REGIONAL BANK

CASE STUDY

How a Regional Bank Turned a One-Person Awareness Function Into a Mature Phishing Program

1-3

hrm-engage-icon-1
Key Stats

Regional US Bank

Midsize — 2,300 employees

PaaS — Managed Phishing Services

 

The Challenge

What does a phishing program look like when it's designed to help people, not catch them out?

The bank had been running phishing simulations for several years. The program was operational: campaigns went out, results came back, people who clicked were directed to training. On paper, the box was ticked.

In practice, employees had learned to associate phishing tests with being caught out. The templates were generic. The follow-up training was the same regardless of what had triggered the click. Nobody was learning why they'd responded, only that they had. Reporting rates, the metric that most directly reflects a security-aware culture, were low and static.

The awareness lead wasn't short of effort. She was short of expertise, strategic support, and time. Running a 3,000-person phishing program solo, while also managing campaigns, content, and reporting, left little room to step back and ask whether the approach itself was working.


"We were running phishing tests. We weren't running a phishing program. There's a real difference."

 

The Approach

What does a human-centred phishing program look like in practice?

The starting point was a strategic review of what the program was designed to achieve. Cybermaniacs worked alongside the awareness lead to reframe the objective: not catching employees out, but building the confidence and habits that make people harder to deceive.

Simulation design shifted accordingly. Templates were replaced with scenarios built around real social engineering vectors relevant to the bank's operating context — the types of attacks targeting financial services organizations, not generic content. Follow-up interventions were matched to the trigger type involved, so employees received contextually relevant learning rather than a uniform module.

Critically, the framing changed. Simulations were designed to be instructive, not punitive. The employee experience was positioned around awareness and confidence-building. Reporting was actively encouraged and recognized as a positive behavior, not treated as an alternative to failure.

The awareness lead gained dedicated advisory support: hands-on guidance on strategy, scenario design, campaign planning, and program development, effectively extending her capacity without adding headcount.


Midsize Use Case

The Results

How do you shift employees from failing phishing tests to reporting them?

Reporting rates increased materially — the clearest signal that employees had moved from passive targets to active participants. Rather than ignoring suspicious emails or clicking through them, staff were flagging communications, asking questions, and demonstrating the kind of engaged skepticism that reflects genuine behavior change.

The program structure improved in parallel. The awareness lead had a coherent simulation strategy, longitudinal tracking, and a reporting format that demonstrated trend data rather than isolated campaign results. Conversations with leadership shifted from "simulations ran" to "behavior is changing."

The advisory relationship changed the nature of the role. Instead of operating in isolation, the awareness lead had a specialist partner for strategic decisions, scenario design, and program development, effectively multiplying her capacity without additional headcount.

Is Your Phishing Program Pulling Its Weight?

Training should cut risk, not waste time.

Before After

Generic vendor templates

Scenarios built for the bank's specific threat context

Uniform follow-up training for all who clicked

Intervention matched to the trigger type and role context

Low and static reporting rates

Material increase in employee reporting

Awareness lead working in isolation

Dedicated advisory support and strategic partnership

phishing-table-img

What Changed & Why It Matters

Security awareness teams at midsize organizations are routinely asked to do more with less. A single practitioner managing phishing simulations, content, campaigns, and reporting for thousands of employees rarely has the time or specialist depth to optimize every part of the program.

A managed phishing model changes that equation. It brings consistent expert input into scenario design, replaces punitive mechanics with a behavior-first approach, and provides the operational support needed to run a rigorous program without the work falling back onto one person.

The improvement in reporting rates matters beyond the metric itself. When employees report suspicious messages rather than clicking or ignoring them, the organization gains a stronger real-time signal on active social engineering threats. Reporting is one of the clearest indicators that employees are becoming active participants in security.

That kind of behavior cannot be created by a training module alone. It has to be built through a program that treats employees as part of the defense — not as the problem to be caught out.

A note on client confidentiality

Human risk work can reveal sensitive information about an organization, its people and its security program. We protect that information. The stories on this site are drawn from real Cybermaniacs client engagements, with names and identifying details removed or changed. Where several organizations have faced substantially similar challenges, we may combine those experiences into a representative story while preserving the substance of the problem, our approach and the outcomes achieved.

Schedule a Demo

We take time to understand your needs, explore the Cybermaniacs Experience, and align on business goals to strengthen your cyber culture.

Let's Chat