Security Awareness
Campus-wide phishing resilience program
Simulated phishing plus targeted training cut credential-submission rates by more than three quarters across staff and students.
Client
Multi-campus educational institution
Duration
3 months
31% → 7%
Credential submission
4,200+
People trained
3
Campuses covered
The challenge
Repeated phishing incidents were compromising staff email accounts, which were then used to target students and vendors.
What we did
- Baseline phishing simulation across staff and student mailboxes
- Review of mail authentication (SPF, DKIM, DMARC) and account recovery settings
- Interviews with IT staff on reporting and response workflow
Key findings
High
31% of recipients submitted credentials in the baseline simulation.
High
DMARC absent, allowing trivial spoofing of the institutional domain.
Medium
No single reporting channel for suspicious mail.
Remediation
- Role-based awareness sessions delivered across every campus
- SPF, DKIM and enforcing DMARC deployed on the primary domain
- One-click report-phish workflow with a named response owner
