TLDR: Security awareness training is a natural add-on for MSSPs, but it only becomes a profitable service when it is packaged, priced, and delivered like one. The best MSSP offerings combine a platform, phishing simulations, reporting, and advisory into tiered subscriptions. This post provides a packaging framework, pricing models, service tiers, and a delivery playbook you can use to turn training into recurring revenue.
Marcus runs a 12-person MSSP serving 80 Midwest SMBs. His clients already pay for endpoint detection, email filtering, and backup. Every quarter, at least one of them asks the same question: “Do you also do that security training thing?”
For two years he answered by handing out a KnowBe4 login and charging cost. The margin was thin, the setup was manual, and the reporting was whatever the vendor export happened to be. Clients stayed, but no one renewed because of training.
Last year he changed the model. He bundled security awareness into three service tiers: a baseline compliance package, a mid-tier behavior-change program, and a premium managed human-risk service. He standardized the cadence, hired a part-time program coordinator, and started reporting risk reduction instead of completion rates. Training revenue tripled. More importantly, client retention in the bundled tier improved, and two clients upgraded to vCISO services because the quarterly reports opened a conversation about broader risk.
That is the difference between reselling a tool and selling a service.
Why Security Awareness Belongs in an MSSP Portfolio
The human attack surface is still the most reliable path into a client environment. The Verizon 2026 Data Breach Investigations Report finds the human element present in 62% of breaches, up from 60% the prior year.1 Mimecast’s State of Human Risk 2026 reports that 96% of security decision-makers expect email security challenges to continue through 2026, and 71% expect negative business impact from collaboration-tool attacks.2
The market response is measurable. Mordor Intelligence estimates the security awareness training market at $6.74 billion in 2026, up from $5.77 billion in 2025, and projects it to reach $14.66 billion by 2031 at a 16.82% CAGR.3 SMBs and mid-market companies that cannot afford a full security team are the natural buyers for a packaged, managed service.
For MSSPs, the offering is strategically attractive for four reasons:
- Low incremental delivery cost. Once templates, automations, and reporting are built, adding users or clients is mostly platform work.
- High retention value. Training is a recurring compliance and insurance requirement, not a one-time project.
- Natural bundling. It fits cleanly with email security, endpoint protection, MDR, and vCISO retainers.
- Differentiation. Many MSPs and MSSPs still sell security awareness as a line item. A structured program with risk metrics stands out.
The economics are also compelling. IBM’s Cost of a Data Breach Report 2025 puts the global average breach cost at $4.44 million, and organizations that use AI and automation extensively in security save an average of $1.9 million per breach compared to those that do not.4 For a client, a $6 per-user-per-month managed awareness service is inexpensive relative to one prevented incident. For the MSSP, that same fee scales across hundreds or thousands of users with limited extra labor.
The Three Components of a Sellable Service
A security awareness service that clients renew contains three layers: a platform layer, a program layer, and an advisory layer. Reselling only the platform is a race to zero margin. Adding the other two layers is what makes it a service.
1. Platform Layer
This is the technology that delivers training, phishing simulations, and reporting. The platform should be multi-tenant, support automation, and provide white-labeled or co-branded client reporting. Key evaluation criteria include:
- True multi-tenant administration across all clients
- Automated user provisioning via directory sync
- Pre-built phishing templates and role-based training tracks
- Executive-ready dashboards and risk metrics
- API access for integration with PSA, RMM, and billing tools
The platform layer is a cost center unless the MSSP adds operational discipline around it.
2. Program Layer
This is the repeatable operating system: the cadence of training, simulations, reminders, and reporting. A mature program layer removes the daily decision-making that kills margins. It includes:
- A standardized onboarding runbook for new clients
- Monthly or quarterly training assignments by role
- Scheduled phishing simulations with difficulty calibrated to client maturity
- Automated remediation workflows for repeat clickers
- A fixed reporting calendar, usually monthly or quarterly
The program layer is what turns a vendor login into a managed service.
3. Advisory Layer
This is the highest-margin layer. It includes risk interpretation, board-ready reporting, policy alignment, and recommendations. The advisory layer is where the MSSP moves from operator to trusted partner:
- Quarterly business reviews with risk trends and action plans
- Mapping training outcomes to compliance frameworks (SOC 2, HIPAA, PCI-DSS, CMMC)
- Incident correlation: connecting phishing simulation results to real email security alerts
- Human risk roadmaps and maturity planning
Advisory is also the bridge to vCISO and governance services. A client who sees quarterly human-risk metrics is a client ready to discuss broader security strategy.
Packaging Models That Work
There is no single right way to package the service. The right model depends on client size, sales motion, and the rest of the MSSP portfolio. Four models are common in mature MSSPs.
A. Standalone Subscription Tiers
Three fixed-price tiers based on capability, not headcount. This is the simplest sales motion and the easiest to quote.
| Tier | Includes | Typical Price Range |
|---|---|---|
| Essential | Annual compliance training, monthly phishing simulations, basic reporting | $3–$6 per user/month |
| Professional | Role-based training, bi-weekly simulations, automated remediation, quarterly business review | $6–$12 per user/month |
| Enterprise | Managed human risk program, custom content, board reporting, policy mapping, vCISO alignment | $12–$20 per user/month |
These prices are illustrative. Actual pricing depends on platform cost, labor intensity, and market positioning. The key is that each tier has a clear service boundary so the sales team does not give away advisory work for free.
B. Bundled with Cybersecurity Stacks
Security awareness is added to a standard stack that includes email security, endpoint protection, MDR, and backup. This positions training as a defense layer rather than a separate product. It also raises the perceived value of the entire bundle and makes it harder for competitors to unbundle.
A typical stack might look like:
- Managed email security and anti-phishing
- EDR/XDR monitoring and response
- Security awareness training and phishing simulation
- Backup and disaster recovery
- Quarterly risk review
Bundling works best when the MSSP can show how the layers reinforce each other. For example, email gateway data can identify real phishing themes that the next simulation should mimic.
C. vCISO Retainer Add-On
For clients already paying for virtual CISO services, security awareness becomes a managed control under the retainer. The vCISO owns the risk strategy, and the MSSP operations team executes the program. This model is less about per-user pricing and more about scope within a fixed monthly fee.
It is also the easiest model to justify. The vCISO can tie training outcomes directly to risk register items, audit readiness, and board reporting.
D. Insurance-Driven Compliance Package
Cyber insurance and compliance frameworks increasingly require proof of security awareness training. An MSSP can package a “compliance-ready” offering that includes training, simulations, policy attestations, and audit-ready reporting. This is especially attractive to healthcare, financial services, and professional services firms.
The package is usually sold as a fixed annual fee per user or as part of a broader compliance retainer. The value proposition is not education; it is lower insurance premiums, faster audits, and fewer compliance gaps.
Pricing for Margin, Not Just Markup
The most common mistake MSSPs make is pricing at platform cost plus a small markup. That ignores the labor of program management, reporting, and client communication. A sustainable service prices all three layers.
A simple cost model:
| Cost Category | What to Include |
|---|---|
| Platform cost | Per-user license from vendor or internal platform |
| Delivery labor | Onboarding, training assignment, simulation setup, remediation |
| Reporting labor | Monthly or quarterly report generation and review |
| Advisory labor | Risk interpretation, board prep, policy alignment |
| Overhead | PSA, documentation, client communication, support |
Target gross margin should typically exceed 50% at scale. If the platform alone consumes 40% of the client price, the service will not survive expansion.
Three pricing levers can protect margin:
- Minimum user counts. A 10-user client should not pay the same per-user rate as a 200-user client. Minimums prevent small accounts from eroding profitability.
- Annual contracts. Annual commitments reduce churn and improve cash flow. They also justify the upfront onboarding work.
- Outcome-based upsells. Premium tiers can include a small success fee tied to measured risk reduction, such as a drop in phishing click rate or an increase in reporting rate.
Building the Service Delivery Playbook
A repeatable service needs a playbook. Without it, each client becomes a custom project and margins collapse. The playbook should cover five areas.
1. Onboarding
Define a standard 30-day onboarding sequence:
- Week 1: Kickoff, stakeholder alignment, directory sync, and risk assessment
- Week 2: Baseline phishing simulation to establish a click rate benchmark
- Week 3: Training assignment and communication plan
- Week 4: First client report and quarterly review scheduling
The goal of onboarding is to establish a baseline and set expectations, not to perfect every detail.
2. Cadence
Fix the operating rhythm. A predictable cadence reduces client anxiety and internal churn. A common cadence is:
- Monthly microlearning module or security tip
- Monthly or bi-weekly phishing simulation
- Monthly automated remediation for high-risk users
- Quarterly executive report and business review
3. Segmentation
Deliver different experiences based on risk. Not every user needs the same training. A practical segmentation:
| Segment | Treatment |
|---|---|
| All users | Foundational training and general phishing simulations |
| High-risk departments | Finance, HR, IT, executives receive targeted simulations and deeper training |
| Repeat clickers | Additional coaching, shorter reinforcement modules, and direct manager notification |
| New hires | Onboarding track within 30 days of hire |
| Privileged users | Admin-specific training on social engineering, credential handling, and incident response |
4. Reporting
Reports should be short, visual, and tied to risk. Avoid leading with completion percentage. A better structure:
- Executive summary: what changed this quarter and why it matters
- Risk metrics: click rate, reporting rate, repeat clickers, time to report
- Benchmarking: how the client compares to industry peers or their own prior quarter
- Actions: what the program will do next and what the client should do
5. Escalation
Define what happens when a user repeatedly fails simulations or when a real incident correlates with training data. A clear escalation path protects the client and limits the MSSP’s liability:
- First failure: automated training assignment
- Second failure: manager notification and additional coaching
- Third failure: client security contact notification and access review recommendation
- Real incident correlation: incident response coordination and policy review
Metrics That Sell and Renew
Clients buy for compliance, but they renew for risk reduction. The metrics that matter in a managed service are behavioral, not administrative.
| Metric | Why It Matters | Target Trend |
|---|---|---|
| Phishing click rate | Measures susceptibility to the most common attack vector | Decrease over time |
| Reporting rate | Shows whether users act as sensors | Increase over time |
| Time to report | Indicates alertness and confidence | Decrease over time |
| Repeat click rate | Identifies persistent high-risk users | Decrease toward zero |
| Training engagement | Tracks whether content is being consumed, not just assigned | Stable or increasing |
| Risk score by department | Enables targeted intervention | High-risk departments improve |
KnowBe4’s 2026 Phishing by Industry Benchmarking Report shows that ongoing training and simulated phishing can reduce susceptibility by 87%.5 That is the kind of outcome that belongs in a renewal conversation, not just a marketing slide.
Avoiding Common Packaging Mistakes
Even experienced MSSPs make these mistakes when adding security awareness to their portfolio:
- Selling training hours instead of outcomes. Clients do not care how many modules exist. They care whether risk is going down.
- Underpricing the advisory layer. Quarterly business reviews, risk interpretation, and compliance mapping are high-value work. They should be in a premium tier or billed separately.
- Letting the vendor define the service. The platform is an ingredient. The service is the recipe, delivery, and measurement.
- Ignoring the client communication plan. Users who see training as surprise punishment will resist. A clear launch communication from the client sponsor changes adoption.
- Failing to connect to real incidents. If a client has a phishing incident, the MSSP should be able to correlate it with simulation data and adjust the program. That is the moment advisory becomes visible.
From Service to Platform Differentiation
The MSSPs that lead in this space treat security awareness as a platform service, not a side project. They invest in:
- Standardized templates and automation
- Multi-tenant dashboards that show all clients at once
- Integration between training data and the rest of the security stack
- A recurring reporting calendar that clients expect
- Clear escalation paths that demonstrate accountability
This is also where a purpose-built platform matters. Symbol Security provides security awareness training, phishing simulations, policy management, and managed program services designed for MSSPs, vCISOs, and internal security teams. The multi-tenant architecture, automation, and executive-ready reporting are built for providers who want to deliver security awareness at scale without scaling headcount proportionally.
The Bottom Line
Security awareness is no longer a nice-to-have training module. It is a recurring, measurable risk control that clients will pay for if it is packaged and delivered like a service.
The MSSPs that capture this opportunity will not be the ones with the best training catalog. They will be the ones with the clearest tiers, the most repeatable delivery, and the metrics that prove risk reduction.
Start with one tier. Define the playbook. Measure what matters. Then expand.
References
- Verizon, 2026 Data Breach Investigations Report. Finds the human element present in 62% of breaches, up from 60% the prior year.
- Mimecast, State of Human Risk 2026. Reports that 96% of security decision-makers expect email security challenges through 2026, and 71% expect negative business impact from collaboration-tool attacks.
- Mordor Intelligence, Security Awareness Training Market Size & Share Analysis. Estimates the market at $6.74 billion in 2026, growing from $5.77 billion in 2025, with projections of $14.66 billion by 2031 at a 16.82% CAGR.
- IBM, Cost of a Data Breach Report 2025. Reports a global average breach cost of $4.44 million and $1.9 million in average savings for organizations using AI and automation extensively in security.
- KnowBe4, 2026 Phishing by Industry Benchmarking Report. Shows that ongoing training and simulated phishing can reduce susceptibility by 87%.
