BMO had no enterprise phishing simulation program when I joined the security team in late 2017. The threat environment was changing fast - credential harvesting campaigns targeting Canadian financial institutions were escalating, and OSFI guidance was increasingly explicit about behavioural training expectations.
A blind baseline test in Q1 2018 surfaced the full problem. With no prior conditioning, 31.2% of employees across all business lines clicked the simulation. 11.4% went further and entered credentials. The median time to report a suspicious email was 6 hours and 40 minutes - meaning most phish that made it past filters were sitting live in inboxes for most of a business day before anyone flagged them.
The program I built had to work across four very different internal populations: Retail Banking (customer-facing, high volume, variable tech literacy), Capital Markets (sophisticated, time-pressured), Wealth Management (relationship-focused, high-value targets), and Technology and Operations (technically aware but high-velocity environment). One size would not fit all four.
| Quarter | Click Rate (%) | Report Rate (%) |
|---|---|---|
| Q1 2018 | 31.2 | 8.0 |
| Q2 2018 | 24.1 | 12.0 |
| Q3 2018 | 19.8 | 15.0 |
| Q4 2018 | 16.2 | 19.0 |
| Q1 2019 | 13.0 | 28.0 |
| Q2 2019 | 10.7 | 35.0 |
| Q3 2019 | 9.3 | 41.0 |
| Q4 2019 | 7.8 | 48.0 |
| Q1 2020 | 6.4 | 55.0 |
| Q2 2020 | 5.5 | 61.0 |
| Q3 2020 | 4.8 | 65.0 |
| Q4 2020 | 4.1 | 68.0 |
"Benjamin built a program that actually changed behaviour at scale - not just trained people to pass a quiz. The click rate numbers speak for themselves, but what's harder to quantify is the culture shift. By the end, teams were competing to have the lowest click rate on the board."
Director, Enterprise Information Security - BMO Financial Group