Skip to main content

What Is Co-Managed Security Awareness Training?

Zach Eikenberry, CEO
Illustration of an MSP and a security vendor sharing responsibility for a security awareness training program

What Is Co-Managed Security Awareness Training?

Co-managed security awareness training is the middle path between fully self-service and fully done-for-you. It is the operating model most MSPs eventually land on once they understand what they actually want to own and what they want a vendor to handle.

This guide defines co-managed security awareness, explains where the responsibilities split, and helps MSPs decide whether a co-managed approach fits better than either of the alternatives.

The working definition

Co-managed security awareness training is a hybrid service model in which the MSP and the vendor share operational responsibility for the program. The vendor handles delivery automation — simulation and training execution, reminders, reporting — while the MSP retains decision-making authority over program design, content selection, and strategic positioning with clients.

The defining characteristic is split responsibility along the design-versus-execution axis:

  • The MSP decides what the program does.
  • The vendor makes it happen consistently.

Who owns what, in practice

The split only works when both sides know exactly which decisions are theirs. In a well-run co-managed program, the MSP owns:

  • The client relationship, positioning, and pricing of the service line
  • Program goals per client - which behaviors matter, what "good" looks like this quarter
  • Simulation difficulty, timing windows, and any client-specific exclusions
  • The QBR: interpreting results, telling the story, recommending next steps
  • Escalations - the conversation when a client asks why the numbers moved

And the vendor owns:

  • Executing phishing simulations on the agreed cadence, every month, for every client
  • Delivering training and the instant coaching moment when an employee clicks
  • Reminders, chasers, and completion follow-up
  • Client-ready reports generated on schedule
  • Content freshness - new lures, new attack types, updated micro-learning

Notice the pattern: everything the MSP keeps is judgment work a client would happily pay an expert for. Everything the vendor takes is repetition work that eats margin.

A month of co-managed, concretely

Week one: the platform launches the month’s simulations across all clients automatically; the MSP touches nothing. Weeks two and three: training and coaching moments deliver themselves; the platform chases stragglers. Week four: reports generate; the MSP spends its only real hours of the month reading trends and preparing QBR narratives for the two or three clients meeting that quarter. Total MSP labor: a few hours across the whole client base, all of it billable-grade advisory rather than administration.

When co-managed is the right model

If you have not yet decided between the three operating models, start with the self-service versus done-for-you decision framework - co-managed is the deliberate middle. It fits MSPs that match these patterns:

  • Security expertise is your differentiator - you sell judgment, vCISO services, or compliance advisory, and you want awareness training to showcase that expertise rather than consume it
  • You want control over strategy without owning execution labor
  • Your clients expect YOU in the room - they buy your interpretation, not a vendor’s PDF
  • You have been burned by pure self-service stalling in month three, but pure done-for-you feels like giving up the steering wheel

If none of that describes you - if you simply want the service line to run itself profitably - fully done-for-you is the simpler answer.

The pitfall: unclear ownership

Co-managed programs fail one way: nobody wrote down the split. The MSP assumes the vendor is watching completion rates; the vendor assumes the MSP wanted to handle it; the client notices first. The fix is boring and works - a one-page responsibility sheet agreed at onboarding: who owns launches, who owns escalations, who talks to the client, and when. Ask any prospective vendor for theirs. If they do not have one, they have not really run co-managed programs.

Where Hook Security fits

Hook Security’s platform is built so the split lands cleanly. Autopilot handles the vendor side - phishing simulations, monthly micro-learning, reminders, and client-ready reporting run continuously across every client from one multi-tenant console. The MSP keeps the strategy dials: simulation cadence and difficulty, scheduling windows, per-client program goals, and the reporting story. Hundreds of MSPs run Hook this way, from fully hands-off to actively co-managed, and the model can shift per client without changing platforms.

Pricing is published - $2 per seat per month ($20 per seat per year billed annually), or $999 per year flat for organizations under 50 seats, no setup fees - and partner pricing for MSPs is wholesale, tiered on aggregate seats across your clients.

Frequently asked questions

What is the difference between co-managed and done-for-you?

Who holds the steering wheel. In done-for-you, the vendor makes program decisions and the MSP mostly resells the outcome. In co-managed, the MSP makes the program decisions - goals, difficulty, cadence, client communication - and the vendor executes them consistently. Delivery automation is identical; decision authority is not.

Is co-managed more work than done-for-you?

Yes, by design - but it is the right kind of work. The hours you keep are strategy and client advisory, the work clients value and pay for. The hours you shed are administration. If the retained hours are not billable-grade for your business, choose done-for-you instead.

Can we start done-for-you and move to co-managed later?

Yes, and it is a common path: start hands-off while the service line proves itself, then take over strategy for your largest clients as the program matures. On a platform where both models coexist, the shift is a permissions-and-process change, not a migration.

Keep reading

Ready to Strengthen Your Security Culture?

See how Hook Security can help protect your organization.