Security awareness training that satisfies your cyber insurance requirements.
Last 30 days
What cyber insurance underwriters ask for
Requirements vary by carrier, and your own questionnaire is the authority. But across policies the same six asks recur — and the last three are where most organizations discover a gap, because their current platform records attendance rather than behavior.
| What underwriters ask for | What that means | How Hook Security produces it |
|---|---|---|
| Annual training for every employee | All staff, not just the ones with admin rights, completed within the policy period. | Autopilot enrolls everyone from your directory and chases completions without you tracking a spreadsheet. |
| Regular phishing simulations | Run on a recurring cadence, not once before the renewal. | Simulations run continuously on a schedule Hook Security designs and operates. |
| Proof of completion | Per-employee records, dated, exportable. | Completion records are continuous and exportable at any time. |
| Click and reporting rates | Underwriters increasingly want behavioral data, not just attendance. | Every simulation records who clicked, who reported, and how quickly. |
| Remediation timelines | Evidence that failures were followed by corrective training. | Remediation auto-assigns on click, privately and immediately, and the timestamp is recorded. |
| Documentation you can hand over | A report a broker, underwriter or auditor can read without a demo. | Monthly and quarterly reports are generated and formatted for you. |
Why the record matters as much as the training
When you bind a policy, you answer a questionnaire, and those answers become warranties. Incomplete or missing training documentation is a recognized cause of reduced payouts and denied claims — not because the training was skipped, but because it could not be evidenced at the moment it was needed.
A program that runs continuously and records itself removes that risk. The evidence is already there when the broker asks, when the renewal comes, and if a claim is ever filed.
The same evidence covers your compliance frameworks
SOC 2, HIPAA, PCI DSS, CMMC, GDPR and ISO 27001 all expect documented security awareness training. In practice, what an underwriter wants and what an auditor wants are close to the same artifact, so most organizations should not run two programs.
Hook Security integrates with Vanta to supply that evidence automatically, forwards events to Splunk for SIEM correlation, and exports records via REST API or CSV for any other compliance platform or auditor request. See the full integrations list.
Who this is for — and who it is not
A good fit
- Small and mid-sized businesses facing a renewal questionnaire or an audit, without a dedicated security team to run a program.
- Organizations that need training documented continuously rather than assembled in a panic each year.
- MSPs running security awareness across many client environments — see the MSP packaging.
Not a good fit
- Organizations that want a one-time video to tick a box. Hook Security runs a continuous program, and that is the point of it.
- Teams needing deep SIEM-integrated security operations tooling. Hook Security addresses human risk, not detection and response.
- Anyone expecting a guaranteed premium reduction. No vendor can promise that, and your broker is the right person to model the pricing effect.
Cyber insurance and security awareness training
In most cases, yes. Insurers commonly treat documented security awareness training as either a condition of coverage or a factor in pricing, and renewal questionnaires typically ask whether you run training and phishing simulations. Requirements vary by carrier and policy, so read your own questionnaire — but training is now a standard line item rather than an optional extra.
More than a completion certificate. Underwriters increasingly ask for documented phishing simulation results — click rates, reporting rates and remediation timelines — alongside proof that every employee completed training within the policy period. The distinction matters: a certificate says training happened, whereas simulation data shows whether behavior changed.
Incomplete or missing training documentation is a recognized cause of reduced payouts and denied claims, because it can put you in breach of a warranty you signed at binding. This is why the record matters as much as the training. Hook Security keeps a continuous, exportable record so the evidence exists before you need it, not after.
It can influence underwriting, but no vendor can promise a specific premium outcome and you should be sceptical of one that does. What a documented program does reliably is let you answer the questionnaire accurately, avoid a social engineering sublimit applied for lack of controls, and produce evidence at claim time. Your broker is the right person to model the pricing effect.
Most organizations are fully launched within two weeks. Hook Security handles configuration, content selection and campaign design; your involvement is a kickoff conversation and connecting your identity provider. If your renewal is closer than that, say so on the demo and we will tell you honestly whether we can meet the date.
The same program generally serves both. SOC 2, HIPAA, PCI DSS, CMMC, GDPR and ISO 27001 all expect documented security awareness training, and the evidence underwriters want is largely the evidence auditors want. Hook Security integrates with Vanta to supply that evidence automatically, and records export via REST API or CSV for any other platform or auditor request.
Hook Security is $999 per year flat for businesses under 50 seats, or $2 per seat per month, or $20 per seat per year billed annually. Every plan includes the full platform — training, phishing simulations, reporting and integrations. Pricing is published rather than quote-gated.
Get the evidence in place before the questionnaire arrives.
Thirty minutes, a live account, and a straight answer about whether we can meet your renewal date.