow down the response to a real incident. Building a no-blame culture that actively rewards the act of reporting — even something as simple as thanking someone at a team meeting — is the key to keeping the program meaningful rather than a box-checking exercise.

A six-step annual loop for security awareness training: baseline e-learning and IPA materials, phishing simulations roughly once a quarter, tallying results with the report rate as the key metric, no-blame follow-up training, refining scenarios for the next round, and adjusting the yearly plan around busy periods before returning to baseline training

Common failure patterns

- Treating one annual session as sufficient: The effect of a single simulation fades within a few months, and the same results tend to repeat the following year
- Publicly shaming employees who clicked: Blaming individuals discourages honest reporting and can raise overall risk
- E-learning with no comprehension check: Watching a video without any follow-up quiz rarely sticks
- A one-size-fits-all curriculum: Departments that are frequently targeted, like accounting and general affairs, need tailored case studies to make the training relevant to their actual work
- Stopping at training and neglecting technical controls: Training should run alongside technical defenses like email spoofing protections (SPF/DKIM/DMARC) and multi-factor authentication, not replace them
- Assuming leadership is exempt: Executives and owners are frequently the actual target of business email compromise scams, and skipping their own training cuts the program's effectiveness in half

Frequently asked questions

Should we start with phishing simulations or e-learning?

Starting with e-learning to build baseline knowledge across the company, then adding hands-on phishing simulations once that has taken hold, is an easier sequence to manage. If budget is tight, starting with an in-house study session built around IPA's free materials is also a reasonable first step.

How often should simulations be run?

Running one just once a year tends to lose its effect quickly. Where possible, aim for roughly once a quarter, or at minimum twice a year, and use each round's results to adjust the training content.

Does a small company really need a paid simulation service?

A company with around 10 employees can build baseline awareness using IPA's free materials plus a simple annual test email, without a paid SaaS contract. If the business handles a lot of personal data or payment information, it's worth considering a paid service sooner rather than later.

Is it fine to flag a high open rate as a problem at a management meeting?

Focusing only on the open rate risks making employees defensive and less likely to report honestly. Tracking the trend in the report rate — how often employees notice and report a suspicious email — over time is a more accurate reflection of real progress.

Feel free to contact us

Contact Us