Knowledge base › Phishing simulation

Phishing simulation costs: what does it cost?

Last updated

At CoBoo a one-off phishing simulation starts at € 1,250, and the annual programme of 10 campaigns costs € 22 per employee per year. All rates are set out in full below, along with the factors that determine the price: your organisation's size, the number and complexity of scenarios, the reporting required and any follow-up training.

What does a phishing simulation cost at CoBoo?

You do not need to fill in a form to get an indicative price. These are our rates:

What Price What you get
One-off phishing simulation from € 1,250 Intake conversation, tailored scenarios, campaign delivery and a final report with management summary
Annual programme € 22 per employee per year 10 phishing campaigns spread across the year, with baseline measurement, re-test and trend reporting
Onboarding (one-off) € 350 One-off setup and coordination at the start of the programme

Onboarding applies once to both options. CoBoo is registered under the Dutch small business scheme (KOR) and does not charge VAT, so the amounts above are the amounts you pay.

A worked example for the annual programme: for 40 employees that is 40 × € 22 = € 880 per year, plus € 350 onboarding in the first year.

The one-off simulation is a starting price. A larger organisation, several scenarios running alongside each other or a campaign segmented by department costs more. Exactly what applies to your situation is set out in the quote, and the quote is free and without obligation. See also our phishing simulation service.

What do phishing simulations cost?

There is no fixed market price. The range is wide: budget automated tools where you do everything yourself sit at one end, while specialist providers like CoBoo offer a fully managed programme from intake to final report at the other.

As a benchmark: a simple, one-off phishing simulation for a company of 20 to 50 employees typically costs between €1,000 and €3,000 at a professional provider. For larger organisations or multiple scenarios this rises to €5,000 and above. At CoBoo a one-off simulation starts at € 1,250.

Important perspective: Phishing is the most common initial access route in data breaches, accounting for 17% of all incidents (IBM, Cost of a Data Breach 2026). The human factor plays a role in 62% of breaches (Verizon DBIR 2026). That is exactly what a simulation makes visible and measurable.

Price comparison by provider type

An overview of what to expect per type of provider:

Type Indicative price What is included Suitable for
Self-service tool € 0 to € 500 / year Platform, generic scenarios, basic reporting Businesses with in-house IT and security expertise
Professional provider (one-off) € 1,000 to € 5,000 Intake, tailored scenarios, full reporting SMEs of 20 to 250 employees
Recurring programme € 800 to € 3,500 / campaign Multiple scenarios, baseline plus re-test, trend reporting Organisations with NIS2 or ISO 27001 obligations
Combined package (simulation and training) Tailored Simulation (CoBoo) plus e-learning (Lumyo), complete programme Businesses that want demonstrable behaviour change

CoBoo sits in the second and third rows of this table. Our own rates are at the top of this page; request a free quote for a calculation tailored to your situation.

Factor 1: company size

The number of employees is the most important pricing factor. More employees means more email addresses, more recipient variation and a more extensive report. Most providers charge per employee or use pricing bands.

Small business (20 to 50 employees)

Manageable, quick to run, smaller report. The cost per employee is relatively higher because of the fixed base effort of preparation and the intake conversation.

Medium-sized business (50 to 250 employees)

Economies of scale apply here. The cost per employee falls, but the total price rises. Segmentation by department or location becomes more interesting and more useful.

Factor 2: number and complexity of scenarios

A simple simulation with a single generic scenario costs less than a campaign with three custom scenarios per department. More advanced variants require more preparation:

  • Generic scenario (fake parcel, fake Microsoft): lowest cost, broadly applicable
  • Company-specific scenario (supplier name, department name): higher prep, better learning moments
  • Segmented campaign per department: higher complexity, more data value
  • Multi-stage attack (email + landing page + login attempt): maximum realism, highest cost

Factor 3: reporting and analysis

The value of a phishing simulation lies in the data. CoBoo includes as standard:

  • Click rate per scenario and overall
  • Department and location breakdown
  • Comparison with sector benchmarks
  • Management summary for directors or board
  • Concrete recommendations for follow-up and training

Factor 4: follow-up training

A phishing simulation without follow-up is a missed opportunity. Employees who click learn most when they are immediately guided to a learning module at the moment of clicking. CoBoo works with Lumyo Awareness Training for e-learning follow-up. A combined package (simulation plus awareness training) is cheaper than buying both separately and delivers measurably better results.

Factor 5: one-off or recurring programme

A one-off measurement gives insight but no proof of improvement. Organisations that choose an annual or bi-annual programme also get a repeat measurement showing how much awareness has improved. Benefits include:

  • Satisfies NIS2 and ISO 27001 requirements (demonstrably recurring testing)
  • Shows development: from baseline to improved awareness
  • Lower rate per campaign through ongoing partnership
  • Different scenarios each round keep employees sharp

Frequently asked questions about cost

Are there cheaper alternatives to a phishing simulation?

Yes, there are self-service tools that let you run a phishing simulation yourself at a lower price. Those tools do require in-house cybersecurity expertise to deploy them properly and to interpret the results. Cheaper tools offer limited guidance, customisation and reporting. For businesses without in-house expertise, a professional provider such as CoBoo is usually more cost-effective.

How often should a phishing simulation be repeated?

For lasting awareness, running phishing simulations at least twice a year is recommended. A first test establishes the baseline; repeating it after six months demonstrates concrete improvement. Organisations with NIS2 or ISO 27001 obligations often opt for quarterly campaigns. Recurring programmes cost less per campaign than one-off assignments.

What are CoBoo's prices?

CoBoo works with a fixed project price for businesses of all sizes across the Netherlands. That price is published at the top of this page and always includes the intake conversation, campaign design, the simulation itself and the final report with management summary.

Our rates are published at the top of this page. What we promise alongside them:

  • No hidden costs: what is agreed is what you pay
  • Fixed price per project, not per click or hour
  • No VAT, because CoBoo is registered under the Dutch small business scheme
  • No-obligation quote conversation without commitment
  • Honest advice about what your organisation actually needs

Request a free quote

Whether you have 5 or 500 employees, there is a solution for every business size.

This opens your email client. You send the email yourself.

Read our privacy policy