ClickCerts
Back to all posts

Your MSP Sells Security. Are You Actually Selling It?

Cyber insurance now requires security awareness training. If your MSP doesn't offer it, you have a gap. Here's how ClickCerts closes it, with margin.

May 14, 2026ClickCerts Team
Your MSP Sells Security. Are You Actually Selling It?

Security awareness training is no longer optional in an MSP’s stack. Here’s why, and what to do about it.

Most MSPs sell themselves as security experts. They put it in the proposal. They put it on the website. They tell prospects, in some form or another, that they’ll keep the client’s business safe.

Then the client gets phished and the lawsuit lands on the MSP’s desk.

This is happening more often than the channel talks about. In 2024, a Sacramento law firm sued its MSP for over $1 million in damages after a Black Basta ransomware attack the firm alleged the MSP failed to prevent. Industry attorneys covering the case said it wasn’t a one-off, and that breach-related lawsuits increasingly include claims against the IT provider. Marketing language about “complete security” or “fully protected” gets pulled from old proposals and used to argue the MSP didn’t deliver what it sold.

There’s a hard truth in here that every MSP needs to look at directly. If you sell security as a service, and 60% of breaches start with human error, and you’re not addressing that 60% in your service offering, you have a gap. The technical stack you sell (EDR, MDR, firewall, backup, MFA, all of it) doesn’t touch the largest single category of breach causes. A trained employee does.

The math your clients are about to do

Cyber liability insurance is changing the conversation faster than anything else. Carriers now require security awareness training as a baseline condition of coverage. The question on the application isn’t “do you have a firewall.” It’s “do your employees receive annual security awareness training and phishing simulations.” If the answer is no, premiums spike or coverage is declined.

Your clients are filling out those applications right now. When they get to the training question, they’re going to look at you. If you don’t have an answer, you’ve just become the reason they can’t get insured at the rate they expected. That’s a conversation no MSP wants to have.

It also means your competitor down the road who does include training is going to win that account. Not because their stack is better, but because their offering covers a question yours doesn’t.

What “doing security training” actually looks like

The mistake most MSPs make is treating training as a side product. Send a link to a third-party platform, hand off the login, hope the client figures it out. The client doesn’t figure it out, the training never gets assigned, and three months later they don’t even remember they bought it.

Real security awareness training, the kind that actually moves the needle on insurance applications and audit findings, looks like this:

  • It’s continuous, not one-time. Quarterly modules at minimum, refreshed annually so the content tracks the current threat landscape.
  • It’s tracked. Admins can see who’s completed what, who’s overdue, who failed a quiz. Reports are available without a data request.
  • It produces evidence. Certificates with serial numbers and expiration dates.
  • A public verification page an auditor can hit to confirm a certificate is real.
  • It’s branded for your business, with your subdomian, its your client, its your name.

The platforms most MSPs offer for this are either bolted-on resells of KnowBe4 (where you’re a thin reseller with no margin and no brand) or generic LMS tools that weren’t built for compliance training and require the client to do all the work themselves. Neither one positions you well.

Where ClickCerts changes the conversation

We built ClickCerts as an MSP-first platform. The whole product is designed around the assumption that you, the MSP, are the prime contractor and the customer relationship belongs to you.

What that means in practice:

  • You get a substancial wholesale discount off retail. You set your own end-customer pricing.
  • The margin between wholesale and what you charge is yours.
  • Your branding goes on the platform. Your logo, your colors, your subdomain. Your customers see your brand, not ours.
  • You manage your customers through a single MSP portal. Add new companies, assign courses, or set it to auto run.
  • You can run portfolio-wide reports across all your customers.
  • You have the ability to pull a CSV of completion rates for every customer at once, without logging into each one separately.
  • Your own internal team gets training too. Up to 50 of your own employees train free. Above that, you pay wholesale for your own seats.
  • We don’t sell to your customers behind your back. Ever. The contract is with you. You bill them. We bill you. If they have a problem, they call you first, and you escalate to us only if it’s a platform issue.

Pricing for your customers, at retail, runs $18 per user per year for small teams down to $12 for larger ones, with four certificate-awarding courses included per user per year. At wholesale, your leaving real margin in the deal.

The choice every MSP is making right now

You can keep selling security without actually selling security awareness training, and hope none of your clients ever fill out a cyber insurance application or get phished. Or you can add a training service to your offering, with your branding on it, with margin built in, and remove a gap that’s increasingly going to define which MSPs win renewals and which lose them.

The clients who are paying attention already know they need this. The ones who aren’t will figure it out the first time their carrier asks the question or their CFO wires money to a fake invoice. Either way, the answer they want from their MSP is “yes, we’ve got that covered.”

Make sure you can say it.

Email sales@clickcerts.com to schedule a call and learn about the ClickCerts MSP reseller program or to talk through wholesale terms for your practice.

Subscribe

Updates that don’t suck.

A short note when we ship something worth knowing about. No spam, no drip campaigns.