Free Phishing Test
FOOD INDUSTRY

From 42% to 5% in 8 Months: Reducing Phishing Click-Through Rates in a Food Company

24-feb-2026 9 minutes read
Industry and scale

Food industry — 650 employees included in the training

Services

Practical Anti-Phishing Training

Results achieved

Phishing click-through rate fell from 42% to 5% within 8 months of starting the partnership

In a food company with several hundred employees, 42% of employees clicked on the simulation during a phishing test. This was a signal of critical risk – more than 4 in 10 people could trigger a chain of events with one click and expose the company to account takeover, data leakage or costly operational downtime.

The organization decided to implement Practical Anti-Phishing Training based on systematic and tailored simulations of cyberattacks which teach how to recognize modern threats in the realities of everyday work.

After 8 months of training, the phishing click-through rate dropped to 5%– the organization not only increased its cybersecurity resilience, but also gained hard data that became the basis for reporting to the management board and supervisory authorities, as well as for planning further educational activities. Most importantly, the organization gained greater control over the risks associated with human error.

Challenge

Almost half of employees could have exposed the organization to a security incident

The organization has not conducted security awareness activities before. There was no recurring program that would build habits, nor data that would show how high the risk was and where exactly it accumulated.

The phishing test made the matter clear. It turned out that a well-prepared message is enough for more than 4 in 10 employees to trigger a chain of events: clicking on a link or attachment, account takeover, access to the mailbox and further escalation in the organization.

In practice, this scenario quickly leads to BEC fraud, data leakage, malware spread and operational downtime. In addition, there are image losses and loss of customer trust – consequences that can follow the company long after the incident.

Key Goal

Reduce the likelihood of an incident through measurable behavior change

The email inbox is a basic work tool, but also the most common entry channel for an attacker. If more than 4 out of 10 people do not recognize that the message is fraudulent, then the risk of an incident is no longer hypothetical and becomes a matter of time.

The priority was to measurably reduce the team’s susceptibility to phishing and to consolidate safe habits so that, under time pressure, the employee would be able to recognize an attempted social engineering attack and not trigger further escalation.
Piotr Kaźmierczak, CEO of SECAWA

Solution

Why didn’t the organization decide on traditional cybersecurity training?

Traditional cybersecurity training most often means providing theoretical knowledge – stationary or online – in isolation from the context in which the threat actually occurs: in an email inbox, under time pressure, in the realities of everyday work. The materials may be too general and not tailored to the specificity of the organization, roles and scenarios that employees may actually encounter.

There are also real operating costs. A few-hour training for 600+ people is a logistical challenge and costs work time, and knowledge retention can be low. Without regular practice, employees quickly revert to old reflexes – and they decide whether someone clicks on a link, opens an attachment or provides data in a false form.

An approach was needed that increases vigilance and consolidates safe habits in the realities of everyday work

Therefore, the organization has implemented Practical Anti-Phishing Training – systematic, realistic simulations of cyberattacks conducted where cybercriminals attack most often: in email inboxes and SMS messages.

Instead of a one-off cybersecurity training, from which knowledge quickly disappears, the organization focused on the rhythm of short experiences. Practical Anti-Phishing Training teaches you to recognize attack patterns the same way you recognize danger on the road while driving – intuitively, before a mistake occurs.

However, when someone makes this mistake, training does not leave him with a feeling of irreversible defeat. After a while, the employee receivesa short micro-training that explains what made the attack work, what to pay attention to next time and how to react safely. This turns a slip into a quick habit correction.

As part of the training, we also implemented a phishing reporting button, so attentive employees could proactively report suspicious messages with a click.

This education model transfers security from theory to practice, strengthening the defense potential of the entire organization.

Results

After 8 months of Practical Anti-Phishing Training the click-through rate dropped to 5%. This is a measurable risk reduction that can be easily proven to the management board, auditors and anyone who asks about the real effectiveness of the security awareness activities undertaken.

Such a large drop in click-through rates, by almost 40 percentage points in 8 months, shows that the improvement was not a temporary mobilization after the campaign, but the result of consolidating safe habits at work.
Piotr Kaźmierczak, CEO of SECAWA

Employees perform their duties with active vigilance. They read more carefully, check the context, detect time pressure and unusual requests before they click. As a result, the cybercriminal has much less opportunity to enter the organization using a crafted message.

A click on a phishing or smishing message has gone from being a likely trigger of an incident to an increasingly rare occurrence.

And the Management Board, CISO and IT have gained something that cannot be achieved by technology alone – peace of mind and confidence that an ordinary email will no longer trigger a crisis.

How did you achieve such effects?

Realistic scenarios tailored to the specificity of the organization

The campaigns included scenarios that used different motivators: time pressure, authority, curiosity, seasonality and urgency. In practice, this allowed us to build vigilance not only against standard phishing, such as the need to change a password, but also against messages that are easiest to smuggle in everyday work.

During the training, campaigns were conducted in five thematic groups:

  • HR, benefits and “rewards” – scenarios based on emotions and social proof: recommendations, distinctions, benefits, surveys and internal communications.
  • Systems and processes – messages impersonating IT systems and processes: alerts, expiring passwords, login verifications.
  • Social media – lures based on image and curiosity: LinkedIn notifications, mentions in publications, comments and interactions.
  • Seasonal and contextual – news that “fits the calendar” and therefore sounds credible: holidays, PIT-11, holidays, new products, current topics.
  • SMS and alerts – simulations of smishing and short alarm messages that require quick clicking and minimal analysis. This is important because modern attacks are rarely single-channel. A well-prepared campaign can pass through inbox, phone and instant messengers – and the employee must recognize the pattern of action, not just the format.

As the results of cyberattack simulations showed, the greatest risk was not hidden in IT alerts, but in messages that were usually part of a normal day at work. It was such scenarios that generated the most mistakes at the beginning of training in this organization.

Why?

These messages fit perfectly into the everyday work context. They looked like ordinary correspondence: the subject “for now”, a request for a quick response, a message related to a process that everyone knows and treats as normal.

In such an environment, it is easy to operate on autopilot – and this is an attacker’s greatest ally.

This is best seen in examples from the HR area: recommendation in recruitment (42%) and reward for a friendly employee (36%). These scenarios worked because they triggered classic social-engineering mechanisms: authority (they sounded formal and organizational), time pressure (they suggested the need to react quickly) and emotions (there was an evaluation, distinction or potential benefit in the background).

In practice, this is exactly the moment when the employee clicks, before he has time to verify the sender, link or intent of the message. And this is often the first step towards an incident.

Would you like to see how your team would respond to phishing—free of charge and with no obligation?

Systematic cybersecurity resilience training instead of one-off security tests

A one-time phishing test can make you aware of a lot, but rarely changes habits. Here, the change came from regular campaigns that returned in different variants and contexts until the safe responses became second nature.

The frequency of the campaigns was 3-4 campaigns per month, or approximately one scenario per week. This is often enough to reinforce alertness and build reflexes, but without overloading employees.

With this consistent cadence, employees stopped treating phishing as something unimportant or “easy to catch.” Instead of assuming that the threat did not affect them, they began to notice how often the attack masquerades as normal, everyday communication – and how easy it is to act rashly in a hurry, which could have disastrous consequences.

In practice, they learned to recognize repetitive social engineering patterns in real news: time pressure, unusual requests, playing on emotions or “urgent” HR and finance topics. And the organization gained what a one-time phishing test or cybersecurity training cannot provide: a trend over time, the ability to compare results between campaigns and measurable proof that the risk of a successful social engineering attack is consistently decreasing.

Risk management based on hard data, not hunches

The results of the Practical Anti-Phishing Training became a risk map that showed not only how big the susceptibility is, but also where exactly it accumulates: in what topics, social engineering methods and – most importantly – in which groups of employees.

This insight into campaign results changes the way you manage security.

As a result, the program did not involve repeating the same templates. Instead, the SECAWA team continuously monitored the course of the training and, based on the collected data, adjusted the subject matter and level of difficulty of subsequent simulations. Where the risk was highest, we ran more targeted campaigns. As resilience increased, we raised the bar, building readiness for more demanding, realistic situations. As a result, the training responded to the actual level of risk in the organization.

The client could measure progress without manually collecting data or tediously creating reports. As part of the Practical Anti-Phishing Trainingwe provide detailed statistics available live on the platform and ready-made reports that can be instantly generated for control or audit purposes – or simply as internal documentation on the effectiveness of security awareness activities.

Summary

42% click-through in the phishing test represented a critical risk that could translate into account takeover, data leakage or costly operational downtime. The implementation of Practical Anti-Phishing Training turned this alarm signal into a structured, measurable behavior change program.

After 8 months, the click-through rate dropped to 5%. This is an impressive decrease of 37 percentage points, which is proof of the organization’s high cybersecurity resilience to phishing.

The program also revealed what influenced employees the most in this organization: scenarios based on HR, benefits and personal topics, as well as reputation and curiosity (recruitment, awards, LinkedIn, PIT-11, leaves, text messages). This information can be used to plan further educational activities.

After completing the program, the organization took the next step: it implemented a reporting button, which lets employees report suspicious messages with one click – without the risk that phishing will go unnoticed and spread further throughout the company.

Each report increases the vigilance of the entire team and builds a culture of proactive response. The company can also recognize attentive employees, reinforcing positive behavior and motivating the team to take an active role in its defense.

Tailored simulations of cyberattacks that shape defense reflexes, measurable training effects and audit-ready reports

Explore more customer success stories

Build a resilient cybersecurity culture with our support

Let's discuss your organization's cyber needs

Fill in the form

Would you like to test the resilience of your systems?

Fill in the form to schedule a free, no-obligation consultation. We will discuss the scope of the penetration tests and prepare a proposed approach tailored to your organization and infrastructure.
Would you prefer to speak to us directly?
+48 732 123 579