The problem.
Ariston wanted employees across different roles and languages to recognize threats and participate in the company's defenses.
What changed.
The team introduced tailored training, suspicious-email reporting and several technical email-security controls.
As described by Proofpoint.
What was reported.
Proofpoint describes a rising simulation reporting rate over three years, without publishing the underlying percentages. Source: Proofpoint
What the evidence can tell us
The account combines training and technical controls. It cannot isolate training's effect on attacks. The article was published in 2022 and updated in 2026; the update is not a new deployment date.
What we take from it.
A security workshop should end with a decision an employee can make at their desk. We would bring examples from the team's actual work: a changed supplier bank detail, an unexpected file request or a message asking for urgent access. The learner should practice checking the request through an independent channel and know who can help when something remains uncertain.
Reporting needs an owner on the receiving side. We would agree where a report goes, what an employee should include and how the security team acknowledges it. A person who receives useful feedback is better placed to report the next concern. Avoid blaming people for an honest mistake; use it to identify confusing instructions or missing controls.
Measure the behaviors the program is intended to improve. Record reporting quality, response time and whether staff can explain the escalation route. Training completion is useful administration, but a completed lesson alone says little about how a team will handle an unfamiliar request.
How to evaluate a similar idea.
Start with your situation and a question you can test. These are evaluation steps we would discuss before choosing an implementation.
- 01
Choose relevant situations
Select examples for the actual roles attending the workshop and remove confidential customer details.
- 02
Practice the response
Have participants rehearse verification, reporting and escalation using the company's approved channels.
- 03
Prepare the receiving team
Assign someone to acknowledge reports, explain next steps and close the feedback loop.
- 04
Check behavior later
Follow up with a fresh scenario and review what people can do without help.
Sources & credits.
- ProofpointGlobal Manufacturer Forges a Stronger Security Culture With Proofpoint
Published 31 October 2022 · Updated 10 March 2026 · Checked 14 September 2026
- Work credited to
- Ariston Group's ICT security team
- Technology / platform
- Proofpoint
- Analysis & explanation
- Cactera. Company wordmarks identify the article subjects.
Independent Cactera analysis of publicly documented work. Cactera was not involved in this work. Company names identify the subjects, not Cactera clients or partners.
