Managed phishing testing

Managed Phishing Testing for Small & Midsize Businesses

We set up and run realistic phishing simulations, provide short follow-up training, and document the results—so your business can test staff readiness without managing another security platform.

From $395 for up to 10 participants. Standard setup included. No Security Baseline required.

What SYB handles

We manage the campaign, not just the email list.

We set up and administer the phishing campaign, coordinate the scenarios, and provide a short follow-up training assignment so the business can review what happened without managing another platform.

Service scope

  • Initial scoping and any insurer-provided requirements
  • Campaign authorization and recipient scope
  • Standard setup and delivery testing
  • Scenario selection and scheduling
  • Campaign administration
  • Short follow-up training and completion reminders
  • Reporting and a plain-English readout

Important boundary

Setup may require assistance or limited authorized access from the email administrator. We do not promise a no-access setup, and we do not collect or retain actual passwords.

Who this is for

Practical testing for teams that need a managed campaign.

This is designed for businesses that need someone to run the process, without building a security program from scratch.

Owners and office managers who need someone to run a campaign

Businesses without an internal security team

Businesses with an MSP that need a separately managed testing engagement

Organizations gathering testing and training documentation for an insurer or customer

Larger teams that need a scoped program

Realistic business scenarios

Examples are controlled and illustrative.

These are emails designed to test judgment in common business workflows. They are not an assessment of real customer incidents.

Unexpected shared document or account notification

A realistic message can test whether employees pause to verify a request before they click or reply.

Supplier invoice or remittance-change request

This type of business scenario is common in accounting, operations, and procurement workflows.

Payroll or administrative request

Organizations often need to confirm whether staff recognize suspicious requests that appear to come from a familiar internal process.

Dispatch, load-document, or carrier-portal notification

For trucking and logistics teams, email scenarios often mimic carrier, driver, or dispatch correspondence.

Phone calls, in-person impersonation, and highly customized executive scenarios are outside the standard email campaign and require separate scoping.

Pricing

Simple pricing for practical staff awareness testing.

Participants are individual people enrolled in the campaign, not total company headcount. Shared mailboxes, contractors, and employees without individual work email accounts are addressed during scoping.

ParticipantsOne-time campaignAnnual program
1–10$395$995/year
11–25$595$1,495/year
26–50$895$2,495/year
More than 50Scoped quoteScoped quote

One-time campaign includes

  • One selected email scenario
  • Standard setup and delivery testing
  • Short follow-up training with completion tracking
  • Dated campaign and training report
  • 20-minute owner or manager readout

Annual program includes

  • Four campaigns over 12 months
  • Four short training assignments
  • Completion reminders
  • Campaign reports
  • Annual summary and readout

Scope

  • USD pricing
  • Standard setup and platform costs included
  • One business domain and one email environment
  • Final scope confirmed before work
  • Additional environments, unusual delivery requirements, and bespoke exercises quoted separately
  • Annual prices are annual totals
  • Quarterly campaigns are the standard annual schedule
  • Different frequencies require a tailored scope

What the business receives

Clear reporting and practical follow-up.

The service is designed to answer what happened, which staff engaged with the scenario, and what needs attention next.

  • Dates and campaign scope
  • Intended participants and available delivery results
  • Observed interactions
  • Reporting behavior where measurable
  • Training assignments and completion
  • Limitations and practical follow-up

Simulation difficulty and automated email-security activity affect interpretation. A click rate is not proof of overall business security.

Insurance documentation

Use the exact language from the insurer or broker.

“If your insurer has requested phishing testing or security awareness training, share the exact wording with us. We will scope the engagement around the stated requirement and provide dated records of the work completed. Your insurer or broker confirms whether those records satisfy its requirements.”

Distinguish testing, training, frequency, participant coverage, and completion evidence. We do not promise insurance approval, renewal, coverage, claim payment, or premium reductions.

How it works

A simple process with useful output.

  1. Confirm needs and participant scope

    We confirm the purpose, the participants, and the business context for the campaign.

  2. Authorize and prepare

    We confirm the email environment, any required access, and final campaign timing.

  3. Run the campaign and follow-up training

    We deliver the simulation, track engagement, and assign concise follow-up training.

  4. Review results and receive documentation

    Leadership receives a short readout, campaign results, and supporting records as published.

FAQs

Plain answers for the decision-makers.

How much does managed phishing testing cost?

The launch pricing is $395 for up to 10 participants in a one-time campaign, $595 for 11–25 participants, and $895 for 26–50 participants. Annual programs are priced at $995, $1,495, and $2,495 respectively. Larger programs receive a scoped quote.

Can we buy one campaign?

Yes. One-time campaigns include one selected email scenario, standard setup, short follow-up training, a dated report, and a short manager readout.

Do we need a Security Baseline first?

No. Managed phishing testing is a standalone service. It is available without the Security Baseline and can be scoped independently for your business.

Can you work with our MSP?

Yes. We can coordinate with your MSP or provider when an authorized email environment or support contact is needed for setup.

Can a larger business enroll a smaller team?

Yes. The campaign can be scoped to the enrolled participants in a given test, but the participants are still counted individually. Testing only some employees does not establish whole-workforce training completion.

How are shared mailboxes and employees without email handled?

Shared mailboxes, contractors, and people without individual work email accounts are addressed during scoping. The campaign scope should reflect the specific participants in the test.

Does this meet our insurance requirement?

If your insurer has requested phishing testing or security awareness training, share the exact wording with us. We can scope the engagement around the stated requirement and provide dated records of the work completed. Your insurer or broker confirms whether those records satisfy its requirements.

Do you collect real passwords?

No. Actual passwords are not collected or retained as part of the campaign. We focus on the business interaction and the training follow-up, not credential capture.

Does the annual program include monthly tests?

The standard annual program includes four campaigns over 12 months, with four short training assignments and completion reminders. Quarterly campaigns are the standard annual schedule.

Are phone and in-person exercises included?

Phone calls, in-person impersonation, and highly customized executive scenarios are outside the standard email campaign and require separate scoping.

Let us handle your next phishing campaign.