How Bay Federal Credit Union Cut Its Phishing Failure Rate by 86% with Adaptive Security

86%
reduction in employee phishing failure rate
~8 in 10
employees use the Phish Alert Button to report a suspicious or simulated email
1+ hr/wk
returned to the security team through automated phish triage
“One of the things that caught my eye immediately was how fresh Adaptive keeps the content. It looks at what’s happening in the world and builds scenarios that are in the moment. That’s what I love, because that’s what the attackers do.”
About Bay Federal Credit Union
Bay Federal Credit Union began more than sixty years ago, when a group of local school teachers pooled their money to start a credit union of their own. That original investment has grown into the largest locally-owned financial institution on California’s Central Coast, with more than $1.9 billion in assets and full-service banking for members across Santa Cruz, Monterey, and San Benito counties. In 2026, Bay Federal was named to the Forbes list of America’s Best-In-State Credit Unions, a recognition built on member sentiment.
Growth has not changed what the credit union stands for. Member-owned and not-for-profit, BayFed does not just hold its members’ money; it holds their confidence, and protecting member data is inseparable from the promise it makes to the people who bank there. Its technology leadership takes that responsibility seriously, investing ahead of threats rather than reacting to them.
Challenge
A mature, defense-in-depth security program that wanted to stay ahead of AI-era attacks
Bay Federal’s security program is led by SVP and Chief Technology Officer Richard Roark, a tenured security and infrastructure professional with more than three decades in the field. Roark runs a defense-in-depth strategy, layering controls so that no single gap can put members at risk, and he is candid that the hardest part of the attack surface is human, since all it takes is one person clicking the wrong thing to open a door.
For years, BayFed ran its awareness and phishing program on a legacy SAT provider. But Roark wanted more than a program that simply ran. He wanted one that kept pace with real-world threats, and the incumbent’s content did not refresh often enough to reflect what attackers were doing week to week. As adversaries began using AI to craft more convincing lures, that staleness capped how sharp his workforce could get.
The Turning Point
Seeing simulations that actually kept up with the real world
Where their previous platform refreshed content only occasionally, Adaptive kept it current by default, exactly the gap Roark had been trying to close.
What set Adaptive apart was how completely Roark could customize. Instead of choosing from a fixed set of generic templates, he could build phishing scenarios tailored specifically to BayFed, including lures modeled on the actual vendors and services his employees use every day. That level of specificity made the simulations far more convincing than anything his previous platform could produce.
I’ll give Adaptive some sources about our organization, and instantly it can craft both phishing simulations and training exercises.

Richard Roark
SVP and CTO, Bay Federal Credit Union
Solution
Fresh, AI-powered simulations plus automation that turns clicks into coaching
BayFed adopted Adaptive Security’s SAT platform and uses three capabilities together: realistic phishing simulations, automated remediation training, and employee-driven phish triage. The simulations surface the risk, but the targeted training, steady reminders, and reporting culture that follow are what actually drove the failure rate down.
The foundation is fresh, AI-powered phishing simulation. Instead of a static library of dated scenarios, Roark builds context-rich lures that mirror how real attacks actually work, which is what makes them land as teaching moments rather than gotchas.
The second pillar is automated remediation, and Roark points to it as the main engine of the improvement. The moment someone clicks a simulated lure, Adaptive assigns short, targeted training built around the exact mistake they made and what to watch for next time. Because the modules are small and digestible rather than hour-long courses, people finish them and the lesson sticks. Managers are looped in so follow-through happens without him chasing anyone.
Underneath it all is Roark’s philosophy: education over punishment. A failed simulation is a coaching moment, not an HR violation, and repeat clickers get a direct, human conversation rather than a reprimand. In one case, a single in-person chat turned a persistent clicker into one of his most vigilant reporters, someone who now flags suspicious email before anyone asks.
The third pillar is employee-driven phish triage, and it is where the culture change is most visible. The Phish Alert Button gives everyone a simple, one-click way to act on a suspicious email, and the more people use it, the more reporting becomes second nature across BayFed. Adaptive automatically clears the reports it can classify with high confidence, so Roark’s team no longer reviews each one by hand. That automation is where the program quietly buys back the team’s time.
I’m easily saving an hour or more a week. Adaptive’s automated phish triage handles the reports it can classify with high confidence, so my team just needs to monitor it. The time savings quickly add up.

Richard Roark
SVP and CTO, Bay Federal Credit Union
Results
A dramatic drop in phishing failures and a more vigilant workforce
The headline result is an 86% drop in how often employees fall for phishing simulations, from approximately 8% to 1%, during the first 6 months of the program. That improvement now puts BayFed’s failure rate significantly below the Adaptive benchmark for financial services, a standout position in a sector attackers probe constantly. It is the trend Roark carries into the boardroom each quarter as proof the program is working.
The day-to-day change is just as real. Employees now actively report suspicious emails instead of quietly deleting them, with nearly 8 in 10 using the Phish Alert Button to flag anything that looks off.
That vigilance could have buried the security team in manual review, but automation absorbs it. Adaptive’s Phish Triage auto-resolves the vast majority of reported phishing emails without anyone on the team touching them, and the same hands-off automation drives the remediation program.
The training is landing, too. With more than 90% of assigned remediation completed, the lessons reach the people who need them, which is what keeps the failure rate falling.
Just as important is what the program prevents. For a member-owned institution, every phishing attempt an employee catches is one less chance for an attacker to reach member data, and protecting that trust is the real return.
Looking ahead, Roark is focused on pushing the program’s realism further and deepening the reporting culture that has taken hold across BayFed.
The best way to sum up Adaptive’s ROI is our progression since implementation. It’s been incredible.

Richard Roark
SVP and CTO, Bay Federal Credit Union
Get started with Adaptive Security
Get started