Overview
The organization did not previously have a formal security-awareness training program. I introduced a structured program as part of a broader security-policy and NIST SP 800-53 compliance effort, using KnowBe4 to deliver training, manage simulated phishing, and generate program reporting.
The program became more than a compliance exercise. Training helped a finance manager recognize suspicious activity that led to discovery of a real fraud event involving spoofed email approvals and escalating payments. The resulting investigation, payment intervention, and cyber-insurance response prevented a significant financial loss and provided concrete evidence of the business value of security awareness.
Business Context
Security awareness was being formalized as part of the organization’s broader security program. The objective was to move beyond policy language and establish a repeatable process that changed user behavior, produced evidence, and supported NIST SP 800-53 control expectations.
Because social engineering targets business processes as much as technology, the program included both annual online education and realistic simulated-phishing exercises.
Program principle
Awareness training has value only if it changes what people notice and how they act when a real attack reaches them.
My Role
I introduced the formal awareness program and supporting policies, selected and operated the KnowBe4-based training and phishing capability, integrated enrollment with Active Directory, reviewed reporting, communicated results to leadership, and used simulations to demonstrate practical organizational exposure to social engineering.
When the real fraud event was reported, the security function helped validate the suspected fraudulent approval, supported investigation and response, and helped connect the incident outcome back to the value of the awareness program.
Program Design & Operation
Automated Enrollment
- Maintained approximately 500 KnowBe4 licenses.
- Automated user enrollment from Active Directory.
- Integrated required awareness training into onboarding for new employees.
Recurring Training
- Delivered formal online security-awareness training annually.
- Ensured employees joining before the annual cycle received required onboarding training rather than waiting for the next organization-wide event.
- Used the program to support security-policy and NIST SP 800-53 compliance objectives.
Simulated Phishing
- Ran simulated-phishing campaigns twice each year.
- Used realistic scenarios to test whether users noticed sender, context, and trust indicators.
- Generated automated reports in the KnowBe4 platform for program review.
Executive Communication
- Shared program results with leadership.
- Translated simulation outcomes into practical examples of organizational exposure.
- Used real-world and simulated events to reinforce the need for continued awareness investment.
A High-Impact Simulation
One simulated-phishing exercise used a highly plausible organizational scenario: an email claiming that then–Vice President Kamala Harris would visit the building. The message was intentionally sent from a non-AFGE account, leaving a visible clue that recipients could have used to question its authenticity.
The scenario was highly convincing to recipients. Its value was not the novelty of the lure; it demonstrated to leadership how easily an attacker could create a believable message using public context and a simple external email account. The exercise helped make social-engineering risk concrete and increased leadership attention to the awareness recommendations.
Real Fraud Event: Training Becomes a Control
From awareness to action
A finance manager, influenced by the security-awareness training, raised concerns that the organization might have been victimized by fraud. Review showed a pattern of escalating payments: first a few hundred dollars, then several thousand dollars, and finally a transaction exceeding $120,000.
The attacker had used email impersonation to make an approval appear to originate from an internal manager. The first investigative step was to corroborate directly that the manager who appeared to approve the expense had not done so. Once the fraudulent invoice and approval were confirmed, the organization acted to stop payment on the latest major charge and engaged its cyber-insurance resources to address the loss.
Results
Significant loss prevented
Rapid recognition and response allowed the organization to intervene in the largest fraudulent payment and limit the financial impact.
Training demonstrated ROI
The incident provided a direct business example of awareness training influencing employee behavior and helping surface a real attack.
Security culture strengthened
Simulations and the real event reinforced that employees were an active part of the security control environment rather than passive training recipients.
Leadership visibility improved
Concrete examples made social-engineering exposure easier to communicate and helped leadership understand why sustained training and testing mattered.
Executive Takeaway
The program began as part of a broader effort to formalize security controls and meet NIST SP 800-53 expectations, but its value became tangible when training influenced an employee to question suspicious activity and initiate the response to a real fraud event.
The lesson was straightforward: security awareness is not merely an annual compliance requirement. When it is integrated into onboarding, reinforced through realistic testing, measured, and supported by leadership, it can become an operational control with direct financial value.