Measure Human Risk. Reduce It. Prove It.
We run a repeatable phishing simulation and human-risk program that you deliver to your clients under your own brand: testing, targeted remediation, retesting, and reporting they can hand to an insurer.
Built for MSPs • Recurring service • Executive-ready reporting

Human risk, measured before and after

KnowBe4 gives you a platform. NopTrace gives you a service.
Traditional security-awareness platforms
Software-first. You configure and run the campaigns yourself. Generic reporting, primarily training-focused.
NopTrace
Service first. We run the whole managed program with targeted remediation, before and after measurement, and client-ready evidence, built to become a recurring service you deliver.
Turn human risk into recurring revenue
We handle the operational burden so you can package human-risk testing as a recurring client service. Tell us your client count and we will show you what the margin looks like.
Your client gets more than a phishing report
Campaign results. Human-risk metrics. Department-level analysis. Before/after measurement. Remediation tracking. Executive summary. Close-out documentation.
Documented phishing defense quarterly
Cyber insurance applications ask whether staff are tested on phishing, and most of your clients cannot answer. We run the simulations and produce the documentation, every quarter, without new software.
Initial risk report
A clean record of where employees stand today. Your client hands it to their insurer.

Vulnerability breakdown
We identify the specific people and departments carrying real risk. Not a pass or fail score.

Before and after comparison
Proof the risk is dropping, built to serve as due-diligence evidence for auditors and insurers.

Four stages repeat quarterly
A structured cycle that proves risk is decreasing.
Baseline where employees stand
We test everyone with a realistic simulated phishing email.
Target who carries risk
We identify the specific people and departments that clicked.
Educate the specific gap
We assign training that addresses the exact tactic they missed.
Retest to prove improvement
We run the simulation again and document the before and after.
No software to install
We run simulations through GoPhish, or through Microsoft Attack Simulator when your client already has Defender or E5. We manage the entire cycle.
GoPhish simulation engine
An open-source platform we configure and run for you. No setup on your side.
Microsoft Attack Simulator
When your client already pays for Defender or E5, we use that licence rather than adding another tool to their bill.
Fully done-for-you
We run the simulations, review the results, and prepare the reports.
Built for SMB scale
KnowBe4 and Proofpoint build for enterprise security teams and long sales cycles. NopTrace is scoped and priced for the clients you already manage.
A predictable recurring line item
Bill your clients quarterly as part of your own recurring pricing. Not a one-off project fee.
Right-sized for SMB clients
No enterprise overhead. No long procurement cycles. Just the service your clients need.
Built on enterprise program experience
We have built and run enterprise phishing programs across member firms in more than 20 countries. The same program, sized for the SMB clients you already manage.
Reports your clients can hand over
Every stage produces a concrete deliverable for insurers and auditors.
Nothing to install or manage
We use GoPhish or Microsoft Attack Simulator. Your techs do nothing.
No long-term lock-in
A quarterly service you can start or stop as your clients need it.
See NopTrace in Action
Ready to add human-risk testing to your MSP offering? See how NopTrace works in 20 minutes.
Cyber insurance applications now ask whether staff are tested on phishing
Of breaches involve the human element (error, social engineering, or misuse)
Of organizations have security awareness training as a cyber-insurance coverage prerequisite
Average cost of a phishing-initiated breach
Sources: Verizon 2025 Data Breach Investigations Report; IBM Cost of a Data Breach Report, 2025; Huntress 2025 Cyber Insurance Trends Report.
Evidence executives can actually use
NopTrace turns employee behavior into measurable evidence that can support security reviews, executive reporting, cyber-insurance discussions, compliance conversations, and security-awareness planning.
Controlled by design
Simulations are authorized by the customer and run in a controlled manner. Real credentials are never captured or stored. Campaign data is encrypted in transit and at rest, access is limited to your assigned analyst, and nothing is sold or shared with third parties. Reporting is built around security outcomes, and customer data is handled according to the applicable agreement and our Privacy Policy.
