Best MDR providers for dental practices compared (2026)
Six MDR options for a dental practice, compared on what each vendor publishes: HIPAA fit, identity coverage, price, term, seat minimum, who responds.
Read articleSecurity Awareness
Six awareness-training options under 100 seats, compared on what each publishes: simulation, managed or self-serve, reporting, price, term, seat minimum.
If you have under a hundred employees, the choice between these six is not really about content quality. Every one of them has a decent library, realistic templates and a one-click report button. The choice is about whether the programme will still be running in month seven, and who writes the report when your insurer asks for completion rates.
Disclosure: the last row is ours. Every other cell comes from that vendor's own website, fetched 29 September 2026 and cited at the end. "Not published" means exactly that — not published — and no per-user figure has been borrowed from a comparison site.
| Provider | Phishing simulation included | Managed or self-serve | Reporting for insurance / compliance evidence | Pricing model | Contract term | Minimum seats |
|---|---|---|---|---|---|---|
| KnowBe4 | Yes — "unlimited phishing security tests" in both SAT Foundation and SAT Advanced | Self-serve. You run the console and the campaigns | Audit log of all administrative actions, described as simplifying compliance reporting | Published: $2.40 (SAT Foundation) or $3.75 (SAT Advanced) per seat/mo (USD) for the 25–50 user band | Published: the listed rate is a 3-year term | Priced in bands from 25–50 users |
| Huntress Managed SAT | Yes — "fully managed learning programs and phishing simulation" | Managed by Huntress | "Automated, detailed reporting". Not framed as insurance evidence | Published: $1.75 per learner/mo at 100 learners; $2.08 at 50 | Published: 12 months standard | 50 per product on direct and reseller purchases; none through an MSP |
| Proofpoint Security Awareness (ZenGuide) | Yes | Self-serve, risk-based and automated inside the console | Not published | Not published | Not published | Not published |
| Phished | Yes — "automated & AI-driven simulations" | Automated, vendor-driven | Reporting plus stated alignment with NIS2, NIST, DORA and ISO 27001. HIPAA not named | Published as a floor: "starting at $175 / month" — no per-user rate | Not published | Not published |
| Hook Security | Yes | Managed — marketed as "training on autopilot" | "Automated, client-ready reporting", and compliance training including HIPAA | Published: $2 per user/mo, $20 per user/yr, or a flat $999/yr under 50 seats. No setup fees | Not published | Not published; the flat plan is scoped to under 50 seats |
| Obsidian Ridge managed SAT | Yes, on the Huntress platform | Managed, with a CISSP owning the programme and the debrief | The evidence pack, packaged for a carrier questionnaire or a HIPAA / ABA / FTC Safeguards file | Published: included in Protected at $32 per user/mo; from $55 per user/mo in Complete. Not sold standalone | Published: annual term, billed monthly | None published |
Of the five outside vendors, three publish a per-seat price. KnowBe4, Hook Security and Huntress do. Proofpoint publishes nothing at all. Phished publishes a $175-a-month floor, which tells a twenty-person company that the effective per-user rate is at least $8.75 and worth asking about directly. If you are comparing outside vendors on per-seat cost, you are comparing three, not five.
KnowBe4's published rate is a three-year commitment. That is the fact most likely to surprise someone who reads the per-seat number and stops. $2.40 per seat per month reads like a simple per-seat number until you notice the term attached to it. A three-year commitment at twenty people is a real decision, not a formality, and the shorter-term rate is not published.
Huntress' fifty-seat minimum bites hardest here. Awareness training is licensed per learner, so a twenty-person company buying Huntress SAT direct pays for fifty learners at $2.08 — $104 a month for twenty people, an effective $5.20 each. Huntress states that purchasing through an MSP carries no Huntress-required minimum seat counts, which is the route that makes the published rate real at small headcounts.
At five hundred people somebody owns security awareness as part of their job. At twenty, nobody does — and a self-serve console is a licence plus an unassigned task.
The failure mode is specific and worth naming, because it is not "the training was bad." It is: the platform gets bought in January, one campaign goes out in February with a good click-rate story, and then the person who set it up gets busy. In October the insurance renewal asks for completion rates over the last twelve months and there is one month of data. The licence was paid for all year.
Self-serve is genuinely cheaper and genuinely gives you more control, and if you have an internal IT person who wants to own it, buy KnowBe4 or Proofpoint and let them. If you do not, buy something that runs itself.
Where a managed provider adds something beyond automation is the part after the report: reading the results, deciding whether the pattern is a training problem or a process problem, and explaining it to the owner in a sentence they can act on. A platform will tell you that 18% clicked. It will not tell you that all of them were in the front office and the lure was a payroll change, and that the fix is a callback rule rather than another module.
Under about ten people, and nobody is enforcing MFA. Enforced multi-factor authentication on Microsoft 365 or Google Workspace, an administrator account separate from daily email, and a written rule that payment-detail changes get verified by phone will block more real attacks than a training platform will. All three are free. Do them, then buy training.
Your carrier has not asked and you have no compliance driver. If nothing on your renewal questionnaire mentions training and you are not under HIPAA, ABA or FTC Safeguards obligations, an annual one-hour walkthrough that you document yourself is a defensible programme at ten people. Write down the date and who attended. That is evidence.
Neither of those stays true for long — training is on most renewal questionnaires now — but paying for a platform before the free controls are on is the wrong order.
Fetched 29 September 2026, from each vendor's own site.
Last updated
September 30, 2026. We refresh this content as the threat landscape and tools evolve.
FAQ
For a company under 100 people the deciding factor is almost never the content library — every vendor here has one — it is whether somebody will actually run the programme.
Self-serve platforms like KnowBe4 and Proofpoint give you a console and expect you to build campaigns, schedule them, chase non-completers and produce the report; if nobody owns that, the licence becomes shelfware.
Managed or automated options — Hook Security, Phished, Huntress Managed SAT, or a managed provider operating one of them — schedule and run it for you.
Of the five outside vendors compared here, three publish a per-seat price you can check without a sales call: KnowBe4 from $2.40 per seat per month on a three-year term, Hook Security at $2 per user per month, and Huntress at $1.75 per learner per month at the 100-learner level.
Phished publishes a $175-a-month floor; Proofpoint publishes nothing.
Some carriers require it, many ask about it, and none of them publish a universal rule — so the only reliable answer comes from your own application.
What carriers typically ask is whether all employees receive training at least annually and whether you run simulated phishing, and increasingly they ask for evidence: completion rates, simulation results, dates.
That last part is where most small companies come unstuck.
Running training and being able to prove you ran it are two different deliverables, and a platform that does not produce an exportable completion report leaves you writing the evidence by hand at renewal.
There is no single range, because each vendor publishes a different kind of number, and the differences are mostly term length, seat floors and who does the work.
KnowBe4 publishes two tiers for the 25-to-50-user band, $2.40 (SAT Foundation) and $3.75 (SAT Advanced) per seat per month, both on a three-year term.
Hook Security publishes $2 per user per month, $20 per user per year, or a flat $999 a year under 50 seats.
Huntress publishes $1.75 per learner per month at 100 learners and $2.08 at 50, with a 50-seat minimum per product and a 12-month term on direct and reseller purchases, so a 20-person company buying direct pays an effective $5.20 each.
Phished publishes a floor of $175 a month rather than a per-user rate, which is at least $8.75 each at 20 people. Proofpoint publishes nothing.
Managed, in almost every case, and the reason is capacity rather than quality.
At twenty people nobody's job description includes running a phishing programme, so a self-serve console tends to get one enthusiastic campaign and then silence — which is worse than nothing at renewal time, because you have a licence and no evidence.
A managed or automated programme keeps sending, keeps recording, and produces the completion and simulation reporting a carrier or an auditor asks for.
The honest exception: if you have an internal IT person who genuinely wants to own it and has the calendar space, self-serve is cheaper and gives you more control over content and timing.
Related reading
Six MDR options for a dental practice, compared on what each vendor publishes: HIPAA fit, identity coverage, price, term, seat minimum, who responds.
Read articleThe 22 controls cyber insurers verify in 2026: what each application question asks, why underwriters care, and the evidence behind a yes.
Read articleA plain-English small-business email security guide focused on the cheap controls that cut business email compromise and phishing risk first.
Read article