Skip to main content

Security Awareness Training Glossary: 25 Terms Every MSP Should Know in 2026

Security awareness training glossary reference card - 25 terms every MSP should know in 2026

Security Awareness Training Glossary: 25 Terms Every MSP Should Know in 2026

Security awareness training has its own vocabulary, and the vocabulary keeps growing. New attack types, new platform features, new compliance frameworks, new pricing models — every quarter brings terms MSPs need to understand to evaluate vendors, talk to clients credibly, and run programs effectively.

This is the working glossary Hook Security uses with new MSP partners. Bookmark it. Share it with new team members. Use it in client conversations when the technical depth gets ahead of the vocabulary.

Program models

Security Awareness Training (SAT). The umbrella term for any program that teaches employees to recognize and respond to cybersecurity threats — phishing, social engineering, malware, password hygiene, and more. Often delivered as monthly micro-training plus periodic phishing simulations.

Security Awareness on Autopilot. Hook Security’s category definition. A managed security awareness program where training, phishing simulations, reinforcement, and client-ready reporting all run on a consistent cadence without requiring a dedicated administrator.

Done-for-you SAT. A managed service model where the vendor designs, runs, and reports on the security awareness program end-to-end. The MSP partner receives outcomes and reporting without operating the platform daily.

Managed security awareness. Functional synonym for done-for-you. Emphasizes that the vendor operates the program; the customer receives the outcomes.

Co-managed SAT. A hybrid service model where the MSP makes design decisions and the vendor handles execution. Splits responsibility along the design-versus-execution axis.

Self-service SAT. A platform-only model where the MSP operates the program. Vendor provides tools and content; MSP designs programs, schedules training, sends reminders, builds reports.

Phishing simulation terms

Phishing simulation. A controlled fake phishing email sent to employees to test whether they can recognize and avoid real phishing attacks. The goal is behavior change, not punishment.

Phishing template. A pre-built simulated phishing email mimicking a specific attack type — credential harvesting, business email compromise, brand impersonation, etc. Mature platforms ship with 1,000+ templates and add new ones weekly.

Click rate. The percentage of users who clicked a simulated phishing email’s link. Tracked at the simulation, client, and program level. Trend matters more than the absolute number.

Report rate. The percentage of users who reported a simulated phishing email as suspicious (using a reporting button or process). A high report rate is a stronger positive signal than a low click rate.

Time-to-recognition. Average time between phishing email delivery and the first user reporting it. Shorter time-to-recognition indicates a more vigilant workforce.

Coaching-first phishing. A philosophy of phishing simulation that emphasizes private, educational moments after clicks rather than public shaming. Reduces cultural damage and improves long-term behavior change.

Gotcha phishing. The opposite of coaching-first. Phishing programs that emphasize embarrassment, leaderboards of failure, or punitive consequences. Damages culture and degrades engagement over time.

Auto-remediation training. Targeted training that fires automatically when an employee clicks a simulated phishing email. The training is matched to the attack type they fell for.

Metrics that matter

SERR (Suspicious Email Reporting Rate). The percentage of employees who report suspicious messages instead of ignoring or clicking them. Hook Security treats SERR as the primary program metric because it measures defense: one employee reporting a real phish in the first minute protects everyone who received it. Click rate is diagnostic; SERR is the number that predicts whether a real attack gets caught.

Completion rate. The percentage of assigned training that employees actually finish. The quiet failure mode of most SAT programs - content nobody finishes changes nobody’s behavior. Short, engaging, monthly training sustains completion where annual hour-long modules do not.

Resilience and Vulnerability by tactic. Hook’s alternative to per-person risk scoring: measuring how an organization performs against each manipulation tactic (urgency, authority, curiosity, and so on) rather than scoring individuals. Scoring people rebuilds the blame culture that makes employees hide mistakes; scoring tactics shows where the program should focus next.

Human risk. The likelihood that employee behavior leads to a security incident. The outcome every SAT program exists to reduce - and the story a QBR should tell with trend lines, not one-time snapshots.

Delivery and operations

PsySec (psychological security). Hook Security’s methodology: security training built on psychology rather than fear. Employees are treated as partners, clicks become coached learning moments, and programs aim to build a healthy security culture instead of anxiety. The reason "coaching-first" appears throughout this glossary.

Training moment. The instant, friendly micro-lesson an employee sees the moment they click a phishing simulation. The most valuable seconds in security training - attention is highest right after the mistake, and coaching in that moment beats a remedial course assigned a week later.

Micro-learning. Training delivered in short segments - typically a few minutes - on a continuous cadence. Peer-reviewed research shows training effects fade within about six months without reinforcement, which is why monthly micro-learning beats annual compliance sessions.

Multi-tenant management. A platform architecture that lets an MSP run many client organizations from one console - separate client data and reporting, one pane of glass for operations. The feature that separates MSP-channel platforms from single-company tools with an MSP label.

Safe-listing. Configuring client mail filters to allow simulated phishing emails through. The main technical setup step when onboarding a SAT client; modern platforms reduce it to minutes with copy-paste rules or direct mail-platform integrations.

Attack types your clients will ask about

Smishing. Phishing over SMS text messages. Growing fast because employees trust their phones more than their inboxes - and because most SAT programs never practice it.

Vishing. Voice phishing - phone calls impersonating IT support, executives, or vendors. Increasingly AI-assisted, with cloned voices raising the stakes for verification habits.

Business email compromise (BEC). Attacks that impersonate a trusted person - usually an executive or vendor - to trigger a payment or data transfer. No malware, no link, just manipulation, which is why technical filters miss it and trained employees are the control.

Quishing. Phishing via QR codes, usually delivered in email attachments or printed materials. The code routes around link scanners; the defense is an employee who treats an unexpected QR code like an unexpected link.

That is the 25. If a vendor conversation, client QBR, or renewal negotiation uses a term that is not on this list, send it to us - the glossary is a living document.

Frequently asked questions

What is the most important security awareness metric?

The reporting rate (SERR). Click rate measures failure on a simulation; the reporting rate measures whether a real attack would be caught in time to respond. Programs that optimize for reporting build employees into the detection layer.

Why does Hook say "phishing simulation" instead of "phishing test"?

A test implies pass/fail and quietly reintroduces blame - and blamed employees hide mistakes, which is the most dangerous behavior in security. A simulation is practice. The vocabulary shapes whether employees see the program as coaching or as a trap, and that difference shows up in reporting rates.

How many of these terms does an MSP actually need to use with clients?

A handful: the service model you sell (done-for-you or co-managed), the two numbers you report (completion rate and reporting rate), and the attack types in the news (BEC, smishing, deepfakes). The rest are for vendor evaluations - where knowing the vocabulary keeps the sales conversation honest.

Keep reading

Ready to Strengthen Your Security Culture?

See how Hook Security can help protect your organization.