Skip to content
FioSec Consulting

Security Awareness · Case study

From clicking phish to reporting them

A baseline phishing simulation caught an uncomfortable share of staff, and almost nobody reported it. A sustained program of training and simulations turned clickers into reporters, so suspicious emails now reach IT before they reach trouble.

The situation

The organization

An organization that had never tested how its people would handle a convincing phish, with staff whose daily work runs on email.

What prompted it

The first simulated campaign answered a question nobody had wanted to ask. A convincing email drew clicks, and almost no one reported it, which meant a real attack would have run unnoticed for hours. Leadership took the baseline seriously, and rather than treating it as a one-off test, engaged FioSec to build a program: the goal was a culture where reporting is the reflex.

What FioSec did

Each step maps to a layer of the Layered Defence model: vendor-agnostic by design, described by the control it delivers rather than any one product.

  1. A fair baseline, not a gotcha

    The opening simulation was realistic but fair, and the results were used as a measurement, not for blame. It established two numbers that matter: how many people click, and how many report.

  2. Training that respects time

    Short, regular awareness training focused on the lure types staff actually see: invoice fraud, credential harvesting, and impersonation of the people they work for.

  3. Simulations on a rhythm

    Campaigns now run on an ongoing cadence with varied difficulty, and every campaign measures both clicks and reports, so the trend is tracked instead of assumed.

  4. Make reporting easy

    Reporting a suspicious email became a one-click action with feedback to the reporter, so people know their report mattered and keep doing it.

The outcome

Reporting, not clicking, is now the default reaction to a suspicious email.

The organization has a measured baseline and a trend line for phishing susceptibility, so improvement is tracked rather than assumed.

Reported phish now give IT early warning of real campaigns targeting the organization.

Facing something similar?

Tell us where you are today and we’ll help you map the right next step. No obligation.