🔗 FieldNotes – The hidden HR cost of security awareness training

TL;DR: security awareness costs include the time spent keeping it running. Before renewing, record the work your teams actually do and ask the vendor to demonstrate those same tasks.

When someone calls an awareness program “automated”, I want to see HR’s calendar – preferably the week before the deadline. HR already has a profession, then “𝘱𝘦𝘳𝘴𝘰𝘯 𝘸𝘩𝘰 𝘢𝘴𝘬𝘴 𝘢𝘨𝘢𝘪𝘯, 𝘮𝘰𝘳𝘦 𝘧𝘪𝘳𝘮𝘭𝘺” is quite an addition.

Consider a hypothetical Tuesday: the course reminder has gone out. An employee says they already completed it. A manager needs another extension. Someone on leave has received an overdue notice, and the completion report is due before lunch. HR checks the records, corrects the list, answers the complaints and sends a more personal reminder to the people the automatic one did not reach.

Somewhere in there, payroll still needs doing.

None of this makes the employees the problem, really!
People have competing deadlines, and systems need accurate information. It does mean that somebody is doing work the licence price does not describe.

The technical detail I would check is how changes in the employee directory reach the training platform. A scheduled reminder can fire exactly as configured and still go to the wrong person if the assignment data is stale – okay, someone has to notice and fix that.

Before renewal, I would follow one real campaign and record each administrative task, who handled it and the time spent. Include the follow-up messages and the report that needed cleaning up after export. Count IT and managers’ contributions too. Keep initial configuration separate from recurring work.

Use your own hours, damn! An industry average will not tell you how much of your HR team’s week has disappeared into this program. Put that internal effort alongside the supplier’s charges when comparing costs. If you need a monetary figure, use hourly costs agreed with Finance. Record employee learning time separately, so you can distinguish the time spent learning from the time spent keeping the program running.

Then bring the list to the vendor. Ask them to show the management steps in the platform: move someone to another department, handle an employee on leave, follow up on an incomplete assignment and produce the report your organization needs. Establish who does each task and whether the proposed package includes the necessary functionality.

I would also ask what happens when the directory sync fails. That is where “automated” becomes a much more interesting conversation.

Here, at Baited, we combine phishing simulations with an interactive, dynamic awareness course. Bring the same scrutiny to us. Look at the learning experience employees will use, then ask us to walk through the administration involved and explain what your team would still need to do.

Book a demo to explore our interactive, dynamic awareness course, with your actual workload as the benchmark.

Leave a Comment

Your email address will not be published. Required fields are marked *

Scroll to Top