GCB
Global Commercial Bank
Financial Services · 8,400 employees · 12 countries
From a 34% click rate to 3.1% in six months
A top-25 global bank faced mounting regulatory pressure after a credential-harvesting campaign compromised 14 internal accounts. They needed measurable, auditable risk reduction fast.
89%
Click rate reduction
100%
Staff completed training
-68%
SOC false positives
The Challenge
A sophisticated spear-phishing campaign impersonating the bank's IT helpdesk compromised 14 employee accounts and triggered a regulatory audit. The CISO needed to demonstrate an ongoing awareness programme within 90 days.
The Solution
- Weekly email simulations targeting high-risk departments.
- Team Chat simulation campaigns mimicking internal IT announcements.
- Automated training enrolment for anyone who clicked.
- Risk score dashboards exported monthly for the board.
Results
- Click rate dropped from 34% to 3.1%.
- 100% training module completion across all 8,400 staff.
- SOC received 68% fewer false positive phishing reports.
- Regulatory audit passed with commendation for programme maturity.