Industry case study

How Ariston connected security training to everyday decisions

A global manufacturer combined role-specific education with a practical way for employees to report suspicious email.

Source publisherProofpoint
Source published31 October 2022
Last checked

Independent Cactera analysis of publicly documented work. Cactera was not involved in this work. Company names identify the subjects, not Cactera clients or partners.

Customer experience reported by Proofpoint

3 yearsof improving phishing-simulation reporting described in the account

Read Proofpoint’s account
Comparison
Reporting across successive simulation campaigns
Scope
Ariston Group employees participating in the program
Timeframe
Three-year trend; exact measurement dates not disclosed
The published work

The problem.

Ariston wanted employees across different roles and languages to recognize threats and participate in the company's defenses.

What changed.

The team introduced tailored training, suspicious-email reporting and several technical email-security controls.

As described by Proofpoint.

Customer experience reported by Proofpoint

What was reported.

Proofpoint describes a rising simulation reporting rate over three years, without publishing the underlying percentages. Source: Proofpoint

What the evidence can tell us

The account combines training and technical controls. It cannot isolate training's effect on attacks. The article was published in 2022 and updated in 2026; the update is not a new deployment date.

Cactera analysis

What we take from it.

A security workshop should end with a decision an employee can make at their desk. We would bring examples from the team's actual work: a changed supplier bank detail, an unexpected file request or a message asking for urgent access. The learner should practice checking the request through an independent channel and know who can help when something remains uncertain.

Reporting needs an owner on the receiving side. We would agree where a report goes, what an employee should include and how the security team acknowledges it. A person who receives useful feedback is better placed to report the next concern. Avoid blaming people for an honest mistake; use it to identify confusing instructions or missing controls.

Measure the behaviors the program is intended to improve. Record reporting quality, response time and whether staff can explain the escalation route. Training completion is useful administration, but a completed lesson alone says little about how a team will handle an unfamiliar request.

A proposed method for your business

How to evaluate a similar idea.

Start with your situation and a question you can test. These are evaluation steps we would discuss before choosing an implementation.

  1. 01

    Choose relevant situations

    Select examples for the actual roles attending the workshop and remove confidential customer details.

  2. 02

    Practice the response

    Have participants rehearse verification, reporting and escalation using the company's approved channels.

  3. 03

    Prepare the receiving team

    Assign someone to acknowledge reports, explain next steps and close the feedback loop.

  4. 04

    Check behavior later

    Follow up with a fresh scenario and review what people can do without help.

Industry case study / Source notes

Sources & credits.

Work credited to
Ariston Group's ICT security team
Technology / platform
Proofpoint
Analysis & explanation
Cactera. Company wordmarks identify the article subjects.

Independent Cactera analysis of publicly documented work. Cactera was not involved in this work. Company names identify the subjects, not Cactera clients or partners.

A relevant next step

Bring the right question.
Let’s make it specific.

Explore how security awareness training could fit the work you have in mind.

Get a quote