What Done-for-You Security Awareness Training Means in 2026

What Done-for-You Security Awareness Training Means in 2026
“Done-for-you” is one of the most overused phrases in the security awareness training category. Every vendor claims it. Most do not deliver it. The gap between what the term should mean and what most vendors actually ship is the reason so many MSP security awareness programs fail in month three.
This guide defines what done-for-you security awareness training should mean in 2026, with specific tests an MSP can run against any vendor pitch to separate real done-for-you from rebranded self-service.
The working definition
Done-for-you security awareness training is a managed service model where the vendor designs, runs, and reports on the security awareness program end-to-end. The MSP partner receives the outcomes and the client-ready reporting without operating the platform daily.
The operative phrase is “without operating the platform daily.” If the MSP team has to log in, design programs, send reminders, or generate reports for the program to function, the service is not actually done-for-you — it is self-service with vendor consulting wrapped around it.
The five tests for genuine done-for-you delivery
Test 1: The do-nothing test
If the MSP does nothing for a month, does the program still run for every client?
Training enrollments should still go out. Phishing simulations should still deploy. Reminders should still fire. Monthly reports should still generate. If any of these break when the MSP is inactive, the program is not done-for-you.
Test 2: The new-client onboarding test
When the MSP adds a new client, how much MSP time does it take to bring that client into the program?
Genuinely done-for-you delivery means under 60 minutes of MSP time per new client — mostly identity-provider integration and program-tier selection. The vendor handles design, configuration, content selection, and program scheduling.
Test 3: The reporting test
Are client-ready monthly reports generated automatically by the vendor and delivered to the MSP in a format that drops directly into a Quarterly Business Review?
If the MSP is rebuilding reports in slides, the platform is doing the data half but not the delivery half.
Test 4: The threat-response test
When a new attack pattern emerges — a new phishing kit, a new social engineering technique, a deepfake-driven program — how does the program adapt?
Done-for-you means the vendor updates content and program templates without MSP intervention. Self-service means the MSP has to discover the threat, find or build new templates, and reconfigure programs.
Test 5: The exception-handling test
When an employee has a problem — missed training, broken email link, complaint about a phishing simulation — who handles it?
Done-for-you platforms route exceptions through vendor-managed support. Self-service platforms surface every exception to the MSP, who then routes it to the vendor.
What done-for-you should include in 2026
The baseline scope of a done-for-you security awareness training service should include:
Program design
The vendor designs the training cadence, phishing simulation schedule, and content mix based on the client’s industry, size, and risk profile. The MSP can input preferences; the vendor delivers the plan.
Content curation
The vendor selects which training modules to assign each month from their library, sequences them in an effective learning order, and refreshes the selection based on emerging threats. The MSP does not pick courses.
Program execution
Phishing simulations and training assignments deploy automatically on the scheduled cadence. The vendor handles all platform operations to make this happen.
Reinforcement and reminders
Employees who miss training receive automated reminders. Escalation paths fire when reminders fail. The vendor manages this layer without MSP involvement.
Client-ready reporting
Monthly reports generate automatically, branded for each client, with narrative explanations the MSP can drop directly into QBRs. Quarterly executive summaries roll up the trends.
Continuous improvement
The vendor analyzes results across the program, adjusts difficulty for risk-tier users, refreshes content based on threat trends, and surfaces optimization recommendations to the MSP.
Sales and renewal enablement
The vendor provides QBR templates, pricing playbooks, sales scripts, objection-handling guides, and client-facing materials. The MSP focuses on the client relationship; the vendor provides the delivery and the proof.
Anything less than this list is partial done-for-you. Partial done-for-you is fine — some MSPs want more control — but the MSP should know exactly which pieces the vendor is delivering and which pieces the MSP is responsible for.
The economics of done-for-you
Done-for-you typically commands a higher per-user license fee than self-service. The premium pays for the operational labor the vendor absorbs.
The right way to evaluate the cost is total cost of ownership, not license fee:
- License fee per user, per month
- Plus MSP labor hours per client per month, valued at fully loaded rate
- Minus revenue per client per month for the SAT line item
For most MSPs at scale, the done-for-you total cost is lower than self-service total cost despite the higher license fee. The MSP labor cost of operating self-service across many clients quickly exceeds the license-fee premium of done-for-you.
When done-for-you is not the right fit
Done-for-you is not the right model for every MSP. The patterns where self-service still makes sense:
- The MSP has a dedicated security awareness specialist or vCISO with capacity to spare
- The MSP serves fewer than ten clients and operational load stays manageable
- The MSP serves clients with significantly different program requirements that need bespoke design per client
- The MSP wants maximum control over program design and content selection for strategic reasons
For MSPs that match any of these patterns, self-service offers more granular control and a lower license fee. For everyone else — which is the majority of the market — done-for-you is the model that compounds advantage over time.
Hook Security’s done-for-you model
Hook Security delivers Security Awareness on Autopilot — a done-for-you managed program where Hook Security designs, runs, and reports on the security awareness program end-to-end. MSP partners receive client-ready outcomes and reporting without operating the platform daily.
The model is built around the five tests above. The do-nothing test, the new-client onboarding test, the reporting test, the threat-response test, and the exception-handling test all pass by design. Hook Security supports over 500 MSP partners running done-for-you security awareness across thousands of client environments.
Frequently asked questions
What is done-for-you security awareness training?
Done-for-you security awareness training is a managed service model where the vendor designs, runs, and reports on the security awareness program end-to-end. The MSP partner receives the outcomes and the client-ready reporting without operating the platform daily.
How is done-for-you different from managed security awareness?
The terms are often used interchangeably. Both describe a service model where the vendor handles operational delivery. “Done-for-you” emphasizes the outcome (the MSP receives a finished program); “managed” emphasizes the operation (the vendor runs the platform). The substance is the same.
Is done-for-you SAT more expensive than self-service?
License fee per user, yes. Total cost of ownership including MSP labor, almost always no. The labor cost of self-service at MSP scale typically exceeds the done-for-you license premium.
Can MSPs offer both done-for-you and self-service?
Yes. Some vendors support both models in a single partnership, which lets MSPs match the model to the client. Hook Security supports done-for-you as the default and offers co-managed options for MSPs that want more control on specific accounts.
Keep reading
- The MSP’s 15-minute QBR template — how to report the results a done-for-you program produces.
- Best security awareness training for MSPs (2026) — how the done-for-you platforms compare.
- Four pricing models for SAT — how MSPs turn a managed program into margin.
Ready to Strengthen Your Security Culture?
See how Hook Security can help protect your organization.