The problem.
Baseline testing exposed risky email behavior across the corrosion-protection business.
What changed.
Monthly simulations and targeted lessons supported employee reporting. PhishER triaged submissions, with PhishRIP removing confirmed malicious mail from inboxes.
As described by KnowBe4.
What was reported.
KnowBe4 reports simulated susceptibility falling from about 52% to 8.6% over five years. Source: KnowBe4
What the evidence can tell us
The comparison measures simulation behavior. Training and response tools were used together; the account does not establish how many breaches training prevented. These are historical program results, not a 2026 deployment.
What we take from it.
Security training becomes more useful when it connects to the team's response process. A workshop can rehearse what happens after an employee reports a message: who checks it, how they decide whether it is malicious and what action follows. The employee should understand that sequence without needing to become an email-security specialist.
For a business planning similar work, we would test the handoff with a harmless sample. Follow one report from the employee's inbox through triage, escalation and closure. Confirm that the receiving team can find related messages and that any removal action follows agreed permissions and review rules. Record how to recover a legitimate message if the assessment changes.
Training progress and operational response need separate measures. Use consistent exercises to assess recognition and reporting. Use incident records to examine the time to review a real report, the decisions taken and the affected accounts. Revisit both after a practical exercise. A lower simulation score is useful feedback; a rehearsed response gives the team a concrete action when a real concern arrives.
How to evaluate a similar idea.
Start with your situation and a question you can test. These are evaluation steps we would discuss before choosing an implementation.
- 01
Rehearse one report
Follow a harmless suspicious-message example from the employee to the person responsible for triage.
- 02
Agree the response
Define the evidence, permissions and escalation needed before searching for or removing related messages.
- 03
Practice recovery
Check how the team restores a legitimate message and communicates a corrected assessment.
- 04
Review both kinds of evidence
Track training behavior separately from the handling and outcome of real incident reports.
Sources & credits.
- KnowBe4MESA Gains IT Capacity and a Stronger Security Culture
Publication date not disclosed · Checked 14 September 2026
- Work credited to
- MESA's IT team and employees
- Technology / platform
- KnowBe4
- Analysis & explanation
- Cactera. Company wordmarks identify the article subjects.
Independent Cactera analysis of publicly documented work. Cactera was not involved in this work. Company names identify the subjects, not Cactera clients or partners.
