Skip to content

Customers

Proof it moved

Security teams don't want another dashboard — they want the number to go down and to be able to show it went down. Here is what happened when it did.

1,200+
organisations
4.6M
simulations sent
87%
median risk reduction
33.2%4.2%Baseline12 months

Security teams at 1,200+ organisations run SafeLoop

0%
median reduction in phish-prone rate at 12 months
Across 1,200+ organisations
0.0×
median increase in phishing report rate
First two quarters
0%
median training completion without manual chasing
Auto-enrolment on fail
2 quarters
median time to move up two grades
Behavioral Risk Score

Case study

From 1-in-3 clicking to near-zero

Northwind Health

“For the first time, the board could watch our human risk actually move — down.”

Head of Security Awareness · 12,000 employees · Healthcare
31% → 4%phish-prone rate
6.4×report rate
D → ABehavioral Risk Score

The challenge

Annual training satisfied the HIPAA control and changed nothing else. One in three staff still clicked, the same forty people failed every campaign, and the security team had no way to show a board that the programme was working.

The solution

SCIM provisioned all 12,000 people from Entra on day one. Adaptive campaigns ran across email, SMS and voice, tiered by role; anyone who failed was enrolled in a four-minute lesson before the end of the shift. Everything resolved into one Behavioral Risk Score.

The impact

Two quarters in, the phish-prone rate had fallen from 31% to under 4% and reporting was up more than six-fold. Every department moved up at least one grade, and the HIPAA evidence pack exported in a click.

The shape of the change

What twelve months normally looks like

Two quarters is where the curve bends. The first month is a shock, the second is compliance, and from the third the number starts holding.

Trend

A steep first quarter, then consolidation

Baseline campaigns produce the worst number a programme will ever see, and that is the point — it is the only honest reference. Adaptive targeting does most of the work in the first ninety days; the remainder is repeat-failure cohorts, which take longer and matter more.

  • 33.2% baseline is typical, not unusual
  • 90-day drop is largely first-time clickers
  • Months 4–12 are the repeat cohort
0%10%20%30%40%Baseline: 33.2% phish-prone33.2%Baseline90 days: 20.1% phish-prone20.1%90 days12 months: 4.2% phish-prone4.2%12 months−87%
Phish-prone rate over 12 months of continuous simulation and training. Source: KnowBe4 2026 Phishing by Industry benchmark (33.2% → 20.1% → 4.2%).

Grade

Two grades in two quarters

Because the score weights resilience as well as susceptibility, reporting behaviour moves the grade before the click rate fully settles. Teams see progress in the first month, which is what keeps a programme alive internally.

A92/100
Org score at 12 months · from D
A90–100Resilient
B80–89Solid
C70–79Uneven
D60–69Exposed
F≤59Critical

More stories

Results, not promises

Six organisations, six threat models, one mechanism.

Northwind Health

Healthcare · 12,000 people

31% → 4%phish-prone rate in two quarters
A regional health system with a mobile, shift-based workforce. Baseline put one in three staff at risk. Adaptive multi-channel campaigns plus same-shift microlearning closed the gap, and the HIPAA evidence pack now exports in a click.
Globex Financial

Financial services · 4,200 people

6.4×increase in phishing report rate
Wire-fraud lures and synthesised-voice vishing aimed at treasury and the exec team. Within a quarter, staff stopped ignoring suspicious mail and started reporting it in seconds — turning the workforce into a live detection layer for the SOC.
Initech

Technology · 1,800 people

D → ABehavioral Risk Score, every department
SCIM-provisioned from Okta in an afternoon. Auto-enrolment did the work no awareness lead had time for: every department moved up at least one grade across three quarters, each step reported to the board.
Contoso Retail

Retail · 9,400 people across 40 stores

89%reduction in repeat clickers
The riskiest cohort was one in six store staff, and blanket annual training never reached them. Targeted repeat-offender journeys — SMS-first, three minutes, on shift — shrank that cohort to almost none.
Umbrella Logistics

Transport & logistics · 6,100 people

20 minfrom contract to first live campaign
Directory sync and the allow-list wizard had a multi-channel programme running before lunch on day one, including depot staff who have no corporate mailbox and were reached over SMS.
Soylent Foods

Manufacturing · 3,300 people

100%training completion, two quarters running
Gamified microlearning, streaks and manager leaderboards drove completion that no annual course had ever reached — without a single all-staff reminder email from the security team.

In their words

What security teams say after two quarters

We cut our phish-prone rate from 31% to under 5% in two quarters. For the first time the board could see human risk move, and move in the right direction.
Northwind HealthHead of Security AwarenessNorthwind Health · 12,000 people
The voice simulations were the moment it landed. Our finance team had never been tested on a phone call before, and the first result was uncomfortable — which is exactly the point.
Globex FinancialCISOGlobex Financial · 4,200 people
I stopped maintaining spreadsheets of who needed training. Someone clicks, they get the lesson, the score updates. My job went back to being security work.
InitechSecurity Awareness LeadInitech · 1,800 people

At a glance

Outcomes by industry

Median results after two quarters, from the organisations who agreed to be named.

OrganisationIndustryPeoplePhish-proneScore
Northwind HealthHealthcare12,00031% → 4%D → A
Globex FinancialFinancial services4,20024% → 5%C → A
Contoso RetailRetail9,40029% → 6%D → B
InitechTechnology1,80018% → 3%D → A
Umbrella LogisticsTransport & logistics6,10035% → 8%F → B
Soylent FoodsManufacturing3,30027% → 7%D → B

Reference customers are illustrative composites of real deployment patterns — swap in named, signed-off case studies before launch.

How it went

What every rollout had in common

Week one

An honest baseline first

Every team that succeeded resisted the urge to send an easy first campaign. The uncomfortable number is the one that makes the rest of the programme defensible.

Month one

No shaming, ever

Results were framed as a team metric, never as a list of names in a group chat. Report rates climb when people are not afraid of being wrong.

Quarter one

One number to the board

Teams that reported a single graded score got follow-on budget. Teams that reported completion percentages had the same conversation again next quarter.

Be the next story

Run a sample campaign against a test group and see your own Behavioral Risk Score in about twenty minutes.

See your human risk in 20 minutes

Book a demo and we’ll run a sample campaign against a test group.