TL;DR
- What it covers: phishing and social engineering, credential and password practice, device and network hygiene, safe handling of customer data, and what to do in the first ten minutes of a suspected breach.
- Formats and cost: live expert-led sessions run 2 hours from $250, half-day from $500, full-day from $900, quote-based. Compliance-LMS subscriptions are priced per seat per year instead.
- How long: most teams get the core material in a half day. Annual refreshers are shorter.
- The main split between providers: automated phishing-simulation platforms with audit trails, versus live instructors who adapt to your environment. They solve different problems.
- Who should not buy a live session: if you need certified, auditable annual training across hundreds of seats to satisfy SOC 2 or ISO 27001 evidence requirements, buy a compliance platform. A workshop is not an audit artifact.
What cybersecurity training for employees actually covers
A good program is built around what your people actually touch. That means credentials, email, browsers, laptops, and customer data. The technical depth stays low, because the audience is not the security team. Here is the agenda most sessions converge on, and the reason each block earns its place.
Phishing and social engineering. Not "look for spelling mistakes." Modern pretexting is well written and often references a real project or a real colleague. The block that works shows employees genuine examples pulled from your own inbox with the identifiers removed, then has them argue about which ones are real. People remember the ones they got wrong.
Credentials and authentication. Password managers, why reuse is the actual risk rather than complexity rules, how multi-factor works and which factors are weak. This is where you handle the awkward question of what happens when someone loses their phone, because the workaround people invent on their own is usually worse than the problem.
Device and network hygiene. Updates, disk encryption, public wifi, personal devices touching work accounts, and what to do with the laptop that has been sitting in a drawer since someone left.
Data handling. Which customer data your team is allowed to copy, where it may go, and what a "quick export to a spreadsheet" costs you if that spreadsheet ends up in a personal drive. For most companies this is the block with the largest gap between policy and practice.
The first ten minutes of an incident. Who to tell, how to tell them, and the explicit promise that reporting a mistake will not get anyone fired. That last point is worth more than the preceding four blocks combined. Teams that hide incidents lose hours you cannot get back.
Role-specific cuts. Engineers need secrets management and dependency risk. Finance needs invoice fraud and payment verification. Support needs identity verification before account changes. A generic session skips all three, which is why a generic session underperforms.
Formats, length, and what it costs
The category is bad at answering this, so here are real numbers.
| Format | Typical use | Duration | Price |
|---|---|---|---|
| Focused live session | One topic, usually phishing, for one team | 2 hours | from $250 |
| Half-day workshop | The core agenda above for a whole team | 3 to 4 hours | from $500 |
| Full-day workshop | Core agenda plus role-specific breakouts and an incident tabletop | 6 to 7 hours | from $900 |
| Compliance LMS subscription | Annual auditable training across all staff | Self-paced, ongoing | Per seat, per year, from other vendors |
MentorCruise workshops are quote-based, so those figures are starting points rather than list prices. You send a brief, get matched with an expert within 48 hours, and most sessions run within one to two weeks of the inquiry.
On working time: a half day for a team of ten is roughly forty person-hours. That is the number your finance partner will ask about, and it is usually larger than the invoice. Say it out loud before someone else does.
A useful reference point for the cost side: a half-day from $500 across a team of ten is $50 a head. Whether that is worth it depends entirely on what you are protecting, which is the argument in the internal case section below.
How to choose a provider
The market splits into two groups that are genuinely trying to do different things. Most buying mistakes come from comparing them on the same axis.
Compliance and simulation platforms run continuous automated phishing tests, assign remedial modules, and produce completion reports.
- KnowBe4 is the largest in this category and the default choice when the requirement is auditable coverage across a big headcount.
- Proofpoint Security Awareness is a common pick where the email security stack is already Proofpoint.
- Hoxhunt and Infosec IQ compete on engagement and on how adaptive the simulation is.
- SANS Institute sits slightly apart, with genuinely deep technical training and a strong reputation with security practitioners. It is the right call when you are training security staff rather than general employees, and it is priced accordingly.
Course marketplaces such as Coursera and Udemy Business give you a broad self-paced library at a low per-seat cost. They work when the goal is optional self-directed learning and nobody needs to certify that a specific person learned a specific thing.
Live expert-led sessions, which is what MentorCruise runs, put a practitioner in the room with your team for a fixed block of time, working from a brief you write.
The axes that actually separate them:
| Compliance platform | Course marketplace | Live expert session | |
|---|---|---|---|
| Adapts to your stack and incidents | Limited | No | Yes, it is the point |
| Audit trail and completion evidence | Strong | Partial | No |
| Continuous phishing simulation | Yes | No | No |
| Cost shape | Per seat, per year | Per seat, low | Per session, from $250 |
| Time to first delivery | Weeks, plus rollout | Immediate | 1 to 2 weeks |
| Good for 500+ seats | Yes | Yes | Not the right shape |
| Handles "why did our incident happen" | No | No | Yes |
Where a live session is the wrong buy. If your driver is a SOC 2 or ISO 27001 control that requires documented annual security awareness training for every employee, a workshop will not satisfy the auditor. Buy KnowBe4, Proofpoint, or an equivalent, and treat the live session as a separate thing you do because the platform is not changing behavior. I would rather say that plainly than sell you the wrong format and have you discover it during an audit.
The reverse also holds. If you have had the platform for two years, completion is at 98 percent, and people are still clicking things, more modules will not fix it. That is the gap a live session is for.
Compliance and what a workshop does not give you
Worth being precise, because this is where buyers get burned.
Frameworks that commonly require security awareness training include SOC 2, ISO 27001, PCI DSS, and HIPAA for covered entities. What they generally want is evidence: who was trained, on what, when, and proof it repeats on a schedule. A live workshop produces an attendee list and a date. It does not produce per-employee module completion records, and it does not automatically repeat.
Two honest positions follow. If compliance evidence is the requirement, the platform is the purchase and the workshop is optional on top. If behavior is the requirement and compliance is already handled, the workshop is the purchase. Anyone who tells you a single live session covers your audit obligation is selling.
How to make the case internally
The cost side is easy and precise: a half day from $500, plus the working time of everyone attending. Write both numbers down. Underselling the time cost is how these proposals fall apart in the second meeting.
The benefit side is where people invent numbers, and I would rather you did not. There is no defensible figure for how much a workshop reduces breach probability at your company, and any provider quoting you one is making it up. What you can do instead is anchor on something specific that already happened.
The framing that works:
In the last quarter we had three reported phishing attempts and at least one that reached a manager before it was flagged. Our platform training completion is at 96 percent, so the problem is not coverage. I want to run a half-day session, from $500, built around the actual emails we received, for the twelve people who handle customer data or payments. Total cost is the session plus about forty person-hours.
That paragraph works because it names a real event, concedes what is already in place, scopes the audience narrowly, and gives a real number. It does not promise an outcome.
Questions to have answers ready for:
- "Doesn't the platform already cover this?" For coverage and evidence, yes. For the specific failure we saw, no, and here is why.
- "Why not just send a reminder email?" Because we did, in March, and the same thing happened in May.
- "What do we get afterwards?" A shared vocabulary, a documented reporting path, and the incident tabletop output. Not a certificate.
- "Will one session fix it?" No. A session sets the method. What makes it stick is the manager follow-up and the reporting culture, and that part is on us.
Be honest about that last one. A single session changes behavior for a while and then decays. If nobody reinforces it, you are buying a good afternoon.
How to run a cybersecurity workshop with your team
If you have platform coverage and are still seeing the same mistakes reach the same people, the gap is not more modules. It is somebody in the room who can work through your actual incidents with the team that had them.
That is what a MentorCruise workshop is. You send a brief describing your stack, your team, and what went wrong. We match you with a vetted practitioner inside 48 hours, and most sessions run within one to two weeks. Two hours starts from $250, a half day from $500, and pricing is quote-based against your brief rather than a fixed package. Under 5 percent of applicants make it onto the platform, so the person in the room has done the work rather than just taught the slides.
Request a quote for a cybersecurity workshop and describe what you are trying to fix. You get a quote and a proposed expert back, not a signup flow.
If you are still comparing formats and providers more broadly, the guide to choosing a corporate training company covers the same decision across every topic.
FAQs
How much does cybersecurity training for employees cost? Live expert-led sessions start from $250 for two hours, $500 for a half day, and $900 for a full day, quote-based against your brief. Compliance platforms price differently, per seat per year, and get cheaper per head as headcount grows. For a team under about thirty people, the live session is usually the cheaper way to address a specific problem.
How long should the training be? A half day covers the core agenda for most teams. Two hours works if you are targeting one topic, usually phishing. A full day makes sense when you want role-specific breakouts and an incident tabletop exercise as well.
How often do employees need cybersecurity training? Most compliance frameworks expect it annually, with new-hire training at onboarding. Behavior decays faster than that, which is why the platform-plus-occasional-live-session combination is common: the platform handles the annual cadence and the evidence, and the live session handles whatever is currently going wrong.
Is a one-off workshop enough on its own? No, and I would not claim otherwise. A session gives a team a shared method and a shared vocabulary. What makes it stick is what managers do in the following weeks, and whether reporting a mistake is genuinely safe. Buy the session as a starting point, and plan the reinforcement yourself.
We already have KnowBe4. Is this a replacement? No. It is a supplement for a specific gap. Keep the platform for coverage, simulation, and audit evidence. Add a live session when completion is high and the same mistakes keep happening, because that is a problem more modules do not solve.
Can you train a remote or distributed team? Yes. Sessions run live over video, which is how most of them run. The tradeoff is that the incident tabletop works better with a smaller group, so for a distributed team of more than about fifteen it is usually worth splitting into two sessions rather than one large one.