01
The Challenge
The client had no security awareness training in place, and staff routinely clicked links and opened attachments from unfamiliar senders — a real risk given the business handled customer payment data.
02
The Approach
1
Ran an initial phishing simulation to establish a baseline click-through and credential-entry rate without alarming staff.
2
Built short, role-specific training modules covering the most common attack patterns relevant to the business (invoice fraud, credential phishing, malicious attachments).
3
Ran a second simulation 60 days later to measure improvement and identify staff needing follow-up coaching.
4
Documented a simple incident-reporting process so staff know exactly what to do if they suspect a phishing attempt.
03
The Outcome
Click-through rate on the follow-up simulation dropped substantially compared to the baseline, and the business now has a documented reporting process where previously there was none.