Adaptive, engaging cybersecurity learning that builds competency over time.
Managed simulations that reveal human risk and build resilience.
Always-on campaigns and content that keep security visible.
Custom films, courses, campaigns, events, and experiences.
Measure the human factors driving risk across your workforce.
Mature, operationalize, and scale your human risk program.
Prepare your workforce for safe, successful AI adoption at scale.
Prepare people, roles, workflows, and governance for AI agents.
See what makes our approach refreshingly different.
Meet the company behind the human risk mission.
Build better human risk solutions and better business together.
Questions, ideas, partnerships, or something else? Start here.
How a Major Healthcare Company Shifted to Higher-Value HRM Work by Leveraging Managed Phishing
National Insurance Company
Midsize — 1,200 employees
PaaS — Managed Phishing Services
For this organization's information security team, phishing simulations were one item on a long list. Campaigns went out when capacity allowed — which meant inconsistently. Results were pulled manually and stored in spreadsheets. There was no standard reporting format, no consistent campaign cadence, and no reliable way to track whether the program was producing improvement over time.
The team wasn't doing anything wrong. They were doing too many things at once. Phishing simulation design, deployment, analysis, and reporting is a program in its own right. Running it well requires time and focus the team simply didn't have.
As social engineering attacks grew more sophisticated and regulators placed greater scrutiny on human risk controls, the gap between the program they were running and the program they needed to run became harder to ignore.
"We knew phishing was a priority. We just didn't have the bandwidth to treat it like one."
Cybermaniacs took full ownership of the program — from scenario design to campaign scheduling, deployment, and post-campaign analysis. The security team's role shifted from execution to oversight: reviewing monthly reports, directing strategic decisions, and acting on the insight rather than producing it.
Simulations were designed to reflect current social engineering vectors relevant to the insurance sector, not generic templates recycled from a content library. Campaign cadence was regularized: consistent scheduling replaced opportunistic deployment. Results were tracked longitudinally, so the team could see movement in click rates over time rather than reading each campaign in isolation.
The reporting format was built for the team's context: concise, structured, and ready to share with leadership without additional preparation.

The immediate change was capacity. Time previously spent on campaign logistics was redirected to higher-priority work. They needed to focus on new AI risk assessment, HRM program maturity planning, and board-level reporting on human risk posture.
The HRM program itself improved. Simulation consistency meant results were comparable across cycles. Monthly reports replaced manual spreadsheet analysis. The security team gained a reliable, longitudinal view of click trends and social engineering exposure across departments — something their previous approach couldn't produce.
High-risk click rates reduced measurably over the engagement period. More significantly, the team now had the data infrastructure to track, explain, and act on that change rather than simply report that simulations had run.
| Before | After |
|---|---|
|
Ad hoc simulation scheduling |
Consistent monthly cadence |
|
Manual results analysis in spreadsheets |
Structured monthly program reports |
|
No longitudinal tracking |
Trend data across campaigns and cohorts |
|
Security team managing logistics |
Security team reviewing insight and directing strategy |
Phishing simulation is both a compliance expectation and a genuine risk control. For small and midsize information security teams, it can also become a significant operational burden — one that competes directly with higher-value work such as AI risk management, program maturity, and strategic human risk oversight.
A managed service model resolves that tension by ensuring the program runs consistently, produces reliable insight, and does not require the internal team to own every step of execution. For organizations where one or two people are responsible for the full scope of human risk, that distinction matters.
As the human risk agenda expands and the demands on security teams increase, the ability to delegate well-defined operational work to a specialist partner is increasingly the difference between a program that simply runs and a program that actually improves.
A note on client confidentiality
Human risk work can reveal sensitive information about an organization, its people and its security program. We protect that information. The stories on this site are drawn from real Cybermaniacs client engagements, with names and identifying details removed or changed. Where several organizations have faced substantially similar challenges, we may combine those experiences into a representative story while preserving the substance of the problem, our approach and the outcomes achieved.
We take time to understand your needs, explore the Cybermaniacs Experience, and align on business goals to strengthen your cyber culture.
Let's Chat