Industry case study

How MESA connected employee training to email threat response

An infrastructure engineering company paired recurring phishing practice with a reporting route that helps IT investigate and remove malicious email.

Source publisherKnowBe4
Source publishedPublication date not disclosed
Last checked

Independent Cactera analysis of publicly documented work. Cactera was not involved in this work. Company names identify the subjects, not Cactera clients or partners.

Customer simulation results reported by KnowBe4

52% → 8.6%reported change in simulated phishing susceptibility

Read KnowBe4’s account
Comparison
The 2018 baseline and the reported result five years later
Scope
MESA's employee phishing-awareness program
Timeframe
Five years from 2018; publication date not disclosed
The published work

The problem.

Baseline testing exposed risky email behavior across the corrosion-protection business.

What changed.

Monthly simulations and targeted lessons supported employee reporting. PhishER triaged submissions, with PhishRIP removing confirmed malicious mail from inboxes.

As described by KnowBe4.

Customer simulation results reported by KnowBe4

What was reported.

KnowBe4 reports simulated susceptibility falling from about 52% to 8.6% over five years. Source: KnowBe4

What the evidence can tell us

The comparison measures simulation behavior. Training and response tools were used together; the account does not establish how many breaches training prevented. These are historical program results, not a 2026 deployment.

Cactera analysis

What we take from it.

Security training becomes more useful when it connects to the team's response process. A workshop can rehearse what happens after an employee reports a message: who checks it, how they decide whether it is malicious and what action follows. The employee should understand that sequence without needing to become an email-security specialist.

For a business planning similar work, we would test the handoff with a harmless sample. Follow one report from the employee's inbox through triage, escalation and closure. Confirm that the receiving team can find related messages and that any removal action follows agreed permissions and review rules. Record how to recover a legitimate message if the assessment changes.

Training progress and operational response need separate measures. Use consistent exercises to assess recognition and reporting. Use incident records to examine the time to review a real report, the decisions taken and the affected accounts. Revisit both after a practical exercise. A lower simulation score is useful feedback; a rehearsed response gives the team a concrete action when a real concern arrives.

A proposed method for your business

How to evaluate a similar idea.

Start with your situation and a question you can test. These are evaluation steps we would discuss before choosing an implementation.

  1. 01

    Rehearse one report

    Follow a harmless suspicious-message example from the employee to the person responsible for triage.

  2. 02

    Agree the response

    Define the evidence, permissions and escalation needed before searching for or removing related messages.

  3. 03

    Practice recovery

    Check how the team restores a legitimate message and communicates a corrected assessment.

  4. 04

    Review both kinds of evidence

    Track training behavior separately from the handling and outcome of real incident reports.

Industry case study / Source notes

Sources & credits.

Work credited to
MESA's IT team and employees
Technology / platform
KnowBe4
Analysis & explanation
Cactera. Company wordmarks identify the article subjects.

Independent Cactera analysis of publicly documented work. Cactera was not involved in this work. Company names identify the subjects, not Cactera clients or partners.

A relevant next step

Bring the right question.
Let’s make it specific.

Explore how security awareness training could fit the work you have in mind.

Get a quote