What changed first was how training reached people. Instead of a single set of generic modules pushed at everyone on the same schedule, RelateCare started running content adapted to specific audiences, including the executive and senior leadership group, whose engagement with frontline-shaped training had historically been weak. “There are modules specifically for the executive suite that highlight their responsibilities for risk. That’s been a definite benefit,” Joe said.
The tailoring also tracks the regulatory reality of who’s serving whom. RelateCare’s US-facing agents handle PHI under HIPAA; the UK and Ireland teams operate under GDPR. The platform now distinguishes between the two and delivers each group the regulation that actually applies to their day-to-day. “We can specifically tailor the training so the American-facing agents have HIPAA training, whereas the UK Irish team would have more GDPR training. That’s another massive benefit, building the course out from the country,” Joe said.
The team also began using past incidents as raw material. After a series of finance-team spoofing attempts, RelateCare built phishing scenarios that replicated those real attacks and delivered them to the finance team specifically. When the quality team subsequently asked to be enrolled in additional phishing campaigns, it was the first time in Joe’s five years at the company that a department had voluntarily requested security training.
The way correction lands has changed too. When a user clicks a simulated phish, they’re enrolled into follow-up training while the context is fresh. “They’re completing training in real time where the context is still really fresh in their head. We’ve found that really helpful,” Joe said. Early on, the reaction from some employees was that simulations felt like an attempt to catch them out. That has shifted as the program has matured and people have come to read the simulations as a way to coach, not a way to trap.
The reporting picture has changed alongside this. In RelateCare’s first campaign with OutThink, 8% of users clicked the simulated phish and 17% reported it. In the latest campaign, the click rate has fallen to 1% and the reporting rate has climbed to 34%. Credential submission, where users actually surrendered information to the simulated attacker, has dropped from 2% to 1%. “When we first started issuing the simulations, it was very minimal, the amount of people opening it versus those reporting it. We’ve seen the reporting rate increase quite substantially in subsequent simulations,” Joe said.
For repeat clickers, the program now distinguishes between will and skill. Some users get coaching when feedback indicates a confidence issue; others get reinforcement on the specific procedure they’re missing. RelateCare has also formalized a disciplinary pathway for the rare case where repeated intervention doesn’t change behavior, a route the team can now take when residual risk would otherwise sit unaddressed.
Reaching a workforce that’s roughly 70% frontline and largely remote was always going to take more than email. The integration with Microsoft Teams, and OutThink’s Eva AI assistant in particular, has been one of the most practical changes for RelateCare’s day-to-day.