Turning social engineering risk into practical, measurable security awareness.
How targeted training, realistic simulations and continuous engagement helped Abbots Care strengthen employee judgement and make cyber security relevant to everyday work.
Protecting a care organisation means supporting the decisions people make every day.
Abbots Care is a social care provider whose employees handle sensitive information and depend on technology to coordinate services. In that environment, security is not limited to technical controls. A convincing email, phone call or request for information can create risk even when systems themselves are well protected.
Fifosys had acted as the organisation's IT department since 2017, giving the team a clear understanding of its people, working practices and operational responsibilities. In 2018 the partnership expanded into a comprehensive social engineering awareness programme.
The objective was to understand how employees responded to realistic attempts to manipulate them, then use that evidence to focus training where it would have the greatest value. The programme needed to be informative without becoming abstract or alarmist.
A combination of simulated campaigns, small-group discussion, bite-size learning, online assessments and face-to-face training created a practical route for improving awareness and keeping new threats visible.
Reduce the human risk that technical controls cannot remove on their own.
Employees needed to recognise manipulation, understand the consequences of sharing information and feel confident responding to suspicious activity.
Threats appear credible
Social engineering uses normal communication channels and human trust, making malicious requests difficult to identify at a glance.
Sensitive information is valuable
Information disclosed unintentionally can be used to access systems, target colleagues or disrupt care operations.
Generic training has limits
Employees needed scenarios and answers connected to their own organisation rather than broad, forgettable guidance.
Awareness changes over time
A one-off session could not account for new starters, evolving attacks or the need to reinforce secure behaviour.
An existing IT partner that understood the organisation and could make risk tangible.
Because Fifosys already operated as Abbots Care's IT department, it could connect awareness activity to the systems, information and behaviours relevant to the organisation. Training was not delivered as an isolated compliance exercise.
The small-group format gave participants room to ask questions specific to their work and receive immediate, practical answers. The wider programme combined education with measurable evidence, allowing priorities to be based on actual employee responses.
Context from the existing partnership
Fifosys understood the organisation's environment and could relate examples to genuine operational risk.
Informal but expert delivery
Complex threats were explained in an approachable way that encouraged questions and practical action.
Measurement as well as training
Simulated campaigns and reporting showed where risk existed and whether awareness improved over time.
Test awareness, focus the learning and keep employees engaged.
The programme established a baseline, used realistic evidence to shape priorities and provided several learning formats to suit the organisation.
Establish the starting point
Run controlled social engineering campaigns to understand current awareness and the behaviours most likely to create risk.
Measure different interactions
Track whether employees opened messages, clicked links or entered information so each response could be assessed appropriately.
Review the evidence together
Present campaign results clearly and agree which areas and employee groups should be prioritised.
Deliver relevant learning
Use bite-size videos, online assessments, face-to-face sessions or a combination based on the organisation's needs.
Turn insight into process change
Help the team identify immediate lessons and translate them into safer internal processes and routines.
Maintain continuous engagement
Provide ongoing activity and current threat guidance so awareness remains active rather than fading after one session.
Security awareness that can be understood, measured and improved.
Abbots Care gained both practical lessons for immediate action and a repeatable way to monitor employee behaviour over time.
Clear visibility of user risk
Campaign dashboards show how employees interact with simulated messages and where additional support is needed.
Training relevant to the business
Small-group discussion and tailored examples connect cyber risk to the situations employees may actually encounter.
Immediate operational improvements
The organisation identified lessons it could apply directly and began introducing new processes following the training.
A basis for continual awareness
Multiple learning formats and ongoing engagement support sustained improvement as threats and teams change.
“The training was delivered to a small group, enabling us to ask questions specific to our business and have them answered directly.”
What would a stronger technology foundation change for your organisation?
Start with the challenge, the risk or the pressure on your team. We will help you understand the most practical route forward.