How a Global Consulting Firm Fixed Its Phishing Simulation Accuracy and Reduced Human Cyber Risk
Learn how a global consulting firm stopped fake phishing clicks from bots, fixed inaccurate reports, and reduced human cyber risk with Keepnet’s Human Risk Management platform.
A leading global consulting firm with 45,000+ employees worldwide was running a highly advanced cybersecurity operation. With a complex enterprise infrastructure, Microsoft Office 365, and layered email defenses — including Proofpoint and a robust internal Security Operations Center (SOC) — the organization was well-equipped to fend off external threats.
Yet, when it came to phishing simulations and security awareness training, they faced a hidden and costly problem: inaccurate simulation data.
This blog post explores how they identified the issue, transformed their simulation accuracy, and reduced human cyber risk with Keepnet.
The Hidden Challenge: Ghost Clicks and Inaccurate Metrics
Despite fully whitelisting phishing simulation IPs and domains across Microsoft Defender and third-party tools, the organization continued to see inaccurate results in its phishing simulation reports.
- Users were reported as having clicked on phishing links without opening the emails.
- Simulation results were filled with misleading data, making them unreliable and hard to act upon.
- Even with full whitelisting across Microsoft Defender, sandboxes, and Proofpoint, the problem persisted.
These false positives, caused by automated systems pre-analyzing emails, led to distrust in the metrics. Security teams couldn’t confidently measure user behavior, which undermined compliance efforts and reduced program effectiveness.
To learn how to avoid misleading results and set metrics that reflect real user behavior, explore the Keepnet article: How to Set the Right Security Awareness Metrics to Protect Your Organization.
The Turning Point: A Proof of Value with Keepnet
Frustrated with unreliable data and growing pressure to meet compliance standards, the firm turned to Keepnet for a Proof of Value (PoV). The goal is to test whether Keepnet’s solution could provide clarity and accuracy where others have failed.
What they found was transformative:
- 100% elimination of bot clicks from security tools like Microsoft Defender, AI scanners, and sandboxes.
- No need for extensive whitelisting, which reduced time and operational complexity.
- Accurate reporting based on real user interactions, not system-generated artifacts.
Keepnet's platform instantly resolved their most critical issue — trust in the data.
To see how advanced reporting can pinpoint high-risk areas in your organization, check out the Keepnet guide on Executive Reports: Companies with the Highest Risk Scores.
The Outcome: Reliable Compliance and Measurable Human Risk Reduction
The results of the PoV were so compelling that the organization quickly adopted Keepnet as its go-to phishing simulation and security awareness tool. With Keepnet, they:
- Achieved compliance by accurately measuring human response to phishing.
- Protected their brand and reputation with data they could trust.
- Shifted focus from technical troubleshooting to driving behavior change and risk reduction.
Keepnet’s seamless compatibility with Microsoft environments and its ability to filter out non-human interactions gave their cybersecurity team the confidence and clarity they had been missing.
Facing False Clicks with Your Current Awareness Provider? Let’s Fix That.
Many security teams using platforms like KnowBe4, Hoxhunt, and Proofpoint face a critical challenge: bots and email security tools auto-click phishing links, generating false positives. These non-human clicks distort simulation results, making it nearly impossible to measure real user behavior—and creating endless whitelisting headaches.
Keepnet eliminates this problem at the root
Keepnet Human Risk Management platform uses advanced bot detection and filtering technology to ensure that only real user interactions are recorded—no clicks from sandboxes, AI scanners, or security gateways. This means:
- 100% human-verified reporting
- No more wasted hours managing whitelists
- Accurate insights you can use to improve user behavior and meet compliance goals
With Keepnet, you don’t just run simulations—you get clean, actionable data that drives real risk reduction.
To understand how to identify and manage users who repeatedly fall for phishing attempts, explore the Keepnet article: Executive Reports: Insights on Repeat Clickers in Phishing Simulations.