CASE STUDIES

Three programs.
Three scales.

Measurable behaviour change across enterprise, global, and SMB environments.

Enterprise
BMO Financial Group
31% to 4.1%
Phishing click rate across 52,000 employees over 34 months. Zero phishing-attributed account compromises in the 12 months following program maturity.
Jan 2018 - Nov 2020
Read case study →
Global
Ritchie Bros. / RB Global
83%
Reduction in credential compromise incidents across 40+ countries, 19 languages, 14,000+ employees. Targeted field-worker and temp-staff cohorts others ignore.
Feb 2021 - Dec 2023
Read case study →
SMB
Rexig Realty Inc.
23% to 6%
Built from zero with no prior program. Zero successful social engineering attacks in 24 months post-launch, including during two active sector-targeted campaigns.
Mar 2023 - Mar 2025
Read case study →

At a glance

Organization Scale Duration Primary Metric Result
BMO Financial Group 52,000 employees 34 months Phishing click rate 31% → 4.1%
Ritchie Bros. / RB Global 14,000+ employees, 40+ countries 34 months Credential compromise incidents/qtr 47 → 8 (83% reduction)
Rexig Realty Inc. 84 staff 24 months Phishing click rate 23% → 6%
Common Methodology
Every program followed the same four-phase framework regardless of scale.
PHASE 01
Baseline
Blind simulation establishes true click rate, credential-entry rate, and report rate. Segment by department, role, and risk tier.
PHASE 02
Targeted Sims
Cadenced simulations with business-relevant lures. Highest-risk cohorts receive more frequent, harder templates.
PHASE 03
Reinforcement
Just-in-time microlearning on click events. Role-based modules tied to the specific threat pattern that caught the user.
PHASE 04
Sustainment
Quarterly cadence, new-hire onboarding, threat-trend bulletins. CISO-level reporting on behaviour change over time.