Case Studies / BMO Financial Group

BMO Financial Group

Cyber Security Analyst
Jan 2018 - Nov 2020
Enterprise Financial Services 52,000 Employees OSFI Regulated
31% to 4.1%
phishing click rate reduction
52,000Employees reached
34Month engagement
26Simulation campaigns
4.1%Final click rate
01

The Challenge

BMO had no enterprise phishing simulation program when I joined the security team in late 2017. The threat environment was changing fast - credential harvesting campaigns targeting Canadian financial institutions were escalating, and OSFI guidance was increasingly explicit about behavioural training expectations.

A blind baseline test in Q1 2018 surfaced the full problem. With no prior conditioning, 31.2% of employees across all business lines clicked the simulation. 11.4% went further and entered credentials. The median time to report a suspicious email was 6 hours and 40 minutes - meaning most phish that made it past filters were sitting live in inboxes for most of a business day before anyone flagged them.

The program I built had to work across four very different internal populations: Retail Banking (customer-facing, high volume, variable tech literacy), Capital Markets (sophisticated, time-pressured), Wealth Management (relationship-focused, high-value targets), and Technology and Operations (technically aware but high-velocity environment). One size would not fit all four.

BASELINE - Q1 2018
31.2%Click rate (blind test)
11.4%Credential entry rate
6h 40mMedian report time
8%Report-button usage
02

Approach

PHASE 1 - JAN to APR 2018
Baseline Assessment and Segmentation
Conducted a full baseline simulation across all business lines with no prior notification. Segmented results by line of business, seniority band, geographic region, and role type. Presented findings to the CISO with a program design proposal and resource requirements. Procured KnowBe4 after a competitive vendor evaluation.
Vendor selection completed
PHASE 2 - MAY to DEC 2018
Targeted Biweekly Simulations
Launched biweekly campaigns with 12 lure templates spanning credential-harvest, payload-delivery, and business-email-compromise scenarios. Highest-risk cohorts from the baseline received harder, more frequent simulations. Click rate dropped from 31.2% to 18.6% by year end - significant early movement from cadence alone.
Click rate: 18.6% by Dec 2018
PHASE 3 - FULL YEAR 2019
Role-Based Microlearning and Just-in-Time Coaching
Automated simulation-to-training pipeline: click events enrolled users in targeted 3-minute remediation modules within 24 hours. Modules were scoped to the specific threat type that caught the user (credential harvest, wire fraud, IT impersonation). Built four role-specific content tracks (Retail, Capital Markets, Wealth, Tech/Ops). Report rate climbed to 41% as staff began actively flagging real suspicious email.
Click rate: 9.3% by Dec 2019  |  Report rate: 41%
PHASE 4 - FULL YEAR 2020
Human Firewall Gamification
Introduced a team-based leaderboard across 230 internal teams. Teams were scored on report rate and click avoidance, with quarterly recognition for top performers. The competitive framing shifted culture - security awareness moved from a compliance obligation to something teams actively competed on. COVID-19 remote-access lures in Q2 tested new threat vectors; click rate held below 7%. Closed the year at 4.1% click rate, 68% report rate, and median report time of 11 minutes.
Click rate: 4.1%  |  Report rate: 68%  |  Report time: 11 min
03

Results

Phishing Click Rate vs. Report Rate - Quarterly (2018-2020)
Click Rate (%) - lower is better
Report Rate (%) - higher is better
0 19 38 56 75 Q1'18 Q3'18 Q1'19 Q3'19 Q1'20 Q3'20 Q4'20 Rate (%)
View data table
QuarterClick Rate (%)Report Rate (%)
Q1 201831.28.0
Q2 201824.112.0
Q3 201819.815.0
Q4 201816.219.0
Q1 201913.028.0
Q2 201910.735.0
Q3 20199.341.0
Q4 20197.848.0
Q1 20206.455.0
Q2 20205.561.0
Q3 20204.865.0
Q4 20204.168.0
04

Campaign Library

CREDENTIAL HARVEST
Payroll Update Notification
Retail Banking
38%
DOCUMENT DELIVERY
DocuSign Q4 Bonus Statement
All Staff
22%
IT IMPERSONATION
IT Password Expiry - Action Required
Tech & Operations
19%
TOPICAL / COVID-19
Remote Access Verification Portal
All Staff
9%
BEC / CEO FRAUD
CEO Wire Transfer Request
Finance Dept
6%
MFA / ACCOUNT ACCESS
Microsoft Teams Re-enrollment
Capital Markets
5%
05

Tools and Stack

KnowBe4 Microsoft Defender for O365 Power BI Dashboards SOC Report-Button Integration OSFI Compliance Reporting

"Benjamin built a program that actually changed behaviour at scale - not just trained people to pass a quiz. The click rate numbers speak for themselves, but what's harder to quantify is the culture shift. By the end, teams were competing to have the lowest click rate on the board."

Director, Enterprise Information Security - BMO Financial Group
06

Application to City of Toronto

Multi-department complexity. BMO's four business lines mirror City of Toronto's diverse service portfolios (transit, public health, emergency services, corporate functions). The segmentation model - risk-tiering by population, not uniform treatment - is directly transferable to a 50,000+ employee municipal environment.
Regulatory accountability. OSFI-driven reporting discipline maps directly to the City's obligations under Ontario municipal cybersecurity frameworks and public-sector audit requirements. CISO-level quarterly reporting was a core program output, not an afterthought.
Culture change at scale. The Human Firewall gamification model works in large organizations because it converts security awareness from individual compliance to collective identity. That mechanism is equally applicable to a municipal workforce where mandatory training completion is the current ceiling.
Automation and pipeline design. The simulation-to-training automation (click event triggers 24-hour targeted module enrolment) is the operational pattern I would propose for Toronto's awareness infrastructure - scalable, consistent, and measurable without manual intervention per-user.