Case Study Deskcasestudydesk.com
Critical InfrastructureSourced

Case Study: MESA lowers its Phish-prone Percentage from 52% to 8.6% and saves nearly seven weeks a year with KnowBe4

MESA Case StudySourced & dated by Case Study Desk
Key facts · TL;DR
Company
MESA
Industry
Critical Infrastructure
Challenge
High click rates and manual email triage
Headline result
MESA reduced its Phish-prone Percentage from around 52% to 8.6% and saved nearly seven weeks of IT time annually after adopting KnowBe4 Security Awareness Training and PhishER.

Key results

52%→8.6%
Phish-prone Percentage
2018 baseline, ~5 years later
~7 weeks
IT time saved annually
via PhishER; min. ~23 hrs/month
507
Suspicious emails reported in one month
92 auto-resolved by PhishER

The challenge

MESA, a critical-infrastructure company working in cathodic protection and pipeline integrity, found through baseline testing that around 52% of employees were clicking simulated phishing links and entering personal information. Reported suspicious emails had to be reviewed individually by the IT team through the ticketing system, creating a heavy manual workload.

The solution

Beginning in 2018, MESA deployed KnowBe4 Security Awareness Training, then added PhishER in mid-2021 with the Phish Alert Button, PhishML, and PhishRIP to automatically analyze and quarantine reported messages.

PhishRIP is an enormous time saver, and efficient in shutting down threats quickly.

SS
Sarfraz Shaikh
CIO/CISO, MESA

The results, in context

MESA reports its Phish-prone Percentage dropped from around 52% in 2018 to 8.6% about five years later. Over one month users reported 507 suspicious messages, of which PhishER automatically resolved 92 without IT involvement, and the IT team saved a minimum of about 23 hours per month—nearly seven weeks annually.

Products used

KnowBe4 KnowBe4 Security Awareness TrainingKnowBe4 PhishER