Cyber Insurance and Security Awareness Training: What MSPs Need to Know in 2026
Cyber Insurance and Security Awareness Training: What MSPs Need to Know in 2026
Cyber liability insurance has quietly become one of the strongest sales arguments for security awareness training (SAT) in the MSP channel. Carriers have spent the past three years tightening underwriting standards, and SAT is now one of the questions every carrier asks before quoting a renewal. MSPs that understand how the conversation works have a structural advantage in both client retention and SAT program expansion.
This guide breaks down what cyber insurance carriers actually require, how SAT shows up in the application and renewal process, and what MSPs should document to make sure their clients pass underwriting cleanly.
---
Why cyber insurance carriers care about SAT
Cyber liability claims data tells a consistent story: over the human element is involved in 62% of breaches (Verizon DBIR 2026). Phishing-driven account takeover, business email compromise, ransomware delivered via clicked links — the common thread is an employee who made a wrong decision in front of an attack.
Carriers underwrite against that data. A client with a real, measurable security awareness program represents lower expected claim severity than a client without one. Carriers price that difference into premiums and, increasingly, they require evidence of SAT as a precondition for issuing or renewing a policy.
Practical implication for MSPs: SAT is no longer just a security service. It’s a precondition for the client’s broader risk-management posture.
- When the SAT program slips, the cyber liability premium goes up.
- When the program runs consistently and produces measurable results, the premium often goes down at renewal.
---
What carriers ask about SAT in 2026
The specific questions vary by carrier, but the standard application now covers six core areas:
1. Program presence
Question: Does the organization have a security awareness training program?
Most carriers want a yes/no answer with supporting documentation. “Yes” without proof is treated as a risk.
2. Program cadence
Question: How often does training run?
Carriers increasingly expect monthly cadence as the standard. Annual training is treated as inadequate and often priced as if there is effectively no program.
3. Phishing simulation cadence
Questions:
Does the organization run phishing simulations?
How often?
What’s the average click rate?
Carriers want the trend, not just a snapshot. A monthly simulation schedule with improving click rates is a strong underwriting signal.
4. Completion rates
Question: What percentage of users complete required training within the assigned window?
Typical underwriting thresholds:
- Below 70%: Yellow flag
- Below 50%: Red flag
High completion rates, especially across critical roles (finance, HR, executives), are treated as a positive control.
5. Reporting and documentation
Question: Can the organization produce reports showing program execution and behavioral trends?
From a carrier’s perspective, “We have a program but no reports” = “We have no program.”
They expect to see:
- Evidence of training delivery
- Phishing simulation results
- Behavioral trends over time
6. Vendor and managed-service relationship
Question: If the program is delivered by an MSP or vendor, who is the provider?
Some carriers maintain internal lists of vendors and MSP-delivered programs they consider sufficient for underwriting. Being able to name a recognized SAT vendor and a managed delivery model can improve underwriting confidence.
Bottom line for MSPs: The MSP that can produce confident, documented answers to all six questions has a client whose cyber insurance application typically sails through. The MSP that can’t is the MSP whose client is renegotiating their premium upward.
---
How SAT affects premiums in practice
The premium impact of SAT varies by carrier, client size, and industry, but typical 2026 patterns look like this:
- No SAT program
- Standard premium +10–25% loading, or
- Outright declination from premium-tier carriers
- Annual SAT only
- Treated as a minimal control
- Standard premium with little or no discount
- Often insufficient for premium-tier carriers
- Monthly SAT with phishing simulations
- Standard premium with positive underwriting
- Better access to higher-quality carriers
- Monthly SAT with documented behavioral improvement trends
- Standard premium with potential 5–15% reduction at renewal
- Improvement in click rates, report rates, and completion rates is key
- Monthly SAT with vendor-validated managed delivery
- Best-case premium pricing, especially for SMB clients
- Carriers view managed SAT as more consistent and auditable
For MSPs, the critical insight is that documentation is the variable, not just the program itself. Two clients can run similar SAT programs, but the one with clean, carrier-ready documentation usually gets the better pricing.
---
The documentation carriers want
Most cyber insurance carriers want three specific artifacts when they evaluate SAT:
1. Program description
A concise, one-page description of the SAT program that covers:
- Cadence (e.g., monthly training, monthly phishing simulations)
- Vendor and delivery model (e.g., MSP-managed via Hook Security)
- Content topics covered annually (e.g., phishing, passwords, social engineering, data handling)
- Phishing simulation approach (frequency, targeting, difficulty)
This is usually shared at application or renewal and becomes part of the underwriting file.
2. Trend reports
Year-over-year metrics that show directional change, not just a single data point:
- Phishing click rates
- Training completion rates
- Phishing report rates (users reporting suspicious emails)
Carriers want to see that the program is:
- Running consistently
- Driving measurable behavioral improvement
Ready to Strengthen Your Security Culture?
See how Hook Security can help protect your organization.