Case Studies / Ritchie Bros. / RB Global

Ritchie Bros. / RB Global

Security Operations Lead
Feb 2021 - Dec 2023
Global 40+ Countries 14,000+ Employees 19 Languages
83%
reduction in credential compromise incidents
14,000+Employees reached
40+Countries covered
19Languages localized
83%Fewer incidents
01

The Challenge

Ritchie Bros. (now RB Global) operates heavy-equipment auctions across North America, Europe, Asia-Pacific, and Latin America - with a workforce split between desk-based corporate staff and yard and field workers who have minimal exposure to formal security training. When I took on security operations in early 2021, the data was stark: 47 credential compromise incidents per quarter, nearly all originating from phishing.

The fundamental problem was that the existing awareness program was English-only and built for corporate audiences. The yard and field workforce - representing roughly 40% of total headcount - was completely uncovered. Auction-event temporary workers, who cycle in and out in high volume across peak seasons, had no onboarding security touchpoint at all. These cohorts had the highest click rates in baseline testing and the least remediation history.

MFA was deployed to only 61% of the organization. The remaining 39% were exposed in a way that made successful phishing directly convertible to account compromise with no secondary gate. Hardening MFA coverage was the technical complement to the awareness program.

BASELINE - Q1 2021
47Credential compromises per quarter
61%MFA coverage
1Training language (English only)
0Field/yard worker coverage
02

Approach

PHASE 1 - 2021
Global Baseline and Risk Cohort Identification
Ran regional baseline simulations across NA, EMEA, APAC, and LATAM with templates localized into the dominant languages of each region. Identified yard and field staff and seasonal auction-event temp workers as the highest-risk cohorts - click rates exceeding 50% in some regional segments. Brought findings to the CISO and regional business leads with a prioritized program roadmap.
Regional baselines completed in 4 regions
PHASE 2 - 2021 to 2022
Multilingual Rollout and MFA Hardening
Coordinated localization of the full simulation template library and training content into 19 languages in partnership with regional HR leads and translation vendors. Simultaneously drove an MFA push-coverage initiative: awareness modules specifically addressed push-bombing and MFA-fatigue attacks. By end of 2022, MFA coverage reached 94% and field-worker cohorts had received their first structured phishing simulation. Credential incidents dropped to 14 per quarter.
19 languages deployed  |  MFA coverage: 94%
PHASE 3 - 2022 to 2023
Business-Model-Specific Simulation Design
The most impactful design decision of the program: building simulation templates around RB Global's specific business context. Auction-bidder-verification phish targeted field staff using familiar auction-portal language. Vendor-invoice and equipment-purchase BEC scenarios targeted finance teams in the context of the actual transactions they process. Click rates in these targeted cohorts dropped faster than any general-population campaign had achieved.
Incidents: 8/quarter by Q4 2023
PHASE 4 - 2023
Sustainment and Onboarding Integration
Embedded phishing simulation into the new-hire onboarding track for all regions, including a seasonal-worker onboarding module specifically built for auction-event temps. Quarterly threat-trend bulletins delivered to regional business leads gave local managers visibility into their cohort's risk posture without requiring a security background to interpret. Closed the engagement at 8 credential compromise incidents per quarter - a reduction of 83% from baseline.
New-hire onboarding fully integrated
03

Results

Credential Compromise Incidents per Quarter (2021-2023)
Incidents / Quarter - lower is better
0 14 28 41 55 Q1'21 Q3'21 Q1'22 Q3'22 Q1'23 Q3'23 Q4'23 Incidents / Qtr
View data table
QuarterIncidents
Q1 202147
Q2 202144
Q3 202138
Q4 202133
Q1 202227
Q2 202222
Q3 202218
Q4 202214
Q1 202312
Q2 202310
Q3 20239
Q4 20238
04

Campaign Library

CREDENTIAL HARVEST
Auction Bidder Verification Portal
Yard / Field Staff
52%
BEC / WIRE FRAUD
Equipment Invoice - Vendor Payment
Finance Teams
31%
CREDENTIAL HARVEST
Concur Expense Report Reset
All Staff
24%
MFA FATIGUE
Microsoft Teams MFA Re-enrollment
All Staff
19%
ONBOARDING TARGET
Seasonal Auction-Event Temp Onboarding
Temp Workers
44%
05

Tools and Stack

Proofpoint Security Awareness (PSAT) Okta + MFA Telemetry Microsoft Sentinel Regional Translation Vendors Regional HR Coordination

"The multilingual rollout and the field-worker targeting were exactly what we needed. Most programs ignore our yard staff entirely - they build for office workers and call it done. Benjamin built for the whole organization. That's where the number moved."

Global CISO - RB Global
06

Application to City of Toronto

Multilingual workforce. Toronto is one of the most linguistically diverse major cities in the world. The multilingual localization program built at RB Global - covering 19 languages with region-specific lure design - translates directly to a City workforce where English is not the first language for a significant portion of staff and public-facing roles.
Non-desk and frontline workers. City of Toronto employs transit operators, recreation staff, shelter workers, and maintenance crews who are rarely reached by conventional awareness programs. The field-worker and temp-worker cohort strategy developed at RB Global is the operational model for reaching those populations.
Distributed regional structure. RB Global's four-region model (NA / EMEA / APAC / LATAM) with separate business leads mirrors the City's service-cluster structure. The regional reporting and coordination model - giving local leads visibility without requiring security expertise - is applicable at the division and agency level.
MFA and technical control integration. The awareness program and MFA hardening were designed together as a paired intervention. Behaviour change and technical controls reinforce each other. That integration-first approach is directly relevant to a public-sector environment actively modernizing its identity and access management posture.