Abbots Care case study

Turning social engineering risk into practical, measurable security awareness.

How targeted training, realistic simulations and continuous engagement helped Abbots Care strengthen employee judgement and make cyber security relevant to everyday work.

Cyber security Awareness training Managed IT
Abbots Care case study
The result Clear visibility of employee risk and a structured programme for building safer behaviour over time.
Client overview

Protecting a care organisation means supporting the decisions people make every day.

Abbots Care is a social care provider whose employees handle sensitive information and depend on technology to coordinate services. In that environment, security is not limited to technical controls. A convincing email, phone call or request for information can create risk even when systems themselves are well protected.

Fifosys had acted as the organisation's IT department since 2017, giving the team a clear understanding of its people, working practices and operational responsibilities. In 2018 the partnership expanded into a comprehensive social engineering awareness programme.

The objective was to understand how employees responded to realistic attempts to manipulate them, then use that evidence to focus training where it would have the greatest value. The programme needed to be informative without becoming abstract or alarmist.

A combination of simulated campaigns, small-group discussion, bite-size learning, online assessments and face-to-face training created a practical route for improving awareness and keeping new threats visible.

The challenge

Reduce the human risk that technical controls cannot remove on their own.

Employees needed to recognise manipulation, understand the consequences of sharing information and feel confident responding to suspicious activity.

01

Threats appear credible

Social engineering uses normal communication channels and human trust, making malicious requests difficult to identify at a glance.

02

Sensitive information is valuable

Information disclosed unintentionally can be used to access systems, target colleagues or disrupt care operations.

03

Generic training has limits

Employees needed scenarios and answers connected to their own organisation rather than broad, forgettable guidance.

04

Awareness changes over time

A one-off session could not account for new starters, evolving attacks or the need to reinforce secure behaviour.

Why Fifosys

An existing IT partner that understood the organisation and could make risk tangible.

Because Fifosys already operated as Abbots Care's IT department, it could connect awareness activity to the systems, information and behaviours relevant to the organisation. Training was not delivered as an isolated compliance exercise.

The small-group format gave participants room to ask questions specific to their work and receive immediate, practical answers. The wider programme combined education with measurable evidence, allowing priorities to be based on actual employee responses.

01

Context from the existing partnership

Fifosys understood the organisation's environment and could relate examples to genuine operational risk.

02

Informal but expert delivery

Complex threats were explained in an approachable way that encouraged questions and practical action.

03

Measurement as well as training

Simulated campaigns and reporting showed where risk existed and whether awareness improved over time.

Our approach

Test awareness, focus the learning and keep employees engaged.

The programme established a baseline, used realistic evidence to shape priorities and provided several learning formats to suit the organisation.

01

Establish the starting point

Run controlled social engineering campaigns to understand current awareness and the behaviours most likely to create risk.

02

Measure different interactions

Track whether employees opened messages, clicked links or entered information so each response could be assessed appropriately.

03

Review the evidence together

Present campaign results clearly and agree which areas and employee groups should be prioritised.

04

Deliver relevant learning

Use bite-size videos, online assessments, face-to-face sessions or a combination based on the organisation's needs.

05

Turn insight into process change

Help the team identify immediate lessons and translate them into safer internal processes and routines.

06

Maintain continuous engagement

Provide ongoing activity and current threat guidance so awareness remains active rather than fading after one session.

The outcomes

Security awareness that can be understood, measured and improved.

Abbots Care gained both practical lessons for immediate action and a repeatable way to monitor employee behaviour over time.

Clear visibility of user risk

Campaign dashboards show how employees interact with simulated messages and where additional support is needed.

Training relevant to the business

Small-group discussion and tailored examples connect cyber risk to the situations employees may actually encounter.

Immediate operational improvements

The organisation identified lessons it could apply directly and began introducing new processes following the training.

A basis for continual awareness

Multiple learning formats and ongoing engagement support sustained improvement as threats and teams change.

“The training was delivered to a small group, enabling us to ask questions specific to our business and have them answered directly.”
Abbots Care Cyber security awareness training participant
Your next chapter

What would a stronger technology foundation change for your organisation?

Start with the challenge, the risk or the pressure on your team. We will help you understand the most practical route forward.