Skip to main content
Cybersecurity Awareness Month: New videos, games, and ready-to-use resources
Customer stories

How Bright Saves 30% of Its Security Team's Time with Adaptive Security

SaaSSMB
Bright
  • 100%

    training completion

  • 30%

    less time spent on the program

  • 100%

    of employees covered

“It has significantly reduced the overall effort and time spent on preparing trainings, running simulations, and assessing results. I'd say we spend at least 30 percent less time on those activities.”

Loris Gutić

Loris Gutić

Global CISO, Bright

About Bright

Bright is an AI-powered application security platform that helps engineering and security teams find and fix vulnerabilities in web apps, APIs, and the AI-driven software they increasingly ship. Bright STAR, the company's flagship platform, is built for the same AI-accelerated development era its customers are racing to keep up with, automating detection, remediation, and validation so security keeps pace with how fast modern teams build.

That mission puts an unusual amount of pressure on Bright's own internal security posture. A company that sells trust in software security has to hold itself to the same standard it asks of its customers, and that responsibility sits with Global CISO Loris Gutić, who has led security and privacy at Bright since 2022 and has more than 12 years in the field.

Challenge

A security-first company outgrowing a training platform that wasn't built for how it actually works

Before Adaptive, Bright ran its security awareness program on a legacy provider. Gutić never found it satisfying. The content was broad and static, built for large enterprises checking compliance boxes rather than for a specific company's real risk. It also had little answer for the threats Gutić actually cared about: deepfakes, voice-based social engineering, and AI-driven phishing, which the old platform covered mostly through long, passive video overviews rather than anything employees could practice against.

It had a lot of content, but it was mostly very static content that didn't wrap nicely around everything our company is. I needed something that could offer a higher level of customization, tailored to the real needs in the field where I see people struggling.
Loris Gutić

Loris Gutić

Global CISO, Bright

The Turning Point

Personalization built around Bright, not a mold built for everyone else

Gutić was introduced to Adaptive through Bright's account team. What won him over was the approach to personalization: training and phishing simulations tailored specifically to Bright, its people, its roles, and its real risk, rather than a fixed library built for the broadest possible customer base. A timing opportunity in Bright's existing contract let the team make the switch, and Bright has run its security awareness program on Adaptive since 2024.

The general idea and the perspective spoke to me, and it seemed like that could and should be the direction we go. The team's been very supportive throughout.
Loris Gutić

Loris Gutić

Global CISO, Bright

Solution

Training built around the department, phishing built around the person

Bright uses Adaptive's security awareness and phishing simulations, running department-specific training alongside automated, role-based phishing simulations. The two work together: simulations surface where attention slips, and targeted training closes the gap for the people and teams who need it most.

Gutić splits some of the training by department rather than running one generic program for the whole company, with dedicated modules on topics like AI security and data privacy. That specificity, paired with content built to feel relevant rather than like a compliance chore, changed how employees engage with it. Where the previous platform meant chasing people to finish training, Gutić now sees full completion without the pushing.

With our old platform, there was always an extra chore getting people to finish training. If you didn't capture their attention, you lost them, and then you're in a tug of war over when they're going to finish. I think our employees have made a huge step forward when it comes to participation.
Loris Gutić

Loris Gutić

Global CISO, Bright

In July, Bright ran its first company-wide campaign using Adaptive's automated phishing simulations, which tailors each simulation to an employee's role, department, and other context automatically rather than requiring Gutić to build every scenario by hand. He tested it closely and found the automated version held up well against what he would have built manually.

I try to test out every new feature that comes along. I liked how it tailored things for different employees and departments. It's fully automatic, and I think it really nailed the structure needed for a particular function. It's incredibly usable and efficient.
Loris Gutić

Loris Gutić

Global CISO, Bright

Gutić also runs department-specific follow-up conversations after simulations, tailored to the fact that sales, customer success, and finance teams each face different threats. He treats a failed simulation as a coaching moment rather than a compliance failure, in line with his view that human complacency, not lack of intelligence, is the real driver of social engineering risk.

Results

Full completion, less manual effort, and a program built to expand

Every department-specific training module Bright has run through Adaptive, including its AI security and data privacy tracks, has reached 100% completion. That is a meaningful shift from the legacy platform, where getting employees to finish training took ongoing follow-up.

Adaptive's remediation training, assigned automatically after a failed simulation, is also completing at a high rate, reinforcing lessons close to the moment they are needed.

Gutić estimates the program now takes roughly 30 percent less time to run than it did before Adaptive, across preparing trainings, running simulations, and reviewing results. The shift has let training stay high quality for employees without becoming more time-consuming for his team.

Get started with Adaptive Security

Human and agent security for the AI era.