Skip to main content

The MSP’s 15-Minute QBR Template for Reporting Security Awareness Results

Clipboard checklist and 15-minute clock illustrating the MSP security awareness QBR template

The MSP’s QBR Template: How to Report Security Awareness Results to Clients in 15 Minutes

Quarterly Business Reviews are where security awareness training (SAT) programs either prove their value or quietly disappear.

If the SAT line in your QBR comes with a clear story — here’s what we delivered, here’s what improved, here’s what’s next — it protects the renewal and reinforces your value.

If SAT shows up as a single bullet — “Security awareness training: continue?” — it becomes an easy target in the next cost-cutting conversation.

This template is designed for MSPs who want to:

  • Make SAT a visible, defensible line item in every QBR
  • Prepare each client’s SAT section in 15 minutes or less
  • Turn raw platform data into an executive-ready story

Use this as your standard QBR SAT section for every client, every quarter.

---

The Five-Section QBR Template

Every client’s SAT section in a QBR should answer five questions in this exact order:

  1. What did we deliver this quarter?
  2. What changed in the data?
  3. What does the change mean?
  4. What’s coming next quarter?
  5. What does the client need to do?

The structure is non-negotiable and the order matters:

  • Sections 1 & 2 prove the program is real and measurable.
  • Section 3 is where you add value through interpretation.
  • Sections 4 & 5 set up the next quarter and the renewal conversation.

Keep each section to one slide (for presentations) or one short paragraph (for written reports).

---

Section 1: What We Delivered

Start with a quick recap of program activity for the quarter. This should fit on one slide or a short paragraph.

Include:

  • Training assignments delivered: [N] modules across [N] users
  • Phishing simulations sent: [N] programs across [N] users
  • Reminders and reinforcement: [N] follow-ups sent automatically
  • Auto-remediation: [N] users received targeted training after phishing clicks

The goal is to show that the program ran consistently.

“We delivered three training modules and three phishing simulations this quarter across all 84 users” is more powerful than any isolated percentage.

Implementation tip:

  • If your SAT platform generates this section automatically, this is 60 seconds of prep.
  • If you’re pulling these numbers manually, your platform is doing only half the job.

---

Section 2: What Changed in the Data

Next, show the key metrics and how they’re trending.

Focus on three numbers, each with a trend line:

  • Phishing click rate: [This quarter’s average] (vs [Last quarter’s average])
  • Training completion rate: [This quarter’s average] (vs [Last quarter’s average])
  • Report rate (suspicious emails reported): [This quarter’s average] (vs [Last quarter’s average])

Use simple visuals:

  • Up/down arrows
  • Green/yellow/red color coding

Avoid unnecessary precision. Clients don’t care that click rate moved from 7.314% to 6.892%. They care that it went down and why.

If there are important outliers, call them out explicitly, not buried in averages:

  • A department with a much higher click rate
  • A single high-impact phishing simulation

Use a one-sentence callout, for example:

“Finance had a 12% click rate on the wire-transfer simulation vs a 4% company average — we’ll target them with additional training next quarter.”

Pulling this data from automated reports should take about 60 seconds.

---

Section 3: What It Means

This is the most important section and the only one that truly requires your judgment.

Your client cannot interpret the numbers on their own. Your job is to answer two questions:

1. Are we on track?

Compare the trend to what you’d expect from a healthy program:

  • Click rate trending down: On track. Users are getting better at spotting phishing.
  • Click rate flat for 2–3 quarters: Plateau. Time to increase difficulty or expand coverage.
  • Completion rate dropping: Engagement problem. Training may be too long, too frequent, or poorly communicated.
  • Report rate increasing: Positive behavior. Users are more likely to escalate suspicious emails.

2. What story do these numbers tell?

Translate the data into executive language:

  • Data: “Click rate is down 3 points.”
  • Story: “Click rate dropped from 9% to 6% this quarter because the team got faster at recognizing fake DocuSign emails after we ran the document security training in April.”

Stories connect the dots between:

  • What you delivered (Section 1)
  • What changed (Section 2)
  • Why it changed (your interpretation)

Over time, your team will build a library of standard interpretations for common patterns, such as:

  • “Click rate down, report rate up” → Users are both avoiding clicks and escalating suspicious emails.
  • “Click rate flat, completion high” → Training is being completed but not challenging enough; phishing templates should get harder.
  • “One department consistently worse” → Targeted manager conversations and department-specific training are needed.

The first time you write this section for a client, it might take 10 minutes. By the tenth time, it should take 90 seconds using your standard patterns.

Plan to spend 5–7 minutes here per client — this is where your value shows up.

---

Section 4: What’s Next

Now preview the next quarter’s plan so the program feels proactive, not reactive.

Include:

  • Training topics:
    • [List of upcoming monthly themes]
    • e.g., “June: Password hygiene, July: Business email compromise, August: Data handling and document security.”
  • Phishing themes:
    • [Threat categories the simulations will cover]
    • e.g., “Fake DocuSign, MFA fatigue, invoice fraud, HR notifications.”
  • Special activities:
    • [Anything notable — cybersecurity awareness month, compliance documentation pull, new feature rollout]
    • e.g., “October is Cybersecurity Awareness Month — we’ll run a company-wide program and provide internal comms templates.”

This section does two things:

  1. Shows there is a plan, not just ad-hoc activity.
  2. Surfaces any coordination needs, such as:
    • Access review activities
    • User list cleanup
    • Policy acknowledgements

If your platform provides a published 12-month calendar, you should be able to copy the next three months into this section in about 60 seconds.

---

Section 5: What the Client Needs to Do

Keep reading

Ready to Strengthen Your Security Culture?

See how Hook Security can help protect your organization.