← All Case Studies|OwnMidwest|Security Awareness Training

Security Awareness Training —
Building the Human Firewall

INS deployed an ongoing security awareness training program for all OwnMidwest employees — including monthly phishing simulations, role-based training modules, and compliance education — turning the team into a human firewall against social engineering attacks.

34% → 3%

Phishing Click Rate (6 mo)

100%

Staff Completion

Monthly

Phishing Simulations

Role-Based

Training Modules

Client

OwnMidwest

Industry

Real Estate & Property Investment

Locations

Indiana · South Carolina

Services

Phishing Simulations · Role-Based Training · Compliance Education · Risk Tracking

The Challenge

Before INS, OwnMidwest had no formal security awareness program. Employees across all three business lines — Midwest Property Investments, PTI Services, and Caddis Real Estate — had never been tested on their ability to recognize phishing emails, social engineering attempts, or suspicious account activity. An initial baseline phishing simulation revealed a 34% click rate — meaning more than one in three employees would click a malicious link.

Real estate and property investment operations are high-value targets for social engineering. Attackers impersonate title companies, lenders, and business partners to redirect wire transfers, steal credentials, and gain unauthorized access to financial systems. With no training program in place, OwnMidwest's employees were the weakest link in an otherwise strengthening security posture.

The INS Solution

INS deployed a structured security awareness training program across all OwnMidwest staff. The program begins with a baseline phishing simulation to establish a starting click rate, followed by targeted training for employees who clicked — explaining exactly what they missed and why it was a phishing attempt.

Monthly phishing simulations test employees with realistic scenarios tailored to OwnMidwest's industry — including fake wire transfer requests, impersonated title company emails, and credential harvesting pages mimicking the tools OwnMidwest employees use daily. Simulation results are tracked per employee and per business line, with targeted follow-up training for repeat clickers.

Role-based training modules cover the specific threats relevant to each employee's function: finance staff receive wire fraud and BEC training, property managers receive social engineering and access control training, and all staff complete compliance education covering data handling, password hygiene, and incident reporting procedures. Completion is tracked and reported to OwnMidwest leadership monthly.

Results

Phishing Click Rate: 34% → 3%

In 6 months, the phishing click rate across all OwnMidwest staff dropped from 34% to 3% — an 11x improvement driven by monthly simulations and targeted training.

100% Staff Completion

All OwnMidwest employees across all three business lines completed their assigned training modules — no gaps, no exemptions.

Role-Based Threat Coverage

Finance, property management, and operations staff each receive training tailored to the specific social engineering threats they face in their roles.

Ongoing Monthly Program

The program runs continuously — monthly simulations, quarterly module updates, and annual compliance refreshers keep the human firewall sharp.

What Would Your Team's Phishing Click Rate Be Today?

INS runs ongoing security awareness training programs for businesses across all industries. Find out where your team stands.