In the financial industry, one careless click can trigger an avalanche of costly consequences – from the leak of sensitive customer data and violation of regulatory requirements to financial fraud and loss of trust. This risk is even more real because phishing remains one of the main cyber threats in Poland. In 2025, 78,391 phishing incidents were recorded, which constituted 30% of all registered events (read our summary of the annual report on the activities of CERT Polska).
If an organization does not conduct security awareness activities and does not have hard data on the level of susceptibility of its employees, it is difficult for it to effectively reduce the risk of a successful phishing attack and assess whether the actions taken are actually effective. In the financial sector, this is of additional importance because regulations such as DORA (Digital Operational Resilience Act) require not only mandatory awareness programs and training for employees and management staff, but also constant adaptation of protection measures to changing risks.
One of the companies from the financial sector found itself in such a situation and decided to implement Practical SECAWA Anti-phishing Training – based on realistic phishing simulations sent to employees during work and micro-training delivered after an employee makes a mistake.
It took only 3 months to significantly reduce employees’ susceptibility to phishing. Click-through rates for phishing simulations dropped from 39% to 4%, confirming that well-designed training can quickly strengthen an organization’s cyber resilience and give it greater control over one of the key cyber threats in the financial sector.
Challenge
Cyberattacks targeting financial sector employees are becoming more credible, automated and easier to scale. Cybercriminals use effective social engineering techniques, fake websites, messages stylized as well-known services and content distributed through various channels. This means that employees are exposed less often to primitive messages and more often to messages that blend into everyday work.
The stakes are extremely high for a financial organization. One careless click can lead to:
- leakage of sensitive data,
- violations of regulatory requirements,
- unauthorized transfers,
- financial losses,
- loss of customer trust, which has been built for years in this sector.
Such an incident does not end with one employee’s mistake. It quickly becomes an operational, legal and reputational problem that requires crisis actions from the Management Board and may have a real impact on the functioning of the entire organization.
This is why the lack of measurable security awareness activities is such a serious gap in this sector. Without regular training, an organization does not know how employees react to different types of baits, which scenarios are most effective and where the risks are greatest. It is then difficult not only to educate effectively, but also to demonstrate to auditors that the actions taken are adequate to the scale of the threat.
This was the challenge faced by the company in question, which decided to implement phishing simulations as part of the Practical SECAWA Anti-phishing Training. The first campaign already showed the scale of the problem – 39% of employees clicked on the crafted message, which could have exposed the organization to a real security incident. The conclusion was clear: the company needed not a one-off training, but systematic training that would quickly reduce employees’ susceptibility to phishing.
Increasing digital resilience in the financial sector – what to remember in the context of DORA
Solution
To reduce employees’ susceptibility to phishing, the company decided that instead of one-off training, it would focus on systematic training in practice – based on realistic simulations of attacks that hit employees in their everyday work environment and micro-training after a mishap, which was delivered while the experience was still fresh and helped consolidate safe habits.
What phishing simulations have we conducted in a company from the financial industry?
During the Practical Anti-Phishing Training, employees received a variety of scenario-based phishing simulations that used both the professional context and everyday habits of users.
The campaigns included messages regarding data access, social media publications, approval of leave requests, security of Google accounts and critical updates. In the training, we also used less formal baits, such as Christmas wishes in the form of a video or a message related to a trip to Zakopane.
Such a wide range of scenarios made it possible not only to measure the level of vulnerability, but also to check which social-engineering techniques are most effective in a specific organization. As a result, the training was not limited to one attack pattern, but gradually built employees’ vigilance against various forms of phishing.
Results
In just 3 months, click-through rates on phishing simulations have dropped from 39% to 4%. This is a very noticeable change in a short time, especially in an organization that had not previously conducted any security awareness activities.
The first campaigns showed that employees were susceptible to different types of bait and different message contexts. The simulation regarding data access achieved the highest click-through rate – 39%, but messages set in a more everyday and credible context also achieved high results, such as:
- communication on the acceptance of leave applications – 34%,
- Easter wishes in the form of video – 31%,
- notification stylized as a mention of the company on LinkedIn – 23%.
This shows that employees responded both to formal messages related to internal processes and to messages embedded in everyday work realities. The effectiveness of the message was determined not only by the topic itself, but also by its context and credible fit to the recipient’s situation.
In the following weeks, however, the results began to decline significantly. The simulation based on the message about account security achieved only 1.5% click-through rate, the message about a critical update – 6%, and the scenario set in a more private context related to the reservation of an apartment in Zakopane – 4%. This shows that with each successive phishing campaign, employees understood the threat mechanisms better and were less likely to react in a dangerous way.

This result should be read in more detail than just a decline in one indicator. It wasn’t just about lowering click-through rates. The change from 39% to 4% is due to the gradual increase in employee vigilance towards various forms of social engineering and the strengthening of safer habits in everyday work, which actually protect the organization against incidents.
Importantly, this decline did not have to be linear in each subsequent campaign. Even if individual scenarios generated higher click rates, subsequent results remained significantly lower than at the beginning of training. This shows that after each subsequent campaign, employees understood the threat mechanisms better and were less likely to react hastily.
A decrease of as much as 35 percentage points in just 3 months confirms that even in an organization starting without previous security awareness activities, real and measurable improvement can be quickly achieved.
Summary
Why have phishing simulations proven to be an effective tool for increasing cyber resilience in the financial sector?
Practical education tailored to the realities of the organization
Employees did not learn phishing in isolation from their daily work, but in practice – by receiving messages that looked credible and resembled real communication. As a result, the training was not an abstract exercise or another training “to be ticked off”, but a direct test of everyday habits.
A short, contextual piece of knowledge
And if a mistake occurred, the employee was not left with only information about the error and a sense of failure. He immediately receiveda short micro-trainingthat explained why a given message was dangerous, what warning signs he had missed, and how he should react next time. It was this method of practical education that allowed us to consolidate safer behaviors.
Variety of scenarios prepared by the SECAWA team
Phishing campaigns included both official messages related to internal processes and account security, as well as messages set in a more everyday, less formal context. As a result,employees did not practice reacting to one attack pattern, but gradually learned to recognize various social engineering methodsthat they may encounter both at work and in everyday life.
Importantly, the client did not have to create scenarios, plan the campaign schedule or manually submit the results into reports. The entire process was taken over by the SECAWA team – from the preparation and implementation of the campaign to the analysis of effects – and the organization gained ongoing insight into the training progress thanks to clear statistics on the platform and automatically generated reports ready for use by the management board or the compliance department.
If you want to see if Practical Anti-Phishing Training will work in your organization, sign up for Free Phishing Test, during which no costs or obligations:
- You will verify employees’ resistance to phishing.
- You will evaluate the effectiveness of current educational activities.
- You will learn about our original phishing simulation platform.
- We will discuss your individual needs in building cyber resilience.

