The IT security team at Harrogate-based logistics firm Meridian Solutions gathered in a windowless meeting room on Tuesday afternoon to mark ninety consecutive days without a single employee clicking on a fraudulent invoice attachment, a milestone described by network administrator James Kellaway as “honestly more than we’d hoped for at this stage”.
The achievement, commemorated with a small selection of meal deal sandwiches from the Tesco Metro opposite the office, represents the longest phishing-free period the company has recorded since the security awareness programme began in 2019. A laminated sign in the IT department now reads “92 days since last incident”, though Kellaway admitted he checks his email with “a sense of creeping dread” each morning.
The celebration comes after the company’s workforce of two hundred and thirty employees completed their seventh mandatory cybersecurity training module in April, a forty-minute course that once again explained why the finance director would not request iTunes vouchers via a Gmail address with three numbers after his name. The training has a pass rate of one hundred per cent, requiring only that participants remain conscious throughout and click “next” at appropriate intervals.
“We’ve implemented a traffic light system for suspicious emails,” explained IT security officer Helen Moss, gesturing to a poster that has been on the staff noticeboard since February beneath three layers of facilities management memos. “Red means delete immediately, amber means check with us first, and green means it’s probably fine. We’re still getting questions about what the colours mean.”
The last recorded incident occurred on July 3rd, when someone in accounts opened an email claiming to be from “Microsoft Security Team” and somehow managed to bypass three separate warning messages before entering their password into what Kellaway described as “a website that looked like it had been designed in 1997 by someone having a stroke”.
Moss noted that the department had prepared a PowerPoint presentation for the occasion but decided against it after realising nobody from senior management would attend. The IT team instead spent twelve minutes eating sandwiches in companionable silence before returning to their desks to begin drafting the autumn training module.
The current record stands in stark contrast to January, when four separate employees forwarded the same “You have a parcel waiting” phishing email to colleagues, with one asking whether anyone else had received it and if they thought it might be legitimate.
When asked about his confidence in the company maintaining its current streak, Kellaway paused for what felt like seven seconds. “I’d rather not speculate,” he said eventually, turning back to his monitor where three new phishing simulation emails awaited distribution to staff inboxes on Monday morning.