What to Ask Before Renewing Security Awareness Training
The renewal notice landed, the per-seat price went up again, and you already have a pretty good idea how the training is going. Videos play in a background tab. Completion jumps to 100% the week before the deadline, right after the third reminder email. Nobody complains. It just doesn’t come up.
Switching security awareness training vendors sounds like one more project for a calendar that’s already full, so signing another year feels like the reasonable call.
Before you decide, spend an hour with your account rep and ask five simple questions. They’re the questions to ask any security training vendor at renewal, and we’d expect you to ask them of us, too. If the answers hold up, renew and stop thinking about it. If they don’t, you’ll know what to look for instead.
Why the renewal call matters more than it looks
At a company of 50 to 250 people, security awareness training usually belongs to someone who also owns the network, the laptops, the vendor contracts, and whatever broke this morning. You set training up once, and it runs in the background.
Renewal is the one point in the year when you have your vendor’s full attention and some real leverage. Once you sign, the next chance to ask could be a year or more away.
It’s also part of your security budget aimed squarely at people or “human risk management.” The 2026 Verizon Data Breach Investigations Report found a human element in 62% of confirmed breaches. Filters catch a lot, and the rest comes down to whether the person who opens it recognizes it.
5 questions to bring to the renewal call with your vendor
Each question comes with what a strong answer sounds like, so you’ll recognize one when you hear it.
How recent is the newest lesson our people have seen, and what real attack was it based on?
Ask for a date and a story. Most providers add new material regularly, so the more useful question is whether anyone at your company saw something this year that looks like what’s landing in their inbox now. Find out when your team was last assigned something new, and whether recent lessons cover current tactics like QR code phishing or a voice call that sounds exactly like your CEO.
Listen for a month and a named incident in the answer. If you get a catalog count instead, ask for the newest lesson specifically.
What do our engagement rates look like beyond completion?
A completion rate tells you the video reached its last frame. Engagement is a different question. Ask your rep for what sits underneath: First-attempt quiz scores, phishing simulation click and report rates across your contract term, and how those numbers compare by department.
The number worth looking for is a trend that moves. If phishing click rates are flat after a year of training, the program is mostly producing records. Those records have value at audit time. They just can’t tell you whether the next convincing email gets clicked.
Does the training know which kinds of pressure work on each person?
People fall for different things. Your controller might ignore every gift card offer and still click instantly on anything that looks urgent from the CEO. Your newest sales hire might be the opposite. When everyone gets the same assignment, most of each person’s training time goes to lessons they don’t need.
Ask whether phishing simulations measure which emotional pressures work on which people, such as urgency, fear, or curiosity, and whether the coaching that follows is built around those results.
What will we pay per seat in years two and three?
Most vendor comparisons start and stop with the first-year price, which is the least useful number in the contract. A fair security awareness training comparison looks at total cost over the full term. Ask for per-seat pricing for every year of the contract in writing, and whether that price is locked or can change before the term ends. Then confirm that the features you rely on are part of your package and not sold separately.
What does switching security awareness training vendors actually involve?
You may never need this answer, but it’s still worth having. Ask whether you can export your training records and phishing history, since an auditor or cyber insurance carrier may want to see them later.
Ask the same about anything your team built inside the platform. Licensed training content normally stays with the vendor that made it, so don’t expect to take their videos with you. Find the auto-renewal date and notice period in your contract and put both on your calendar. Then ask what setup with a new vendor involves and who does the work.
None of these questions are aggressive. Account reps field these questions every day, and renewal is when the answers are easiest to get. A vendor that’s easy to leave must keep earning the renewal. That works in your favor whether you stay or go.
How to evaluate your renewal once the answers are in
If all five questions come back strong, sign with confidence and keep this list for next year. You’ll have the answers in writing and a baseline to measure against. If the answers come back vague, it’s worth a second conversation or shopping around before you sign anything. Changing vendors only makes sense when it changes something for your people.
How NINJIO answers the same five questions
We wrote these questions knowing we’d have to answer them, too. Prodigy Plus, our standard package, includes everything below, unless we say otherwise.
Freshness. A new NINJIO AWARE episode comes out every month. A recent episode, Calendar Con, is about calendar invite phishing and was inspired by a data breach in April 2026.
Hollywood writers and animators make each episode, which runs three to four minutes and is inspired by a real-world attack. The rest of the month keeps the topic in front of people in small doses: A quiz and blog post in week one, an infographic in week two, a reminder comic in week three, and a teaser for the next topic in week four.
Attention. Short episodes with characters and a plot get watched for the same reason people finish a good show. NINJIO Insights shows you whether that’s happening at your company. The phishing dashboard breaks results out by campaign, user group, or individual across any date range: Lure rate, time to lure, report rate, and how long people take to report.
Training results sit alongside them: Completions, quiz performance, and who passed, failed, or hasn’t finished. You can schedule any of these reports to export to managers automatically.
All these security awareness metrics are measured through phishing behavior, and NINJIO clients see an 80-90% reduction in phishing susceptibility within six months based on our internal data.
Personalization. NINJIO PHISH3D simulations test each person against the seven emotional pressures attackers lean on: Fear, urgency, greed, curiosity, social pressure, opportunity, and obedience. Those results build each person’s Emotional Susceptibility Profile (ESP).
NINJIO SENSE then sends that person a 60-second coaching episode every month aimed at the pressure that works on them, and it adjusts as their behavior changes. You can also see which pressures are shifting across your organization over time. For example, fear giving way to curiosity and urgency.
Price. Sign a one-, two-, or three-year contract, and we lock your per-seat price for the full term.
Switching. Your training records and phishing history are yours to export, and so is any training your team builds with our Training Content Generator. NINJIO’s own episodes are licensed content, so those stay with us.
NINJIO connects with Microsoft 365, Google Workspace, Entra, and Okta. Learners can watch from an emailed link with no login, or you can run episodes in any LMS that supports SCORM, xAPI, or HTML5.
If you’d rather not run the training program yourself, our Managed Services Program is available as an add-on and can handle kickoff, onboarding, scheduling, and reporting.
Most security awareness programs go live within a few weeks of signing. You find out whether the training is working in months, not at your next renewal. Hands-on setup usually takes less than two hours. Get the minute-by-minute breakdown on setting up your NINJIO account.
See a NINJIO episode before your renewal call
Watch a full episode. It takes about three minutes. Then compare it to the last training your team was assigned and decide which one you’d rather put in front of them every month.
If you’d like all five answers from us in writing, you can also book a demo and bring your renewal date.
Frequently Asked Questions
Ask when the newest lesson was made and what real attack it was inspired by, how engagement looks beyond completion rates, whether training adapts to the pressures that work on each person, what you’ll pay per seat in every year of the term, and what you can take with you if you leave.
It depends on what the increase buys. If phishing results are improving and the content reflects attacks happening now, a higher price can be fair. If the invoice is the only number moving, compare total cost over a full term with at least one other vendor before you sign.
It’s usually less work than teams expect. Export your training and phishing records, check your notice period, and ask the new vendor who handles setup. Most NINJIO programs go live within a few weeks of signing.
Training short enough that people actually watch it (around three to four minutes), phishing simulations that show behavior changing over time, a per-seat price that holds for the length of the contract, and as little admin work as possible, since security is usually one job among several.