Adaptive, engaging cybersecurity learning that builds competency over time.
Managed simulations that reveal human risk and build resilience.
Always-on campaigns and content that keep security visible.
Custom films, courses, campaigns, events, and experiences.
Measure the human factors driving risk across your workforce.
Mature, operationalize, and scale your human risk program.
Prepare your workforce for safe, successful AI adoption at scale.
Prepare people, roles, workflows, and governance for AI agents.
See what makes our approach refreshingly different.
Meet the company behind the human risk mission.
Build better human risk solutions and better business together.
Questions, ideas, partnerships, or something else? Start here.
How a Global Manufacturer Turned Security Awareness Data Into Board-Level Risk Intelligence
Financial Services
Midsize — 2,500 employees
CLX — Cyber Learning Experience
Following a security incident, the CISO of a 20,000-employee global manufacturer needed to answer a direct board question: where is the organization exposed, and what is being done about it? The data available at the time could not answer either part.
Fewer than 40% of the global workforce were enrolled in any structured security awareness program. The remaining population — spanning five regions, including operational technology environments and recently acquired entities — had no formal learning in place.
The program that did exist ran on a corporate LMS. Content was generic and undifferentiated by role. Assessment produced pass/fail outcomes and completion rates. There was no mechanism to distinguish between an employee who understood the material and one who had clicked through it. No view of risk by region, function, or role. No signal about where behavior was strong and where it was weak.
The organization was simultaneously managing a digital transformation and an early-stage AI rollout — both of which were introducing new attack surfaces and new categories of human risk the existing program had no way to detect.
"We had data that told us people had completed training. We had no data that told us anything about our actual risk. The board was asking the right questions and I didn't have the right answers."
Chief Information Security Officer, Global Manufacturer
CLX was deployed as the organization's primary learning and risk intelligence layer, replacing the LMS with a role-based, adaptive curriculum built on five competency pillars: threat recognition, data handling, access security, AI-era risk, and reporting behavior.
The initial deployment established a baseline risk profile across the workforce. Three distinct cohort profiles emerged — each requiring a different intervention.
The first showed foundational knowledge deficits: limited working understanding of ransomware vectors and AI-assisted phishing techniques. The second showed adequate knowledge scores but weak behavioral indicators — employees understood policy but were not consistently applying secure behavior in practice. The third showed low responsiveness: a measurable tendency not to report suspicious activity or escalate uncertainty. Contributing factors included unclear reporting channels and insufficient cultural normalization of asking questions.
Each profile received a targeted intervention. Knowledge-gap cohorts received CLX Foundation Series content mapped to current threat patterns. Behavioral-gap cohorts received procedural reinforcement content alongside a leadership cascade, with the CISO driving a consistent "doing things the right way" message through regional management. Low-responsiveness cohorts received structural changes — expanded reporting channels, increased service desk visibility — alongside a sustained cultural message that reporting is expected, not exceptional.
Content was delivered in local languages across all five regions. OT-adjacent teams and AI-transformation cohorts received role-specific content mapped to their actual exposure profiles. CLX's regional and departmental dashboards gave the CISO a single, consistent reporting view across the full organization — segmented by region, function, role, and competency pillar — for the first time.

The program reached 100% of the global workforce within the first program year — up from fewer than 40% — with multilingual delivery across all five regions.
For the first time, the CISO had visibility into human risk by department, role, and competency pillar: which groups had knowledge gaps, which had behavioral gaps, and which were underreporting. High-risk cohorts were identified, prioritized, and targeted with specific interventions rather than general content.
Board reporting moved from a single completion metric to a structured risk dashboard: posture by region and department, competency progression over time, behavioral trends, and a clear view of the remediation program in progress.
“For the first time we could see the real picture — not just who had clicked through a module, but where our actual exposure was and why. That's the conversation the board needed to have.”
Chief Information Security Officer, Global Manufacturer
Security awareness programs that measure activity rather than risk cannot answer the questions boards are now asking. Completion data can show that a program ran. It cannot show which parts of the organization are exposed, whether behavior is changing, or whether the investment is reducing risk. As scrutiny of human risk increases, the gap between activity metrics and risk intelligence becomes a governance issue, not just a program design problem.
One of the most important shifts is separating knowledge gaps from behavioral gaps. An employee who understands policy but does not consistently apply secure behavior does not necessarily need more training. They may need reinforcement, clearer reporting routes, environmental cues, or stronger leadership signals. Treating every problem as a content problem leads to the wrong intervention.
A globally distributed workforce adds another layer. Cultural and linguistic variation affects how people interpret authority, accountability, reporting, and security norms. That makes localization more than a translation exercise. Programs need to account for those differences as part of the risk model itself.
The result is a fundamentally different kind of program: one that moves from reporting training activity to explaining human risk posture — where exposure sits, why it exists, and what should happen next.
A note on client confidentiality
Human risk work can reveal sensitive information about an organization, its people and its security program. We protect that information. The stories on this site are drawn from real Cybermaniacs client engagements, with names and identifying details removed or changed. Where several organizations have faced substantially similar challenges, we may combine those experiences into a representative story while preserving the substance of the problem, our approach and the outcomes achieved.
We take time to understand your needs, explore the Cybermaniacs Experience, and align on business goals to strengthen your cyber culture.
Let's Chat