Skip to content
CISO Marketplace Services

Managed Security Awareness & Phishing Simulation

Buying an awareness platform is easy; running it well every month is what nobody has time for. We run the whole program on the platform of your choice: monthly phishing simulations written against current lures, targeted training for repeat clickers, new-hire onboarding, and the metrics your auditor and insurer ask for — reviewed by a CISO, not just scheduled by a tool.

In scope

  • Monthly phishing simulations based on current lures
  • Role-based and remedial training assignments
  • New-hire onboarding track
  • Executive and finance-team spear-phishing scenarios
  • Audit- and insurer-ready reporting

You receive

  • Monthly campaign results and trend report
  • Repeat-clicker remediation plan
  • Annual training completion evidence
  • Quarterly human-risk briefing

Tiers

Choose the depth.

Essential Awareness Program

$450 / mo

Up to 50 users: monthly simulations, annual training and compliance reporting

Users
50

Advanced Awareness Program

$1,200 / mo

Up to 250 users: adds role-based training, repeat-clicker coaching and quarterly briefing

Users
250

Enterprise Awareness Program

$2,800 / mo

Up to 1,000 users: adds executive spear-phishing, vishing scenarios, custom content and human-risk scoring

Users
1000

Members: engagement coupons from the CISO Marketplace coupon book apply to services. There is no blanket discount.

What's inside this engagement

Phase by phase.

How a advisory & fractional leadership engagement runs, what happens in each phase and what you see. Exact scope, tier and timeline are fixed in your proposal and SOW.

  1. 01Onboarding & baseline

    Current program, risks, commitments and stakeholders reviewed.

    You see · Access to leadership and existing documents.

  2. 02Priorities & roadmap

    A risk-ranked roadmap agreed with leadership.

    You see · Decisions on priorities and budget.

  3. 03Ongoing cadence

    Regular working sessions, decisions and deliverables to the agreed scope.

    You see · A named advisor and a standing rhythm.

  4. 04Reporting to leadership

    Board and executive reporting in business terms.

    You see · Board-ready updates.

Commercials

From first call to final report.

  1. 01

    Scoping call

    A practitioner, not a salesperson, walks through targets, constraints and what a good outcome looks like for you.

  2. 02

    Proposal & rules of engagement

    A fixed-scope proposal with tier, price and deliverables. Rules of engagement, contacts and out-of-bounds systems are agreed in writing.

  3. 03

    Sign, then start

    MSA and SOW are signed electronically and the deposit is paid. Only then does testing begin.

  4. 04

    Execution

    Testing runs to the agreed plan. Critical findings are escalated as they are found; you don't wait for the report.

  5. 05

    Report & debrief

    An executive summary plus technical findings with evidence, reproduction steps and fixes, walked through with your team.

  6. 06

    Retest

    Where the tier includes it, we verify your fixes and reissue the report, so auditors and customers see the issues closed.

Timelines are set per engagement in the SOW.

Related

Research

Latest from the blog

All posts on cisomarketplace.com →
Talk to an advisor
Advisor