The 12-Month Security Awareness Calendar Every MSP Should Steal

The 12-Month Security Awareness Calendar Every MSP Should Steal
The single biggest reason security awareness training programs fail in MSP environments is not bad content. It is inconsistent cadence. Programs that run every month for the full year change behavior. Programs that run hot for three months and then go quiet for six produce no measurable improvement and cost the MSP credibility with the client.
This is the 12-month calendar Hook Security recommends MSP partners use as a starting point for every client. Tune it for industry, season, and client size, but treat the cadence itself as non-negotiable.
The structure: monthly training plus monthly phishing
Every month, every client, gets two activities:
- One training assignment (usually a 5–10 minute micro-module on a single topic)
- One phishing simulation (a single test, themed around the same topic or a current threat)
The two reinforce each other. Training teaches the concept; the simulation tests whether the concept stuck. Auto-remediation training fires when someone clicks, closing the loop.
This structure works across industries and client sizes. The variable is what the topic is each month — which is what the calendar below answers.
The 12-month calendar
January — The new year reset
Training topic: Password hygiene and credential management. Most clients have a backlog of credential cleanup from the holiday season; this is the right month to nudge it.
Phishing theme: Credential harvesting. Microsoft 365 password expiration emails are the highest-impact template here.
Reporting moment: Annual review summary. Pull last year’s program metrics and share with the client champion. This sets up the year’s QBR rhythm.
February — The financial fraud month
Training topic: Business email compromise (BEC) and CEO fraud. February is wire-fraud peak season because corporate financial activity is high.
Phishing theme: Wire transfer fraud, gift card scams, fake executive requests. Test the finance team especially.
March — The tax-season threats
Training topic: Tax-related phishing and identity theft. March–April is the highest-volume tax fraud window of the year.
Phishing theme: Fake IRS notices, payroll fraud, fake tax software notifications.
April — The post-tax cleanup
Training topic: Data handling and document security. Many clients have just generated piles of sensitive tax documents and need a refresher on storage and disposal.
Phishing theme: Shared document attacks, fake DocuSign and Adobe Sign requests, fake invoice processing.
May — The mobile and travel threats
Training topic: Mobile security and travel cybersecurity. Summer travel season starts; remote work patterns shift.
Phishing theme: Travel-related (fake flight cancellations, hotel reservation issues), smishing (SMS phishing), QR code attacks.
June — The cybersecurity culture month
Training topic: Security culture and reporting. Reinforce the “see something, say something” muscle. Make the reporting button visible and friction-free.
Phishing theme: Test the report rate explicitly. Use templates that should be easy to spot and measure how many users actually report them.
July — The social engineering deep dive
Training topic: Social engineering tactics beyond email. Phone-based attacks (vishing), in-person pretexting, social media impersonation.
Phishing theme: Multi-channel attacks — an email followed by a phone call or text message, simulating a real attacker’s playbook.
August — The back-to-business focus
Training topic: Insider threat awareness and access management. Many clients are returning from summer vacation; access reviews are the right activity for the month.
Phishing theme: Internal threat templates — fake HR emails, fake IT support requests, fake password reset notifications.
September — The new attack-vector month
Training topic: Emerging threats. Cover the year’s newest attack patterns — AI-generated phishing, deepfake audio, voice cloning attacks.
Phishing theme: AI-enhanced templates that demonstrate how realistic modern attacks have become.
October — Cybersecurity Awareness Month
Training topic: Comprehensive review of the year’s training. October is national Cybersecurity Awareness Month; clients expect heightened activity. Use this month for higher visibility and reinforcement.
Phishing theme: A multi-template program that mixes attack types. Generate a strong year-over-year report metric for the QBR.
Reporting moment: Cybersecurity Awareness Month recap. Generate a special client-facing summary that ties this month’s program activity to the broader awareness narrative.
November — The holiday-season threats
Training topic: Holiday shopping scams and personal financial security. Employees are vulnerable to personal-life attacks that often cross into work systems.
Phishing theme: Fake delivery notifications, fake holiday gift card offers, fake charity donation requests.
December — The year-end wind-down
Training topic: Out-of-office and travel security. Many employees travel; many will be using personal devices for work email. Reinforce the basics.
Phishing theme: Out-of-office reply attacks, fake holiday party invitations, fake year-end performance reviews.
Reporting moment: Year-end annual report. Roll up the full year’s program metrics into a client-facing report that becomes the foundation for the January QBR.
Why monthly cadence is non-negotiable
The data is consistent across thousands of MSP-managed programs: skipping months produces non-linear damage. A program that runs eight months out of twelve does not produce 67% of the behavior change of a 12-month program. It produces closer to 30%, because the gaps between training reset the learning curve and erode the cultural muscle.
The practical takeaway: pick the calendar (this one, or a variant tuned for your client base) and commit to running every activity, every month, for every client. The hardest months are the ones where nothing major happens — the program manager forgets, the client champion is on vacation, the MSP team is busy with other work. Those are the months a managed program protects against.
How to adapt the calendar for client industry
The baseline calendar works for general SMB clients. Industry tuning makes it stronger:
Healthcare clients: Add HIPAA-specific content in April (HIPAA compliance month) and emphasize patient data handling year-round.
Financial services clients: Heavier emphasis on BEC, wire fraud, and data security throughout the year. Add quarterly compliance documentation pulls.
Legal clients: Emphasize document security, client confidentiality, and privileged communication protection. Add bar-association continuing education credit tracking if relevant.
Government/public sector: Tie content to NIST, CMMC, or other applicable frameworks. Heavy emphasis on FOIA-adjacent data handling.
Manufacturing/industrial: Add OT (operational technology) awareness modules. Phishing themes should include supplier-impersonation attacks.
How Hook Security delivers the calendar
Hook Security delivers Security Awareness on Autopilot — a fully managed program where this calendar runs automatically for every MSP partner’s clients without the MSP team scheduling, building, or deploying a single program. Industry-tuned variants are configured at client onboarding; monthly execution runs without intervention.
MSP partners receive the calendar as a deliverable they can share with clients, and the resulting monthly cadence becomes part of the QBR narrative each quarter. The 12-month rhythm is what makes the program effective and what makes the MSP look proactive every time it surfaces in client conversations.
Frequently asked questions
How often should MSPs run security awareness training programs?
Monthly per client. Monthly cadence is what produces measurable behavior change. Skipping months produces non-linear damage — a program that runs eight months out of twelve produces closer to 30% of the behavior change of a 12-month program, not 67%.
Should MSPs use the same training calendar for every client?
The baseline calendar works for general SMB clients across industries. Tune for industry where it matters — healthcare clients need HIPAA emphasis, financial services need wire-fraud emphasis, legal needs document security emphasis. Most clients can use the baseline as-is.
What happens if an MSP misses a month?
Do not try to make it up by doubling activity the next month. The program goes back on cadence and accepts the gap. The lesson is to fix the operational layer that caused the miss — usually that means moving to a more automated or done-for-you delivery model.
Where can I get the calendar as a template?
Hook Security ships the 12-month calendar as part of the MSP-resellable packaging that comes standard with every partnership. MSP partners receive the calendar, the monthly content recommendations, and the client-facing summary templates that go with it.
Keep reading
- What done-for-you SAT means in 2026 — how to run this calendar without your techs owning it.
- The MSP’s 15-minute QBR template — turn each quarter of this calendar into a renewal story.
- Best security awareness training for MSPs — platforms that automate this calendar.
Ready to Strengthen Your Security Culture?
See how Hook Security can help protect your organization.