Industry case study

How CoreDux built stronger phishing reporting habits

A manufacturer made security practice recurring, with short training cycles and a clear route for reporting suspicious messages.

Source publisherKnowBe4
Source publishedPublication date not disclosed
Last checked

Independent Cactera analysis of publicly documented work. Cactera was not involved in this work. Company names identify the subjects, not Cactera clients or partners.

Customer simulation results reported by KnowBe4

About 12% to 5%reported change in simulated phishing susceptibility

Read KnowBe4’s account
Comparison
Initial simulation result versus the reported program average
Scope
Program initially covering about 300 corporate-email users
Timeframe
Measurement dates not disclosed; source checked September 2026
The published work

The problem.

CoreDux needed an awareness program its small IT team could run across employees with different languages and digital experience.

What changed.

Employees received biweekly phishing simulations, quarterly training and extra practice for repeated mistakes, with an email reporting button.

As described by KnowBe4.

Customer simulation results reported by KnowBe4

What was reported.

KnowBe4 reports an average Phish-prone Percentage of 5%, down from about 12%, and approximately 900 suspicious-email reports over six months. Source: KnowBe4

What the evidence can tell us

These are vendor-reported simulation and reporting metrics, not a measured reduction in real breaches. Individual campaigns reached 2%; that is not the reported average. The webpage gives no publication date.

Cactera analysis

What we take from it.

Useful security practice should resemble the decisions a team encounters without turning every message into a trap. We would agree the learning goal before choosing a scenario and explain the reporting route in advance. Any simulation needs an agreed scope, appropriate authorization and a way to support participants who are unsure what happened.

A click count needs context. Message difficulty, language and prior exposure can all change the result. We would keep a consistent baseline and review the quality of reports alongside the raw count. A rise in reports may mean more awareness, while also creating work for the team receiving them. That team needs enough capacity to respond.

Follow-up should teach the missing skill. If someone struggles with a payment-change request, rehearse how to verify it through a trusted contact. A short, specific exercise is more useful than repeating a broad presentation. Managers should see aggregate learning needs and actions without creating a public ranking of individual mistakes.

A proposed method for your business

How to evaluate a similar idea.

Start with your situation and a question you can test. These are evaluation steps we would discuss before choosing an implementation.

  1. 01

    Agree the exercise

    Define the audience, authorization, learning objective and participant support before running a simulation.

  2. 02

    Make reporting easy

    Use a familiar channel and explain which details help the receiving team act.

  3. 03

    Interpret the numbers

    Compare scenarios of similar difficulty and distinguish test behavior from confirmed incidents.

  4. 04

    Rehearse the missing skill

    Offer targeted practice and check whether the employee can apply it to a new example.

Industry case study / Source notes

Sources & credits.

Work credited to
CoreDux's IT team and employees
Technology / platform
KnowBe4
Analysis & explanation
Cactera. Company wordmarks identify the article subjects.

Independent Cactera analysis of publicly documented work. Cactera was not involved in this work. Company names identify the subjects, not Cactera clients or partners.

A relevant next step

Bring the right question.
Let’s make it specific.

Explore how security awareness training could fit the work you have in mind.

Get a quote