COMPARE2026 buyer's guide · For MSPs 

The best white-label security awareness platforms for MSPs in 2026.

Six platforms, seven dimensions that actually matter to an MSP - white-label depth, seat minimums, multi-tenancy, phishing automation and more. Every claim cited and dated.

How we built this guide (and a disclosure):Cyber Aware makes this list - we build one of these platforms, so read our take on ourselves accordingly. Every claim about another vendor comes from their public website, documentation or review platforms, linked in the sources below with the date we checked it. Where a vendor doesn't publish something, we say so rather than guess.

THE MATRIX

Every platform, side by side.

DimensionCyber AwareuSecureBreach Secure NowHornetsecurityTerranova SecurityCyberHoot
White-label depthFully branded portal, emails, reportsPartialPortal, dashboard, reports and phishing branded to MSP; no custom domain for the admin/training portalPortal resold under MSP brand; emails/certs not itemisedPartialEmail security white-label via partners; training portal not itemisedPartner/child-environment structure confirmed; no branding or custom-domain claim foundPartialLogo, colours and brandable certificates confirmed; custom portal domain and email branding not confirmed
Pricing model & seat minimumsPer-seatNo minimumsPer-seatNo minimums - billed per active userPer-clientUnlimited-employee, per-client pricing; rates not publishedNot publishedBundled into 365 Total Protection tierNot publishedCustom quote-based pricing; no rate or minimum publishedTieredFrom $25/mo (Capterra); MSP tier minimums not confirmed
Multi-tenant client managementTemplate clientsManage every client from one dashboardPartialOne MSP-branded portal for many clients; per-client branding unconfirmedPartial365 Multi-Tenant Manager covers M365 config, not confirmed per-client brandedPartialPartner Licensing API + child environments per Fortra's release notes; self-service branding not confirmedUnlimited clients from one dashboard, ~5-minute setup
Phishing automationAuto Phish - a year from one chatuPhish - automated schedules, adaptive campaignsPartialSimulated Phishing + Catch Phish plugin; cadence not statedSpear Phishing Engine + Employee Security Index benchmarkPartialImmediate remediation (auto-assign on failed sim) + annual Gone Phishing Tournament; Campaign Manager decommissioned May 2026 - ongoing per-client cadence not confirmedAttackPhish - scheduled phishing simulations per client
Gap assessmentsEssential 8 / SMB1001PartialRisk/GAP reporting; no framework-mapped assessment foundPartialHIPAA-aligned risk assessment; not a multi-framework gap toolESI benchmarks phishing performance; not framework-mappedPartialCyber Hero Score and Security Awareness Index risk-profile users; not framework-mappedNo dedicated compliance gap assessment found
Australian frameworks (Essential 8, SMB1001)No mapping found; EU-centric set (GDPR, DORA, NIS2)No mapping found; US-focused, HIPAA-centric vendorNo mapping found; pan-European, M365-centric vendorNo mapping foundNo mapping found
IntegrationsGoogle, Microsoft, Zapier, APIPartialMicrosoft 365, Google Workspace; no Zapier/API/PSA confirmedPartialM365/Google SSO + Teams app; no API/Zapier confirmedPartialDeep M365 integration; API/Google Workspace/Zapier not confirmedPartialSSO/SCIM via Okta, JumpCloud, Azure AD; partner Licensing API; no Zapier/general API/PSA confirmedPartialEntra ID, Google Workspace, SyncroMSP PSA, API (partner-only); no Zapier/ConnectWise confirmed
Last verified July 2026. “—” means the vendor does not publish this information.
VENDOR BY VENDOR

Strengths, trade-offs, best fit.

Cyber Aware

The white-label human-risk platform built for MSPs

Strengths

  • Portal, notification emails, phishing simulations, reports and certificates all carry the MSP's brand - no Cyber Aware branding visible to end clients
  • Per-seat pricing published up front, with no seat minimums
  • Auto Phish generates a full year of varied phishing campaigns from one setup conversation
  • Essential 8 and SMB1001 mapped and evidenced out of the box
  • Google Workspace, Microsoft 365, Zapier and a direct API

Considerations

  • Specialist platform - no bundled email security, backup or wider IT suite to consolidate onto one invoice
  • Newer entrant than several vendors on this list, with fewer third-party review-platform ratings to compare against

Best for: MSPs who want one fully branded human-risk platform - training, phishing and Australian gap assessments - without folding it into a wider suite.

uSecure

White-label human-risk platform, no seat minimums

Strengths

  • Portal, dashboard and reports carry the MSP's brand
  • Per-seat pricing with no minimum licences and no long-term commitments
  • Manage every client from one dashboard, built specifically for growing and enterprise MSPs
  • uPhish runs phishing simulations on automated schedules with adaptive campaigns

Considerations

  • No custom domain for the admin panel or training portal - limited to usecure-controlled domains per uSecure's own help centre
  • Its published compliance framework set (ISO 27001, GDPR, DORA, NIS2, HIPAA, PCI DSS) is EU/UK-centric - no Essential 8 or SMB1001 reference found
  • No dedicated, framework-mapped gap assessment found - reporting centres on risk trends and a customer-cited GAP analysis feature
  • No Zapier, direct API or PSA (ConnectWise/Autotask) integration confirmed in public docs

Best for: MSPs serving EU/UK-regulated clients who want a white-label, per-seat platform with no minimums.

Breach Secure Now

US-centric platform spanning cybersecurity, AI adoption, M365 and HIPAA compliance

Strengths

  • Channel-only model - training and portal resold under the MSP's brand, per partner-marketplace listings
  • Unlimited Clients Subscription plus a per-client Breach Prevention Platform upgrade - a flat per-client rate that can beat per-seat pricing for very large clients
  • Four training pillars: cybersecurity, AI adoption, Microsoft 365 productivity and HIPAA/FWA/OSHA compliance
  • Employee Secure Score benchmarks phishing and training performance over time

Considerations

  • Current pricing isn't published - both tiers route to a demo or partner conversation
  • No Essential 8 or SMB1001 reference found; compliance training centres on HIPAA, FWA and OSHA for the US market
  • Branding on phishing emails and certificates specifically isn't itemised in public docs

Best for: MSPs with large, flat-fee US healthcare clients who want HIPAA-specific compliance training bundled with security awareness.

Hornetsecurity

Security Awareness Service bundled inside 365 Total Protection

Strengths

  • AI-driven Spear Phishing Engine builds scenarios from public company data, paired with the Employee Security Index benchmark
  • 365 Multi-Tenant Manager covers Microsoft 365 tenant configuration for MSPs
  • Serves customers through 12,000-plus MSPs and channel partners globally
  • EU-headquartered, which may suit MSPs whose clients prefer EU-domiciled vendors

Considerations

  • No white-label claim found for the training portal, phishing emails or certificates specifically - only the wider email-security line is described as white-label/co-branded
  • Pricing isn't published on its own - bundled into a 365 Total Protection tier, with a trial request in place of a price list
  • No Essential 8 or SMB1001 reference found
  • Now operates as a dedicated MSP business unit inside Proofpoint following a December 2025 acquisition

Best for: MSPs already standardised on 365 Total Protection for email security and backup who want awareness training bundled into the same suite.

Terranova Security

Enterprise security awareness training under Fortra

Strengths

  • Runs the annual Gone Phishing Tournament - the 2023 event deployed roughly 1.37 million simulated phishing emails across around 300 organisations
  • Training content translated into 40+ languages and built to WCAG 2.2 AA accessibility standards, per Fortra's own materials
  • Cyber Hero Score and the Security Awareness Index (SAI) profile user risk from role, access, knowledge and behavioural metrics
  • Confirmed partner/child-environment account structure and a partner Licensing API; SSO/SCIM integrations with Okta, JumpCloud and Azure AD

Considerations

  • No branding, custom-domain or sender-identity claim found for the partner/child-environment structure in the materials we could access - MSPs should confirm white-label depth directly with Terranova
  • Pricing is custom quote-based; no per-user rate or seat minimum is published across the listings we checked
  • Phishing automation beyond the annual Gone Phishing Tournament is real (immediate remediation auto-assigns training on a failed simulation) but an ongoing, per-client automated cadence is not confirmed - note its separate Campaign Manager orchestration tool was decommissioned in May 2026
  • Cyber Hero Score and SAI are risk-profiling tools, not compliance-framework-mapped gap assessments
  • No Essential 8 or SMB1001 reference found; no Zapier, general-purpose API or named PSA integration confirmed

Best for: Enterprises wanting a benchmarked, Fortra-backed awareness programme with deep multilingual reach, rather than an MSP-resold white-label product.

CyberHoot

Multi-tenant, white-labeled training built for the MSP channel

Strengths

  • "Multi-tenancy white-labeled solution" with brandable certificates and custom logos/colours on communications
  • Complete visibility over unlimited clients from a single dashboard, with new clients set up in around five minutes
  • AttackPhish schedules realistic phishing tests per client; HootPhish offers a genuine positive-reinforcement alternative to attack-style testing
  • Entra ID and Google Workspace sync, a documented SyncroMSP PSA integration, and a no-cost Gradient MSP billing integration

Considerations

  • No dedicated compliance-framework gap assessment found - the homepage references generic compliance progress reports without detail
  • No Essential 8 or SMB1001 reference found
  • Published pricing is inconsistent - a $25/month flat-rate Basic plan is listed on Capterra and a $199/month Autopilot tier on SourceForge, but MSP-specific tier rates and minimums sit behind an email-gated form on CyberHoot's own site
  • No Zapier or ConnectWise integration confirmed in public docs; API access is partner-restricted

Best for: MSPs wanting a low-friction, purpose-built white-label channel tool with fast per-client setup.

HOW TO CHOOSE

What actually matters for an MSP.

🏷

Whose brand does the client see?

Some vendors white-label the portal but stay quiet on phishing emails and certificates - the touchpoints clients actually open. Check every touchpoint, not just the login screen.

💺

What happens at renewal when seats double?

Per-seat, per-client and bundled-suite pricing all behave differently as a client grows. Model your biggest and smallest client on each vendor's structure before you sign anything.

🧭

Can you run 50 clients from one pane?

Multi-tenant management ranges from a genuine template-and-scale dashboard to a reseller program that still routes each deal through a sales conversation. Ask to see the partner console, not the marketing page.

🎣

Does phishing run itself?

Automated, adaptive campaigns save an MSP from hand-building a new simulation every month across every client. Ask what happens after month one, not just what the first campaign looks like.

🇦🇺

Will it evidence the frameworks your clients get audited against?

Several platforms on this list have no public reference to Essential 8 or SMB1001 at all. If your clients are audited against Australian frameworks, confirm mapping and evidence generation before you buy - not after the audit.

📦

What's bundled vs. what's the whole product?

A suite module competes for roadmap attention with everything else in the suite. A dedicated platform has nowhere else to point its engineering time. Neither is automatically better - but know which one you're buying.

QUESTIONS

Frequently asked

What is white-label security awareness training?

White-label security awareness training is a platform an MSP resells under its own brand - the training portal, phishing simulation emails, reports and completion certificates carry the MSP's logo and domain rather than the underlying vendor's. Depth varies a lot between vendors: some brand every touchpoint, others brand the portal but stay quiet on emails and certificates specifically.

How do MSPs make money reselling security awareness training?

Most MSPs mark up a per-seat or per-client wholesale rate and bundle it into a managed-services retainer, so security awareness becomes recurring revenue rather than a one-off project. Per-seat pricing with no minimums (like Cyber Aware and uSecure) makes margin predictable across small and large clients alike; per-client or bundled-suite pricing can work better for MSPs with a few very large, flat-fee accounts.

What should an MSP look for in a phishing simulation platform?

Look for automated scheduling and difficulty scaling so campaigns don't need manual setup every month across every client, varied templates that avoid staleness, and clear reporting an MSP can hand to a client without extra work. Several platforms in this guide automate scheduling to different degrees - confirm cadence and template variety before committing.

Do these platforms support Essential 8 and SMB1001 for Australian businesses?

As of July 2026, Cyber Aware is the only platform in this guide with a confirmed public mapping to both Essential 8 and SMB1001. We found no public reference to either framework in the materials published by uSecure, Breach Secure Now, Hornetsecurity, Terranova Security or CyberHoot - MSPs serving Australian clients against these frameworks should confirm current support directly with each vendor.

What's the difference between per-seat and per-client pricing?

Per-seat pricing charges by the number of end users enrolled, so cost scales directly with headcount. Per-client pricing (used by Breach Secure Now) charges a flat rate per client organisation regardless of employee count, which can favour MSPs with a few very large clients but cost more for many small ones. Some vendors, including Hornetsecurity and Terranova Security, don't publish pricing at all.

Is it fair for Cyber Aware to rank itself in this comparison?

We think so, with a disclosure: Cyber Aware built this guide and appears in it. Every claim about another vendor is sourced to that vendor's own public materials, documentation or a review platform, linked below with the date we checked it - the same standard we'd want applied to a claim about us.

Sources

See it live

Same platform.
Your brand.

Spin up a fully branded portal and judge for yourself - live, before you finish your coffee.