Phishing simulations are becoming an increasingly important part of the cybersecurity services offered by MSPs and MSSPs.
For customers, regular phishing tests provide a practical way to measure how employees respond to realistic threats. For MSPs, they can create an additional recurring security service that delivers genuine value to customers while generating another source of revenue.
The challenge is finding a phishing simulation platform that works for the MSP business model.
Traditional security awareness platforms are often designed around large organisations buying annual licences based on the number of users. That can make them unnecessarily expensive or complicated for an MSP that wants to offer phishing simulations across multiple customers.
A better approach is to give MSPs a simple, flexible platform that allows them to run simulations when their customers need them, at a price that works for everyone.
1. Competitive pricing that allows the MSP to make money
The first consideration for an MSP is simple: does the service make commercial sense?
If a phishing simulation platform charges a high annual fee based on every employee across every customer, it can be difficult for an MSP to build an attractive service around it.
Instead, MSPs should look for a pricing model that allows them to control their own margins.
For example, an MSP might offer a customer:
Quarterly phishing simulation — £499 per year
The MSP can then purchase the campaigns required to deliver that service and retain the difference as margin.
This creates a straightforward service that can be packaged alongside other managed security services.
The customer gets regular phishing testing without having to purchase an expensive standalone platform, while the MSP creates an additional revenue stream.
2. No long-term contract
Phishing simulation shouldn’t need to involve a complicated licensing agreement.
For many MSP customers, particularly smaller businesses, flexibility is important. They may want to run a campaign quarterly, twice a year or simply when required.
A pay-as-you-go model gives the MSP the flexibility to match the service to the customer’s requirements rather than forcing every customer into the same annual subscription.
It also makes it easier for an MSP to introduce phishing simulations to an existing customer.
There is no large upfront commitment and no need to predict exactly how many employees or campaigns a customer will need over the next year.
3. Let the customer decide how frequently they are tested
There isn’t necessarily a single frequency that works for every business.
One customer might want:
Quarterly simulations
Another might prefer:
Monthly testing
While a smaller business may initially choose:
Twice-yearly testing
An MSP should therefore be able to offer phishing simulations at whatever frequency makes sense for the individual customer.
The important thing is that phishing simulation becomes an ongoing security activity, rather than something that happens once a year simply to satisfy a compliance requirement.
Over time, repeated simulations can also demonstrate whether employee behaviour is improving.
4. Clean, professional reporting
The simulation itself is only part of the service.
The MSP needs to be able to show the customer what happened.
Reports should clearly communicate:
- Number of employees tested
- Emails delivered
- Emails opened
- Links clicked
- Credentials submitted
- Phishing emails reported
- Overall campaign results
- Results by department or group
- Changes compared with previous campaigns
The report should be understandable to someone who isn’t a cybersecurity specialist.
A business owner shouldn’t have to interpret a complicated security dashboard to understand whether their employees are becoming more resilient to phishing.
For an MSP, professional reporting also makes the service easier to demonstrate during quarterly business reviews and security meetings.
5. Make creating realistic campaigns easy
An MSP shouldn’t need a security-awareness specialist to create every campaign.
The best platforms make it possible to create realistic phishing simulations quickly.
This means providing ready-made templates covering common scenarios such as:
- Microsoft 365 password expiry
- Shared documents
- Invoice notifications
- Delivery notifications
- HR communications
- Payroll
- IT support requests
- MFA notifications
- Security alerts
- Executive impersonation
But pre-built templates are only part of the solution.
6. Give MSPs the freedom to create their own templates
Every customer is different.
A generic phishing email might work for one organisation but be completely inappropriate for another.
MSPs should therefore be able to create their own email templates easily, without needing HTML or development skills.
Being able to customise the sender, subject, message, branding, links and landing page makes it possible to create simulations that closely reflect the threats a particular customer is likely to encounter.
This also gives MSPs the ability to develop their own library of reusable campaigns.
7. Make landing pages easy to replicate
Real phishing attacks often imitate familiar websites.
A simulation platform should make it straightforward to create realistic landing pages without requiring developers to build each one from scratch.
The ability to clone an existing landing page and customise it can dramatically reduce the time required to create a campaign.
An MSP might create a Microsoft 365-style login simulation for one customer and then clone it for another, changing the branding, domain and scenario as required.
This turns campaign creation into a repeatable process rather than a development project.
8. Manage all customers from one place
This is particularly important for MSPs.
An MSP shouldn’t need to maintain a separate phishing simulation account for every customer.
Instead, the platform should provide a centralised environment where the MSP can manage:
Customer A
Customer B
Customer C
Customer D
and all of their campaigns, users, results and reports.
This makes it much easier to scale the service from a handful of customers to dozens or hundreds.
9. White-label the service
If the MSP is selling phishing simulation as part of its own managed security offering, the customer experience should feel like part of the MSP’s service.
White-label functionality allows the MSP to use its own:
- Company name
- Logo
- Branding
- Customer-facing reports
- Portal
The customer sees the MSP delivering the service rather than being presented with another unrelated security vendor.
This strengthens the MSP’s relationship with the customer and makes phishing simulation feel like a natural part of the wider managed security offering.
Turning phishing simulation into a managed service
When these capabilities are combined, phishing simulation becomes much more than a one-off security test.
An MSP can create a simple recurring service:
Step 1 — Select the customer
Choose the customer and the employees to be tested.
Step 2 — Choose or create a campaign
Select an existing template or create a realistic scenario specifically for that customer.
Step 3 — Schedule the simulation
Run the campaign immediately or schedule it for the customer’s preferred frequency.
Step 4 — Measure the results
Track clicks, credential submissions, reports and other relevant metrics.
Step 5 — Provide the customer with a report
Deliver a clear, professional report showing what happened and how the organisation is progressing.
Step 6 — Repeat
Run the next simulation according to the customer’s requirements.
The process can be repeated across every customer in the MSP’s portfolio.
Why this model works for MSPs
The biggest advantage of this approach is flexibility.
The MSP isn’t locked into selling the same package to every customer.
One customer might pay for two simulations per year. Another might want quarterly testing. A higher-risk customer might require monthly simulations.
The MSP can tailor the service accordingly.
At the same time, the MSP can establish its own pricing and margin rather than simply passing the cost of another SaaS licence on to the customer.
This creates a service that is:
Flexible for the customer.
Profitable for the MSP.
Simple to operate.
Easy to demonstrate.
And because phishing threats continue to evolve, there is a natural reason to keep the service running over time.
What should MSPs look for in a phishing simulation platform?
Before choosing a platform, MSPs should consider whether it provides:
| Capability | Why it matters |
|---|---|
| Competitive pricing | Allows the MSP to build a profitable service |
| Pay-as-you-go | Avoids unnecessary long-term commitments |
| No contracts | Makes it easier to introduce the service to customers |
| Multi-customer management | Allows the MSP to scale across its customer base |
| White-labeling | Keeps the customer experience under the MSP’s brand |
| Flexible scheduling | Allows testing at a frequency appropriate for each customer |
| Professional reporting | Makes results easy for customers to understand |
| Custom templates | Allows realistic, customer-specific simulations |
| Template cloning | Speeds up campaign creation |
| Custom landing pages | Enables more realistic simulations |
| Campaign library | Makes recurring campaigns easier to manage |
| Automation | Reduces the ongoing operational workload |
The RapidPhish approach
RapidPhish was built around this model.
Rather than requiring MSPs to commit to expensive per-user licences or long-term contracts, RapidPhish provides a flexible phishing simulation platform that can be used across multiple customers.
MSPs can create and customise campaigns, use existing templates, clone landing pages, schedule simulations and produce clean, professional reports — while choosing how frequently each customer is tested.
The result is a straightforward way for MSPs and MSSPs to add phishing simulation to their existing cybersecurity services without adding unnecessary complexity.
Your customers already trust you with their cybersecurity. Phishing simulation can be another valuable service you provide to them.

