NopTrace for MSPs

Measure Human Risk. Reduce It. Prove It.

NopTrace gives MSPs a repeatable phishing simulation and human-risk program they can deliver to clients, complete with testing, targeted remediation, retesting, and executive-ready reporting.

Built for MSPs • Recurring service • Executive-ready reporting

Line graph shows risk score dropping from 30% in Q1 2025 to 15% in Q2 2026; bars show click rates by department
Sample results

Human risk, measured before and after

Workforce click rate dropped from 31.2% baseline to 9.6% close-out, a 21.6-point reduction.
Why NopTrace

KnowBe4 gives you a platform. NopTrace gives you a service.

Traditional security-awareness platforms

Software-first. You configure and run the campaigns yourself. Generic reporting, primarily training-focused.

NopTrace

MSP-first and service-oriented. We run a repeatable managed program with targeted remediation, before/after measurement, and executive-ready evidence, built to become a recurring service you deliver.

MSP economics

Turn human risk into recurring revenue

NopTrace handles the operational burden so you can package human-risk testing as a recurring client service. Illustrative example: we'll show you exactly what your margin could look like.

The report

Your client gets more than a phishing report

Campaign results. Human-risk metrics. Department-level analysis. Before/after measurement. Remediation tracking. Executive summary. Close-out documentation.

View the Sample Report
Service

Documented phishing defense monthly

Insurers want proof your clients test their people. We run the simulations and produce the reports they need, every month, without new software.

Deliverable

Initial risk report

A clean record of where employees stand today. Your client hands it to their insurer.

NopTrace baseline report shows 31.2% clicked lure, 12.4% self-reported risk, 1,284 employees tested across six departments.
Deliverable

Vulnerability breakdown

We identify the specific people and departments carrying real risk. Not a pass/fail score.

Chart showing risk score at 31% for Q2 2026 and department click-through rates with Finance highest at 44.9%.
Deliverable

Before and after comparison

Proof the risk is dropping. Auditors accept this as due diligence.

Workforce click rate drops from 31.2% baseline to 9.6% close-out, a 21.6-point reduction.
Cycle

Four stages repeat monthly

A structured cycle that proves risk is decreasing.

Baseline where employees stand

We test everyone with a realistic simulated phishing email.

Target who carries risk

We identify the specific people and departments that failed.

Educate the specific gap

We assign training that addresses the exact vulnerability exposed.

Retest to prove improvement

We run the simulation again and document the before and after.

Delivery

No software to install

We run simulations through GoPhish or Microsoft Attack Simulator when your client has Defender or E5. A security analyst manages the entire cycle.

Tool

GoPhish simulation engine

An open-source platform we configure and run for you. No setup on your side.

Tool

Microsoft Attack Simulator

When your client already has Defender or E5, we use their existing license.

Delivery

Fully done-for-you

A security analyst runs the simulations, reviews the results, and prepares the reports.

Positioning

Built for SMB scale

KnowBe4 and Proofpoint build for enterprise security teams and long sales cycles. NopTrace is scoped and priced for the clients you already manage.

Pricing

A predictable recurring line item

Bill your clients monthly as part of your own recurring pricing. Not a one-off project fee.

Scope

Right-sized for SMB clients

No enterprise overhead. No long procurement cycles. Just the service your clients need.

Credibility

Run by a working analyst

The founder has built and run phishing simulation programs for large global organizations.

Evidence

Reports your clients can hand over

Every stage produces a concrete deliverable for insurers and auditors.

Simplicity

Nothing to install or manage

We use GoPhish or Microsoft Attack Simulator. Your team does nothing.

Commitment

No long-term lock-in

A monthly service you can start or stop as your clients need it.

See NopTrace in Action

Ready to add human-risk testing to your MSP offering? See how NopTrace works in 20 minutes.

Cyber insurers now require proof of phishing awareness testing before they underwrite

60%

Of breaches involve human error, including phishing

81%

Say awareness training is now a coverage prerequisite

$4.8M

Average cost of a phishing-initiated breach

Sources: Verizon 2025 Data Breach Investigations Report; IBM Cost of a Data Breach Report, 2025; Huntress 2025 Cyber Insurance Trends Report.

For your client's leadership

Evidence executives can actually use

NopTrace turns employee behavior into measurable evidence that can support security reviews, executive reporting, cyber-insurance discussions, compliance conversations, and security-awareness planning.

Trust

Controlled by design

Simulations are authorized by the customer and run in a controlled manner. Real credentials are never captured or stored. Reporting is built around security outcomes, and customer data is handled according to the applicable agreement and our Privacy Policy.