Adaptive, engaging cybersecurity learning that builds competency over time.
Managed simulations that reveal human risk and build resilience.
Always-on campaigns and content that keep security visible.
Custom films, courses, campaigns, events, and experiences.
Measure the human factors driving risk across your workforce.
Mature, operationalize, and scale your human risk program.
Prepare your workforce for safe, successful AI adoption at scale.
Prepare people, roles, workflows, and governance for AI agents.
See what makes our approach refreshingly different.
Meet the company behind the human risk mission.
Build better human risk solutions and better business together.
Questions, ideas, partnerships, or something else? Start here.
How do you manage cyber training compliance for 2,500 employees without it consuming your team?
Financial Services
Midsize — 2,500 employees
CLX — Cyber Learning Experience
For the security team at this US regional bank, compliance wasn't optional. As a regulated financial services organization, 100% completion on mandatory security awareness training wasn't a goal — it was a requirement. The question was never whether to get there. It was how much it would cost them to do it.
The answer, for years, was: a lot.
The bank had been running a well-known security awareness platform. The kind with a large content library, a phishing module, and dashboards full of completion percentages. On paper, a program. In practice, a grind.
Every year followed the same pattern. Training assignments went out. The 60-day compliance window opened. And then the real work started — because somewhere around 40% of employees completed training on time, and the rest had to be individually chased. The security awareness manager spent the next six months at 8 hours a week doing exactly that: emailing, escalating, cajoling, and reporting. Week after week, until the last employee crossed the line.
That's not a program. That's a compliance operation running on human effort alone.
"I wasn't managing a program. I was managing a spreadsheet of people who hadn't done it yet. The platform told me who was behind — it couldn't tell me why, or who actually needed help."
Security Awareness Manager, US Regional Bank
When the bank started evaluating alternatives, the brief was simple: less admin, better engagement, data that means something. What they found with CLX was something more fundamental — a different model of what security awareness training is supposed to do.
Most security awareness platforms are built on a content library and a delivery mechanism. You choose the content, assign it, track who completes it. The platform records the activity. The admin chases the gap. The cycle repeats.
CLX is built differently. The curriculum is structured around five competency pillars — the dimensions of security behavior that actually matter in a financial services environment: from recognizing social engineering to understanding data handling, access management, and the everyday decisions that separate a secure organization from a vulnerable one. Each employee's learning journey is mapped to their role and their starting point. The system determines what gets delivered and when. The admin doesn't choose, assign, or manage the content cadence.
The content itself was a departure from what staff had experienced before. Monthly learning moments of around 10 minutes — short, specific, and built to be genuinely engaging rather than endured. No more hour-long modules blocked out of calendars. Instead, a regular rhythm that fitted around real working days, in a format that didn't feel like a regulatory obligation.
The launch mattered too. Rather than dropping a new platform into the same old cycle, the team sent a deliberate ahead-of-time communication: this is different, here's what to expect, here's why it's worth your time. Skepticism was real — staff had learned to dread annual training, and changing that expectation took intentional effort.
Month one was slow. That was expected. But the employees who logged in first had a different reaction to the training they'd been dreading. They came back. Month on month, completion momentum built — not because someone was chasing it, but because the experience itself had changed.

Within 90 days of launch, 85% of the workforce had completed their first learning cycle — without a single manual chase. By the end of the first program year, sustained completion sat above 90%, consistently, month on month.
For a bank that had previously spent six months chasing a 40% on-time rate, that number represents a structural change — not a one-time effort.
The admin's working week changed too. The 8 hours a week she had spent chasing completions — for up to six months after each assignment window — dropped to 2 hours a month. Not because the job got easier. Because most of it stopped being her job. CLX handled the delivery, the sequencing, and the follow-up. What remained was the work that actually required human judgment.
Those hours went somewhere useful. For the first time, the security awareness manager had capacity to build proper management reports, communicate risk in terms the business understood, and have the conversations with leadership that a strategic program makes possible.
The data changed too. For the first time, the team had visibility into competency across the five pillars — not just who had clicked the module, but who was demonstrating secure behaviors and where the gaps were. Departments with lower competency scores could be targeted with reinforcement content. High-risk roles were identifiable and actionable. The program moved from completion tracking to genuine risk intelligence.
At the next management review, the security team didn't present a completion percentage. They presented a picture of the organization's human risk posture — by department, by role, by behavior — and a plan for where to focus next.
“We went from one number — completion rate — to actually understanding which parts of the business were exposed and why. That changed the conversation completely.”
Security Awareness Manager, US Regional Bank
The shift this bank made wasn't really a platform migration. It was a change in what the program was designed to do.
The previous model treated assignment and completion as the outcome. But completion only proves that someone finished a module. It doesn't show what they understood, whether their behavior changed, or where human risk is increasing or improving.
CLX changed the model from recorded participation to measurable competency development. Learning adapted to the employee and the role. The data started showing something about risk, not just activity. And because the experience itself was better, completion no longer depended on months of manual chasing.
For the bank, that change showed up in three places at once: significantly less administrative effort, better insight for management, and a better experience for 2,500 employees.
Compliance did not become harder to achieve. It became easier because the program was finally designed around how people learn and behave — not simply around proving that training had been assigned.
A note on client confidentiality
Human risk work can reveal sensitive information about an organization, its people and its security program. We protect that information. The stories on this site are drawn from real Cybermaniacs client engagements, with names and identifying details removed or changed. Where several organizations have faced substantially similar challenges, we may combine those experiences into a representative story while preserving the substance of the problem, our approach and the outcomes achieved.
We take time to understand your needs, explore the Cybermaniacs Experience, and align on business goals to strengthen your cyber culture.
Let's Chat