Knowledge base › Phishing simulation
Phishing simulation costs: what does it cost?
Last updated
At CoBoo a one-off phishing simulation starts at € 1,250, and the annual programme of 10 campaigns costs € 22 per employee per year. All rates are set out in full below, along with the factors that determine the price: your organisation's size, the number and complexity of scenarios, the reporting required and any follow-up training.
What does a phishing simulation cost at CoBoo?
You do not need to fill in a form to get an indicative price. These are our rates:
| What | Price | What you get |
|---|---|---|
| One-off phishing simulation | from € 1,250 | Intake conversation, tailored scenarios, campaign delivery and a final report with management summary |
| Annual programme | € 22 per employee per year | 10 phishing campaigns spread across the year, with baseline measurement, re-test and trend reporting |
| Onboarding (one-off) | € 350 | One-off setup and coordination at the start of the programme |
Onboarding applies once to both options. CoBoo is registered under the Dutch small business scheme (KOR) and does not charge VAT, so the amounts above are the amounts you pay.
A worked example for the annual programme: for 40 employees that is 40 × € 22 = € 880 per year, plus € 350 onboarding in the first year.
The one-off simulation is a starting price. A larger organisation, several scenarios running alongside each other or a campaign segmented by department costs more. Exactly what applies to your situation is set out in the quote, and the quote is free and without obligation. See also our phishing simulation service.
What do phishing simulations cost?
There is no fixed market price. The range is wide: budget automated tools where you do everything yourself sit at one end, while specialist providers like CoBoo offer a fully managed programme from intake to final report at the other.
As a benchmark: a simple, one-off phishing simulation for a company of 20 to 50 employees typically costs between €1,000 and €3,000 at a professional provider. For larger organisations or multiple scenarios this rises to €5,000 and above. At CoBoo a one-off simulation starts at € 1,250.
Important perspective: Phishing is the most common initial access route in data breaches, accounting for 17% of all incidents (IBM, Cost of a Data Breach 2026). The human factor plays a role in 62% of breaches (Verizon DBIR 2026). That is exactly what a simulation makes visible and measurable.
Price comparison by provider type
An overview of what to expect per type of provider:
| Type | Indicative price | What is included | Suitable for |
|---|---|---|---|
| Self-service tool | € 0 to € 500 / year | Platform, generic scenarios, basic reporting | Businesses with in-house IT and security expertise |
| Professional provider (one-off) | € 1,000 to € 5,000 | Intake, tailored scenarios, full reporting | SMEs of 20 to 250 employees |
| Recurring programme | € 800 to € 3,500 / campaign | Multiple scenarios, baseline plus re-test, trend reporting | Organisations with NIS2 or ISO 27001 obligations |
| Combined package (simulation and training) | Tailored | Simulation (CoBoo) plus e-learning (Lumyo), complete programme | Businesses that want demonstrable behaviour change |
CoBoo sits in the second and third rows of this table. Our own rates are at the top of this page; request a free quote for a calculation tailored to your situation.
Factor 1: company size
The number of employees is the most important pricing factor. More employees means more email addresses, more recipient variation and a more extensive report. Most providers charge per employee or use pricing bands.
Small business (20 to 50 employees)
Manageable, quick to run, smaller report. The cost per employee is relatively higher because of the fixed base effort of preparation and the intake conversation.
Medium-sized business (50 to 250 employees)
Economies of scale apply here. The cost per employee falls, but the total price rises. Segmentation by department or location becomes more interesting and more useful.
Factor 2: number and complexity of scenarios
A simple simulation with a single generic scenario costs less than a campaign with three custom scenarios per department. More advanced variants require more preparation:
- Generic scenario (fake parcel, fake Microsoft): lowest cost, broadly applicable
- Company-specific scenario (supplier name, department name): higher prep, better learning moments
- Segmented campaign per department: higher complexity, more data value
- Multi-stage attack (email + landing page + login attempt): maximum realism, highest cost
Factor 3: reporting and analysis
The value of a phishing simulation lies in the data. CoBoo includes as standard:
- Click rate per scenario and overall
- Department and location breakdown
- Comparison with sector benchmarks
- Management summary for directors or board
- Concrete recommendations for follow-up and training
Factor 4: follow-up training
A phishing simulation without follow-up is a missed opportunity. Employees who click learn most when they are immediately guided to a learning module at the moment of clicking. CoBoo works with Lumyo Awareness Training for e-learning follow-up. A combined package (simulation plus awareness training) is cheaper than buying both separately and delivers measurably better results.
Factor 5: one-off or recurring programme
A one-off measurement gives insight but no proof of improvement. Organisations that choose an annual or bi-annual programme also get a repeat measurement showing how much awareness has improved. Benefits include:
- Satisfies NIS2 and ISO 27001 requirements (demonstrably recurring testing)
- Shows development: from baseline to improved awareness
- Lower rate per campaign through ongoing partnership
- Different scenarios each round keep employees sharp
Frequently asked questions about cost
Are there cheaper alternatives to a phishing simulation?
Yes, there are self-service tools that let you run a phishing simulation yourself at a lower price. Those tools do require in-house cybersecurity expertise to deploy them properly and to interpret the results. Cheaper tools offer limited guidance, customisation and reporting. For businesses without in-house expertise, a professional provider such as CoBoo is usually more cost-effective.
How often should a phishing simulation be repeated?
For lasting awareness, running phishing simulations at least twice a year is recommended. A first test establishes the baseline; repeating it after six months demonstrates concrete improvement. Organisations with NIS2 or ISO 27001 obligations often opt for quarterly campaigns. Recurring programmes cost less per campaign than one-off assignments.
What are CoBoo's prices?
CoBoo works with a fixed project price for businesses of all sizes across the Netherlands. That price is published at the top of this page and always includes the intake conversation, campaign design, the simulation itself and the final report with management summary.
Our rates are published at the top of this page. What we promise alongside them:
- No hidden costs: what is agreed is what you pay
- Fixed price per project, not per click or hour
- No VAT, because CoBoo is registered under the Dutch small business scheme
- No-obligation quote conversation without commitment
- Honest advice about what your organisation actually needs
Request a free quote
Whether you have 5 or 500 employees, there is a solution for every business size.
This opens your email client. You send the email yourself.