Real case study: A 50-person accounting firm reduced phishing clicks from 35% to 14% in 90 days using Sonark. Learn their approach and results.
Nisi enim consequat varius cras aliquam dignissim nam nisi volutpat duis enim sed. Malesuada pulvinar velit vitae libero urna ultricies et dolor vitae varius magna lectus pretium risus eget fermentum eu volutpat varius felis at magna consequat a velit laoreet pharetra fermentum viverra cursus lobortis ac vitae dictumst aliquam eros pretium pharetra vel quam feugiat litum quis etiam sodales turpis.

Porta nibh aliquam amet enim ante bibendum ac praesent iaculis hendrerit nisl amet nisl mauris est placerat suscipit mattis ut et vitae convallis congue semper donec eleifend in tincidunt sed faucibus tempus lectus accumsan blandit duis erat arcu gravida ut id lectus egestas nisl orci id blandit ut etiam pharetra feugiat sit congue dolor nunc ultrices sed eu sed sit egestas a eget lectus potenti commodo quam et varius est eleifend nisl at id nulla sapien quam morbi orci tincidunt dolor.
At risus viverra adipiscing at in tellus integer feugiat nisl pretium fusce id velit ut tortor sagittis orci a scelerisque purus semper eget at lectus urna duis convallis. porta nibh venenatis cras sed felis eget neque laoreet suspendisse interdum.
“Vestibulum eget eleifend duis at auctor blandit potenti id vel morbi arcu faucibus porta aliquet dignissim odio sit amet auctor risus tortor praesent aliquam.”
Lorem cras malesuada aliquet egestas enim nulla ornare in a mauris id cras eget iaculis sollicitudin. Aliquet amet vitae in luctus porttitor eget. parturient porttitor nulla in quis elit commodo posuere nibh. Aliquam sit in ut elementum potenti eleifend augue faucibus donec eu donec neque natoque id integer cursus lectus non luctus non a purus tellus venenatis rutrum vitae cursus orci egestas orci nam a tellus mollis.
Eget lorem dolor sed viverra ipsum nunc aliquet bibendum felis donec et odio pellentesque diam volutpat commodo sed egestas aliquam sem fringilla ut morbi tincidunt augue interdum velit euismod eu tincidunt tortor aliquam nulla facilisi aenean sed adipiscing diam donec adipiscing ut lectus arcu potenti eleifend augue faucibus bibendum at varius vel pharetra nibh venenatis cras sed felis eget.
Phishing remains the #1 attack vector compromising Canadian SMBs. Attackers know that gaining employee access is easier than breaking through technical defenses. This case study demonstrates how Sonark helped a mid-sized Canadian accounting firm dramatically reduce phishing risk and build a security-conscious culture.
Our client was a 50-person accounting firm based in Toronto with multiple satellite offices. The firm handled sensitive financial information, tax returns, and confidential client data. Despite having basic email filters, employees were falling for phishing attacks at an alarming rate.
The Baseline Assessment
When Sonark conducted the initial security assessment, we found:
These metrics revealed significant vulnerability. With 1 in 3 employees clicking phishing links, the firm was essentially leaving doors open for attackers.
The Business Risk
For an accounting firm, a successful phishing compromise could mean:
The partner team understood they needed to act.
Phase 1: Assessment and Strategy (Weeks 1-2)
We began with comprehensive assessment:
We presented findings to the leadership team with clear metrics showing the risk and a roadmap for improvement.
Phase 2: Customized Training Rollout (Weeks 3-6)
Rather than generic security training, we created accounting-firm-specific content:
Training was delivered via short videos, interactive modules, and live Q&A sessions. Each module took 15-20 minutes, minimizing disruption to daily work.
Phase 3: Ongoing Simulations and Reinforcement (Weeks 7-12)
Knowledge alone doesn't change behavior. We deployed regular simulations with reinforcement training:
Each simulation was followed by targeted training for employees who fell for the phishing attempt. We identified click patterns and provided personalized coaching to high-risk individuals.
The Numbers
The results exceeded expectations:
More importantly, credential submission dropped significantly:
This means fewer employees would fall for fake login portals designed to steal credentials.
Engagement and Culture Changes
Beyond the metrics, we observed cultural shifts:
1. Executive Buy-In
Success required partner involvement from day one. When partners understood the risk and committed to the program, employees took it seriously. Leadership participation was visible and consistent.
2. Role-Specific Training
Generic security training fails because employees don't see the relevance. By creating accounting-firm-specific scenarios, we made the training immediately relevant and memorable.
3. Ongoing Simulations
A single training session doesn't create lasting behavior change. Regular simulations with reinforcement training kept security top-of-mind and created accountability.
4. Psychological Safety for Reporting
We emphasized that reporting suspicious emails was good, not a sign of failure. We created positive reinforcement for reporting and counseling rather than punishment for falling for simulations.
5. Personalized Remediation
Employees who repeatedly clicked phishing links received additional targeted training and coaching rather than generic remediation.
Behavior Change Takes Time
The largest drop occurred between weeks 4-8, not immediately after training. Employees needed to practice and see multiple simulations before behavior truly changed.
Role Matters
Administrative staff improved faster than senior staff. Executive assistants and admin staff had higher initial vulnerability but showed the steepest improvement curves. Partners and senior staff required more personalized coaching.
Phishing Sophistication Increases Difficulty
Simulations using common phishing tactics saw 8-12% click rates by day 90. Simulations using advanced tactics (well-researched, personalized attacks) saw 18-22% click rates. No training can eliminate all vulnerability to advanced attacks.
Reporting is the Real Victory
The 400% increase in suspicious email reporting may have been the most important metric. Employees became the organization's front line of defense, reporting suspicious emails before they could be exploited.
At the 90-day mark, the firm committed to ongoing security programs:
The firm also implemented technical controls:
Six months after the program began, the firm experienced zero successful phishing compromises. Before the program, they had suffered 2-3 phishing incidents per year.
The cost of the Sonark program was roughly $8,000 for 90 days. A single successful phishing compromise (leading to ransomware, data breach, or wire fraud) costs $50,000-$500,000 in incident response, downtime, and regulatory fines. The ROI was clear.
More importantly, the firm had built a security-conscious culture where employees viewed themselves as partners in defense rather than security as an IT burden.
This case study demonstrates several important principles:
If you're running a Canadian SMB, your employees are likely vulnerable to phishing attacks. The first step is measuring your current risk with a baseline phishing assessment.
Ready to reduce your phishing risk? Contact Sonark today to schedule a phishing risk assessment for your organization. Learn more about our phishing and security awareness programs or view our pricing to get started.