CASE STUDY · HEALTHCARE
Safety starts with someone speaking up
A healthcare institution wanted to know how well its workforce is prepared for phishing — and wanted to be able to prove it. A report on 18 months of monthly simulations: what the first measurement revealed, why the click rate is the less important number, and how proof is generated without anyone having to scramble to gather it.
The starting point
Measured in the first campaign, without prior notice. Not to catch anyone out, but to have an honest baseline against which progress can later be proven.
Click-through rate in the first campaign. Almost every third person opened the link in an email that looked like a standard course registration - without anyone noticing anything.
Reporting rate. Only a fraction actively reported the attempt to IT. The actually alarming figure: those who do not click, but also do not report, do not protect the organization.
Program staff, from administration and teaching to external lecturers with system access. A group of people that is constantly changing.
Anyone who works with patient data on a daily basis is a rewarding target
Healthcare facilities process data that is worth many times more on the black market than payment data: diagnoses, insurance numbers, and treatment histories. At the same time, operations run under such time pressure that no one is checking email headers.
Added to this is a structure that plays into the hands of attackers. High staff turnover, external service providers with system access, and communication with the outside world through many channels — with payers, referrers, laboratories, and suppliers. An email that looks like one of a hundred routine emails a day goes unnoticed by everyone. That is precisely the problem.
As is so often the case, it was triggered by an external question — asking for proof that did not yet exist in this form. Not because no one had raised awareness, but because no one had documented it. Anyone who schedules a training session at short notice in this situation has a piece of paper, but no indication of whether anything has changed.
The management therefore decided against the obvious solution. Instead of a one-off measure, a program was to be created that runs permanently, whose impact can be measured, and whose evidence is generated without anyone having to scramble to gather it afterwards.
Three conditions that have narrowed the solution space
No in-house security team
IT is designed for operations — keeping systems running, providing support. No one had the capacity to design campaigns, write scenarios, and evaluate results on a monthly basis. A software license for self-configuration would have been left unused after four weeks.
Acceptance was the condition
A simulation that exposes employees would have turned the staff against the program — and would have been over after the second round. In professions where people already work under pressure, shaming is not a method.
Supporting documents had to be provided
It is foreseeable that auditors, payers, or financial auditors will ask for documented awareness training. A program whose documentation has to be gathered retrospectively causes twice the work — and is regularly incomplete.
First measure, then increase, then document
STEP 01
A baseline instead of a gut feeling
At the beginning, there was a single campaign. The workforce was informed in advance that a program was starting and that simulations would be part of it — but not when. The purpose was not to catch anyone, but to get an honest baseline.
Two metrics were measured: the click rate, i.e., how many people reacted to the bait. And the reporting rate, i.e., how many actively reported the attempt. The second number is the more important one, and it is overlooked almost everywhere. An organization where nobody clicks, but nobody reports either, is not secure — it is just silent. Security only arises when anomalies find their way to IT.
Result of the first campaign: click rate 28%, reporting rate 6%.
The value was unpleasant, but not unusual. It corresponded to what we know from facilities without a prior program.
STEP 02
Scenarios from your own inbox
Generic phishing templates fail in the healthcare sector because they do not look like anything that actually arrives there. An alleged parcel service generates no response if no one is expecting packages. The campaigns therefore work with bait from the real inbox: appointment confirmations, invoices from suppliers, messages from payers, diagnostic reports, or alleged alerts from their own IT department.
Anyone who clicks does not land on a scolding page, but on a brief explanation: These were the three characteristics by which this email could be recognized. Anyone who reports it receives positive feedback. This asymmetry is the actual lever. It shifts behavior toward reporting instead of hiding — and it is the reason why the reporting rate can increase at all.
STEP 03
The level of difficulty increases with it
A simulation that still uses the same patterns after six months only measures who has memorized the old examples. Therefore, the requirements were increased starting in month four. Later, patterns that are significantly harder to recognize were added: requests that seemingly came from management and arrived at the end of the month, precisely when everyone is under time pressure. Replies within existing email threads. Sender addresses that differ by only a single character.
The effect is intentional: the click rate rises again in the short term with a more difficult wave. That is precisely why the reporting rate is the more resilient metric — it remains stable once the organization has learned from the experience.
STEP 04
The proof is generated on the fly
Each campaign automatically generates documentation: date, number of participants, aggregated click and reporting rates, maturity level over time, and derived measures. Prepared in a format that management, auditors, and inspectors can work with directly.
The evaluation remains aggregated throughout. There is no list of who clicked — and there never has been one. This is not out of kindness to the workforce. Firstly, it is a prerequisite for the program to run properly on the basis of Art. 6 Para. 1 lit. f GDPR. And secondly, it is a prerequisite for people to report incidents at all. Anyone who fears that a report will be used against them will not report.
What has changed after 18 months
The click-through rate has decreased, and that is the number they ask for in board meetings. The other one is more meaningful.
Click-through rate. The metric demanded by the board of directors — and one that can also be reduced through sheer caution.
Reporting rate. Nearly half of the workforce actively reports a suspicion instead of silently deleting it.
Monthly effort on the client's side. Concept, distribution, analysis, and documentation are handled by us.
"We had expected that such a program would generate resistance. The opposite happened — now colleagues are coming to us on their own with screenshots and asking about it. Being able to simply send a report to the carrier was the side effect we had actually been looking for."
Management of the facility
What of this can be applied to your facility
Every institution is different — in size, regulatory requirements, and system landscape. However, three patterns apply everywhere in healthcare.
No statement without a baseline
If you don't know where you are starting, you won't be able to prove progress later — neither to your own management nor to an auditor. The first campaign is not a measure, but a measurement.
The reporting rate is the more honest metric
Click rates can be reduced in the short term through fear. Reporting rates only increase when people trust that nothing will happen to them. Anyone who only measures the click rate is ultimately measuring the wrong thing.
Evidence belongs in the process
Documentation that is only created at the time of the audit costs many times more — and regularly has gaps exactly where people look.