How to Audit Your MSP's Security Awareness Training Program in 30 Minutes

How to Audit Your MSP’s Security Awareness Training Program in 30 Minutes
Most MSPs do not formally audit their security awareness training (SAT) program. The program runs, reports get pulled when clients ask, and life moves on. Then a client renewal stalls, an insurance carrier asks for evidence, or the cyber liability premium goes up — and the MSP realizes nobody actually knows whether the program is working.
A proper audit does not require a consulting engagement. The signals that matter can be assessed in thirty minutes if you know what to look for. This is the checklist Hook Security recommends MSPs run quarterly.
Block out thirty minutes, open your SAT platform’s console, and answer the seven questions below. Each one has a pass condition. Count your passes at the end — the score tells you whether you have a healthy program, a drifting one, or a program that is quietly running you.
Question 1: Is every client actually enrolled and running? (minutes 0–4)
Start with coverage, because it fails silently. List your clients, then list the tenants with an active simulation and training schedule this month. The gap between those two lists is where the audit usually ends early: a client onboarded in a hurry, a program paused for a busy season and never resumed, new hires sitting outside the enrollment group. Pass condition: every contracted client has a live monthly cadence, and new employees are auto-enrolled within their first week.
Question 2: Are completion rates holding above 90%? (minutes 4–8)
Completion rate is the number your client contract implicitly promises and the first number an insurance carrier asks about. Pull it per client for the last quarter. Healthy programs hold above 90% without heroics because the training is short and watchable; drifting programs show a slow slide as assignments pile up unwatched. Pass condition: above 90% across clients — and no single client below 80%, because that client is your next uncomfortable renewal call.
Question 3: Is the reporting rate rising? (minutes 8–12)
Click rate gets the attention, but it is a noisy number — it moves with simulation difficulty as much as with employee skill. The metric that actually measures a maturing security culture is the reporting rate: the share of employees who flag the simulation instead of ignoring or clicking it. A rising reporting rate means employees are becoming sensors. Pass condition: reporting rate trending up quarter over quarter, and a one-click way for employees to report real suspicious email.
Question 4: What happens in the moment someone clicks? (minutes 12–16)
Click on your own simulation and watch what an employee experiences. If the answer is a scolding page, a write-up, or nothing at all, the program is training people to hide mistakes. The click is the single best coaching moment a security program ever gets: attention is total, and the lesson writes itself. Pass condition: an immediate, friendly training moment at the click — education, not shame — and no punitive process attached to simulation results.
Question 5: Can you produce compliance evidence in five minutes? (minutes 16–20)
Pick a client with a cyber insurance renewal coming and time yourself producing what the carrier questionnaire asks: proof that training ran, who completed it, and when. If the answer lives in screenshots and spreadsheet exports, the program has an evidence problem that surfaces at the worst possible moments. Pass condition: a per-client report, generated in minutes, that you would hand to a carrier or auditor unedited.
Question 6: How much admin time does each client cost you? (minutes 20–24)
Estimate the hours your team spent on SAT administration last month — scheduling simulations, chasing completions, assembling reports — and divide by client count. This number is your margin, inverted. If the program depends on a technician remembering to launch things tenant by tenant, you do not have a program; you have a recurring task list wearing one. Pass condition: under half an hour per client per month, which in practice requires automation and a single multi-tenant console rather than per-tenant logins.
Question 7: Would the program survive a renewal conversation? (minutes 24–30)
Open the last report you actually sent a client. Would a non-technical owner look at it and conclude the service is worth paying for another year? A healthy program produces a story — two numbers moving the right way and an employee who forwarded a real phish before anyone clicked it. A drifting one produces a PDF nobody reads. Pass condition: a client-facing monthly report you are proud to send unprompted, not one you assemble when asked.
Scoring your audit
- 6–7 passes: healthy. Keep the quarterly audit cadence and spend your energy on the renewal story.
- 4–5 passes: drifting. The usual culprits are coverage gaps and manual administration — fix enrollment automation first, because every other number improves downstream of it.
- 3 or fewer: the program is running you. The honest question is no longer process tuning — it is whether the platform underneath makes these failures structural.
That last case is usually an operating-model problem, not an effort problem. The self-service vs done-for-you decision framework walks through when it is rational to stop running SAT by hand.
Where Hook Security fits
Hook Security is built so this audit passes by default. Autopilot runs the monthly simulation and training cadence across every client from one multi-tenant console, the Training Moment delivers the friendly lesson at the click, auto-enrollment keeps new hires covered, and per-client reporting is generated for you — completion and reporting-rate trends on one page a business owner understands. Hundreds of MSPs run it this way. Hook prices per seat with every feature included — no add-on ladder, no multi-year term; MSP partner pricing is available on request.
Frequently asked questions
How often should an MSP audit its SAT program?
Quarterly. Monthly is busywork — the numbers barely move — and annually lets a drifting program decay for too long. Run the thirty-minute version each quarter and reserve a deeper review for the client QBR cycle.
Why is click rate not one of the seven questions?
Because click rate on its own rewards the wrong behavior: you can drive it to zero by sending easy simulations, and learn nothing. Judge clicks per tactic and per difficulty if you track them at all, and treat completion rate and reporting rate as the health metrics — they are the ones that improve when the culture does.
What should I do if a client fails most of the audit?
Treat it as a reset, not a crisis. Re-run onboarding for that tenant — enrollment, cadence, reporting — and tell the client you are doing it; the transparency itself rebuilds confidence. A failed audit you caught is a better renewal story than a healthy-looking program nobody inspected.
Keep reading
- Onboard a client to SAT in under 60 minutes — the fix for most coverage-gap failures.
- How MSPs win renewals with security awareness — what a passing Question 7 looks like in practice.
- The MSP’s SAT buying guide for 2026 — if the audit says the platform is the problem.
- See Hook in action — all-inclusive, no add-on ladder, no multi-year term.
Training courses on this topic
From Hook Security’s security awareness training library.
- 30 minPCI Security Awareness TrainingPCI (Payment Card Industry) compliance training is designed to educate employees on the requirements and best practices for protecting payment card data. Compliance with PCI standards is required by contractual agreements between organizations and payment card brands.
- 30 minGDPR Security Awareness TrainingGDPR compliance training educates employees on the principles, requirements, and best practices for protecting personal data of individuals within the EU and EEA.
- 30 minHIPAA Security Awareness TrainingWelcome to your HIPAA Security Awareness Training for HIPAA covered entities and business associates. Our HIPAA Compliance Training gives employees a HIPAA introduction including how to recognize PHI (protected health information), proper uses and disclosures of PHI, how to keep PHI secure, and how to report a breach of PHI.
Ready to Strengthen Your Security Culture?
See how Hook Security can help protect your organization.