The problem.
The team's existing awareness program had reached a plateau, with limited reporting and repeated simulation failures.
What changed.
Personalized simulations, short follow-up lessons and multilingual content made practice more relevant to employees.
As described by Hoxhunt.
What was reported.
Hoxhunt reports simulation reports increasing from 1,200 to over 8,000, alongside fewer repeat failures. Source: Hoxhunt
What the evidence can tell us
These are vendor-reported training outcomes. The report count is not a count of attacks stopped, and changing exercise difficulty can affect comparisons. The undated article describes a program with 2025 results.
What we take from it.
A useful exercise teaches the next action as well as the warning sign. Recognizing urgency or an unfamiliar sender is only part of the task. An employee needs to know how to verify a request, preserve the message and contact the right team. We would rehearse that complete sequence with examples from the roles taking part, using fictional company data.
A reporting button needs a working response behind it. Before inviting more reports, agree who receives them, what deserves urgent escalation and how employees hear back. Someone who has already clicked should be able to say so promptly. A calm response keeps attention on containing the issue and collecting the information needed for a decision.
Track whether skills carry into an unfamiliar situation. Keep the audience, exercise difficulty and reporting window visible when comparing results. Review reports per delivered simulation alongside response time and repeat mistakes. Then check real incident records separately. That gives the team a way to improve its training without turning a simulation score into a promise about future security.
How to evaluate a similar idea.
Start with your situation and a question you can test. These are evaluation steps we would discuss before choosing an implementation.
- 01
Choose a familiar decision
Practice a supplier change, document request or access prompt that the participating team actually encounters.
- 02
Teach the complete response
Rehearse independent verification, reporting and what to do after an accidental click.
- 03
Make feedback useful
Explain the missed signal and offer a fresh example, with support in the employee's working language.
- 04
Compare like with like
Record audience size, exercise difficulty and reporting time alongside the training results.
Sources & credits.
- HoxhuntLyondellBasell: Gamified Security Training for Increased Engagement and Reduced Repeat Clickers
Publication date not disclosed · Checked 14 September 2026
- Work credited to
- LyondellBasell's cybersecurity team and employees
- Technology / platform
- Hoxhunt
- Analysis & explanation
- Cactera. Company wordmarks identify the article subjects.
Independent Cactera analysis of publicly documented work. Cactera was not involved in this work. Company names identify the subjects, not Cactera clients or partners.
