Customers
Proof it moved
Security teams don't want another dashboard — they want the number to go down and to be able to show it went down. Here is what happened when it did.
- 1,200+
- organisations
- 4.6M
- simulations sent
- 87%
- median risk reduction
Security teams at 1,200+ organisations run SafeLoop
- Northwind Health
- Contoso Retail
- Globex Financial
- Initech
- Umbrella Logistics
- Soylent Foods
Case study
From 1-in-3 clicking to near-zero
“For the first time, the board could watch our human risk actually move — down.”
The challenge
Annual training satisfied the HIPAA control and changed nothing else. One in three staff still clicked, the same forty people failed every campaign, and the security team had no way to show a board that the programme was working.
The solution
SCIM provisioned all 12,000 people from Entra on day one. Adaptive campaigns ran across email, SMS and voice, tiered by role; anyone who failed was enrolled in a four-minute lesson before the end of the shift. Everything resolved into one Behavioral Risk Score.
The impact
Two quarters in, the phish-prone rate had fallen from 31% to under 4% and reporting was up more than six-fold. Every department moved up at least one grade, and the HIPAA evidence pack exported in a click.
The shape of the change
What twelve months normally looks like
Two quarters is where the curve bends. The first month is a shock, the second is compliance, and from the third the number starts holding.
Trend
A steep first quarter, then consolidation
Baseline campaigns produce the worst number a programme will ever see, and that is the point — it is the only honest reference. Adaptive targeting does most of the work in the first ninety days; the remainder is repeat-failure cohorts, which take longer and matter more.
- 33.2% baseline is typical, not unusual
- 90-day drop is largely first-time clickers
- Months 4–12 are the repeat cohort
Grade
Two grades in two quarters
Because the score weights resilience as well as susceptibility, reporting behaviour moves the grade before the click rate fully settles. Teams see progress in the first month, which is what keeps a programme alive internally.
More stories
Results, not promises
Six organisations, six threat models, one mechanism.
In their words
What security teams say after two quarters
We cut our phish-prone rate from 31% to under 5% in two quarters. For the first time the board could see human risk move, and move in the right direction.
The voice simulations were the moment it landed. Our finance team had never been tested on a phone call before, and the first result was uncomfortable — which is exactly the point.
I stopped maintaining spreadsheets of who needed training. Someone clicks, they get the lesson, the score updates. My job went back to being security work.
At a glance
Outcomes by industry
Median results after two quarters, from the organisations who agreed to be named.
| Organisation | Industry | People | Phish-prone | Score |
|---|---|---|---|---|
| Northwind Health | Healthcare | 12,000 | 31% → 4% | D → A |
| Globex Financial | Financial services | 4,200 | 24% → 5% | C → A |
| Contoso Retail | Retail | 9,400 | 29% → 6% | D → B |
| Initech | Technology | 1,800 | 18% → 3% | D → A |
| Umbrella Logistics | Transport & logistics | 6,100 | 35% → 8% | F → B |
| Soylent Foods | Manufacturing | 3,300 | 27% → 7% | D → B |
Reference customers are illustrative composites of real deployment patterns — swap in named, signed-off case studies before launch.
How it went
What every rollout had in common
An honest baseline first
Every team that succeeded resisted the urge to send an easy first campaign. The uncomfortable number is the one that makes the rest of the programme defensible.
No shaming, ever
Results were framed as a team metric, never as a list of names in a group chat. Report rates climb when people are not afraid of being wrong.
One number to the board
Teams that reported a single graded score got follow-on budget. Teams that reported completion percentages had the same conversation again next quarter.
Be the next story
Run a sample campaign against a test group and see your own Behavioral Risk Score in about twenty minutes.