Harrogate accountancy practice cuts phishing click rate from 31% to 4%
A 34-staff Harrogate accountancy practice reduced its simulated phishing click rate from 31% to 4% in six months, with credential entry falling from 12% to 0% and 62% of staff now reporting suspicious email.
After a near-miss invoice fraud attempt during self-assessment season, the partners wanted evidence that staff could recognise a convincing phishing email — and a way to prove that improvement to their professional indemnity insurer.
Client: 34-staff accountancy practice. Name withheld under our confidentiality terms.
At a glance
- Client
- 34-staff accountancy practice
- Sector
- Professional Services
- Location
- Harrogate, North Yorkshire
- Size
- 34 employees, 1 office
- Services
- Phishing Simulation, Cyber Awareness Training, Email Security
- Timeline
- 6 months, ongoing
- Headline result
- 31% → 4% — Phishing click rate over six months
Measured results
- Phishing click rate over six months
- 31% → 4%Phishing click rate over six months
- Credential entry in the latest campaign
- 0%Credential entry in the latest campaign
- Of staff now report suspicious email proactively
- 62%Of staff now report suspicious email proactively
- Monthly training completion rate
- 96%Monthly training completion rate
The challenge
- A spoofed supplier email nearly resulted in a five-figure payment to a fraudulent account.
- Annual classroom-style training was completed but had no measurable effect on behaviour.
- No baseline data on how staff actually responded to phishing attempts.
- The PI insurer had begun asking for evidence of ongoing staff training at renewal.
What we did
- 1
Ran a baseline simulated phishing campaign with no prior warning to establish a true click rate: 31% clicked, 12% entered credentials.
- 2
Enrolled all staff in 3–5 minute monthly awareness modules with automated reminders and completion tracking.
- 3
Delivered in-the-moment micro-training to anyone who clicked a simulation, rather than a punitive report to management.
- 4
Layered AI email security in front of Microsoft 365 to catch spoofing and Business Email Compromise attempts.
- 5
Introduced a one-click reporting button so staff could flag suspicious mail to IT.
- 6
Reported quarterly to the partners with click rate, report rate and department-level trends.
The outcome
- Documented training and simulation evidence supplied at PI insurance renewal.
- Finance team now verifies bank detail changes by callback as standard procedure.
- Suspicious emails reach IT in minutes rather than being deleted silently.
- Training runs without partner time: enrolment, reminders and reporting are automated.
“We thought we were fine because everyone had done the annual training. The first simulation told us otherwise, and that was uncomfortable but useful.”
The concepts behind this engagement
Plain-English reference pages explaining the certifications, threats and controls involved in this piece of work.
Where this fits in what Complete Cyber Security does
FAQ
Questions about this engagement
The questions businesses in a similar position ask most often before starting.
Is a 31% baseline click rate unusually high for a professional firm?
+
No. Unannounced first campaigns in UK SMEs commonly land between 20% and 35%, and professional services firms are not immune — often the opposite, because staff handle a high volume of legitimate external email under time pressure. The number matters less than the trajectory. A baseline captured before any training tells you where you actually are, and each subsequent campaign shows whether behaviour is changing. What we look for after six months is a click rate in single figures, near-zero credential entry, and a rising report rate, which is the strongest signal that staff have moved from passive to active.
Does phishing simulation damage trust between staff and management?
+
It does when results are used punitively, so the programme is designed to avoid that. Anyone who clicks sees a short, non-judgemental training page immediately rather than a message to their manager, and reporting to leadership is aggregated by department rather than named individually. Staff are told at the outset that simulations will run and why. In this engagement the report rate rose from near zero to 62%, which only happens when people feel safe flagging something they are unsure about. The goal is a workforce that reports quickly, not a list of who failed.
Why layer additional email security in front of Microsoft 365?
+
Microsoft 365 includes solid baseline filtering, and it stops the bulk of commodity spam and known malware. What it catches less reliably are the targeted attacks that hurt SMEs: display-name spoofing of a director, a compromised supplier mailbox sending a genuine-looking invoice, and Business Email Compromise with no attachment or link to scan. The added layer analyses sender behaviour, relationship history and message intent rather than signatures alone, and it quarantines the small number of highly targeted messages that matter. It sits alongside Microsoft's protection rather than replacing it.

