Back to Case Studies Security Training

Accounting Firm Sharply Reduces Phishing Click Rate

How a Tampa CPA firm transformed their security culture and dramatically reduced their vulnerability to phishing attacks through comprehensive training.

Based on a real EasyWayIT client engagement; client details anonymized.

Industry
Accounting / CPA
Company Size
28 Employees
Location
Tampa, FL
Improvement
Sharply reduced phishing clicks

The Challenge

This well-established Tampa CPA firm handles some of the most sensitive data imaginable: tax returns, financial statements, social security numbers, bank account details, and business valuations for hundreds of clients. A single breach could be catastrophic - not just for the firm, but for every client they serve.

When they engaged EasyWayIT, one of our first recommendations was a baseline phishing simulation to assess their human security posture. The results were alarming:

Initial Phishing Test Results

High click rate
Many clicked the malicious link
Credentials entered
Several entered credentials
No reports
No one reported the email

In plain terms: a large share of employees clicked a fake phishing link, and many entered their actual credentials on a fake login page. Perhaps most concerning, not a single person reported the suspicious email to IT.

The results were a wake-up call. The firm employs smart people - CPAs, tax attorneys, and financial advisors - yet so many had still fallen for a single phishing email.

The answer was simple: they'd never been trained to recognize them. And like most people, they were busy, distracted, and trusting - exactly what attackers count on.

Our Solution

We implemented a comprehensive security awareness program designed specifically for busy professionals who don't have time for lengthy training sessions but desperately need the knowledge to protect client data.

The Training Program

1
Kickoff Workshop (90 minutes)
In-person session showing real examples of attacks targeting accounting firms. We showed actual breach costs and consequences - making it personal and relevant.
2
Monthly Micro-Learning (5-10 minutes)
Short, engaging video modules covering specific threats: BEC attacks, invoice fraud, credential harvesting, social engineering tactics.
3
Monthly Phishing Simulations
Realistic test emails that mirror current attack trends. Employees who click receive immediate "teachable moment" training explaining what they missed.
4
Gamification & Leaderboards
Department competitions, recognition for reporters, quarterly prizes for top performers. Made security engaging rather than punitive.
5
Phish Alert Button
One-click reporting in Outlook. Made it easy for employees to report suspicious emails and get immediate feedback if it was a simulation.

Curriculum Topics

Over 6 months, we covered:

  • Email red flags - Sender mismatches, urgency tactics, suspicious links
  • Business Email Compromise (BEC) - Recognizing fake wire transfer requests
  • Invoice fraud - Vendor impersonation and payment redirect scams
  • Credential harvesting - Fake login pages and MFA bypass attempts
  • Social engineering - Phone-based pretexting and physical security
  • IRS impersonation scams - Tax-season specific threats
  • Safe browsing - Avoiding malicious websites and downloads
  • Password hygiene - Creating strong passwords, using password managers

The Results

Sharply reduced
Phishing Clicks

Click rate fell from a high level to near zero over six months

Near zero
Final Click Rate

Very few employees now click simulated phishing - strong performance

Most employees
Report Rate

Most employees now actively report suspicious emails (up from none)

None
Successful Attacks

No successful phishing attacks since program implementation

6-Month Progress

The simulated phishing click rate improved steadily over six months, falling from a high baseline to near zero:

Month 1 (Baseline) High
Month 2
Month 3
Month 4
Month 5
Month 6 Near zero

For the firm, the initial test results were a wake-up call - they had assumed they were safe simply because they were careful people. Months later, the team was actively hunting for phishing attempts, with staff catching and reporting a real attack that targeted one of the partners. The training had become a core part of the firm's defenses.

CPA Firm, Tampa

Key Takeaways

Smart people aren't immune. Intelligence doesn't protect against social engineering. Even CPAs and attorneys fall for well-crafted phishing attacks without proper training.

Consistent practice beats one-time training. Monthly simulations and micro-learning keep security top of mind without overwhelming busy professionals.

Make reporting easy and rewarded. A one-click report button and positive recognition transformed employees from targets into active defenders.

Gamification drives engagement. Competition and recognition make security training something people look forward to rather than dread.

Transform Your Security Culture

Find out how vulnerable your team is with a free baseline phishing assessment.

How Vulnerable Is Your Team?

Get a free baseline phishing assessment and find out where you stand.