Phishing risk and training, in the same view as everything else.
Corei syncs Hook Security training completions, phishing test results, and per-user risk scores. At-risk users surface in dispatch, customer health, vCISO reporting, and QBR decks — automatically.
- Per-user
- risk scoring
- Live
- phish + training sync
- vCISO
- ready exports
Hook · Cobalt Tooling · User risk
Security awareness, finally usable in operations.
- 01
Connect Hook
Drop in your Hook Security API key. We pull tenants, user lists, training, and phishing campaign history.
- 02
Sync risk signals
Phishing test outcomes, clicks, reports, and training completion stream into Corei continuously.
- 03
Surface at-risk users
High-risk users show up in dispatch, customer health, and on the vCISO dashboard — by department and role.
- 04
Report without copy-paste
QBR decks and vCISO reports auto-build with phish-prone rate, training compliance, and trend over time.
What we pull, and where it lands.
What vCISOs and security-minded MSPs do with it.
Repeat clickers, surfaced
Users who click multiple sim-phish in a quarter get auto-escalated — to the customer's IT lead, vCISO, and the QBR.
Overdue training, nudged automatically
No more chasing. Overdue assignments trigger digest emails to the user, their manager, and the customer admin.
Trend the right number
Phish-prone rate by tenant, department, and role — trended over quarters, ready for the QBR.
vCISO reporting without copy-paste
Monthly vCISO PDF auto-builds with training compliance, phish-prone trend, top at-risk users, and recommended actions.
Risk-weighted onboarding
New hires with low training compliance get flagged before they get production access — surfaced to dispatch.
Department-aware coaching
Finance and exec assistants get prioritized for advanced training when their phish-prone rate trends up.
Ask Corei about security posture.
Corei combines Hook signals with tickets, MFA coverage, and policy data to answer real questions — with sources and recommended next steps.
Example
"Which customers' phish-prone rate trended up this quarter, and who in finance is highest risk?"
3 customers up >5 pts: Cobalt Tooling, Meridian Health, Northwind. In finance, Maya Alvarez (Cobalt) and Tom Reyes (Meridian) are top risk — I queued advanced training and a vCISO talking point for next QBR.
Common questions.
Do users need to install anything?
No. We sync through the Hook Security API. End users keep doing training and sims exactly as they do today.
How is per-user risk calculated?
We use Hook's score as the baseline and optionally blend in Corei signals like overdue tickets and MFA gaps. Fully configurable per tenant.
Can vCISOs export per-customer reports?
Yes — monthly PDF and CSV exports per tenant, with phish-prone trend, training compliance, top risk users, and recommended actions.
Does this work alongside ConnectWise or HubSpot?
Yes. User identities map across PSA, CRM, and Hook so risk scores attach to the right customer contact everywhere.
Where does the data live?
In your Corei tenant. Scoped API access, revocable. We don't store training content — just outcomes and identifiers.
Turn awareness into action.
Bring Hook Security risk into the same view as service, projects, and QBRs.
