Skip to main content
Conan O’Brien featured in series of 15+ AI security training modules
Customer stories

How Fireworks Has Automated Security Awareness and Hit 96% Training Completion with Adaptive Security

SaaSSMB
Fireworks
  • ~96%

    completion across compliance trainings

  • 100%

    completion on continuous cyber training

  • Near-automated

    run by a nimble GRC function just months into the role

Get ready for a super user-friendly platform that lets you almost fully automate your security awareness training.

Natalie Zelman

Natalie Zelman

GRC Lead, Fireworks

About Fireworks

Fireworks runs one of the fastest inference and training platforms in the industry, serving open models in production for more than 10,000 companies such as Cursor and Notion, and processing over 40 trillion tokens every day. Founded in 2022 by a group of engineers from Meta's PyTorch team and based in Redwood City, the company has become core infrastructure for the AI boom, backed by leading investors and trusted by names from startups to the enterprise.

Sitting at the center of that much traffic and customer data makes security foundational, not optional. A governance, risk, and compliance function owns that responsibility, keeping the company inside its own policies, meeting frameworks like SOC 2 and ISO 27001, and making sure the people behind the platform are ready for the attacks aimed at them. It is a fitting place to run an AI-native security program, and that is exactly what the team set out to build.

Challenge

Mature and ever-evolving GRC function that needed to tailor training to real AI threats

Natalie Zelman joined Fireworks as GRC Lead and, within her first months, owned the full sweep of governance, risk, and compliance, from policies and controls to audits, third-party risk, and staff training. Building a security awareness program that actually fit a fast-moving AI company was part of the mandate from day one.

The tools she had worked with before made that hard. Generic, off-the-shelf training was difficult to tailor to the threats Fireworks actually cared about, and preparing employees for AI-driven attacks like deepfakes meant a lot of manual effort.

We were looking for a tool that let us fully customize our phishing and security awareness campaigns. Our previous approach relied on more generic, off-the-shelf content, which made it hard to tailor campaigns to real AI-driven threats like deepfakes.
Natalie Zelman

Natalie Zelman

GRC Lead, Fireworks

The worry behind that was specific and current.

We were worried about deepfakes and the uptick in phishing attempts.
Chris Ulrich

Chris Ulrich

Director of Security & Trust, Fireworks

The Turning Point

Native customization plus AI deepfake practice, without stitching tools together

What won Natalie and Chris over was the ability to build and shape everything in one place, then take it a step further into AI-era scenarios that her old approach could not produce. She could fully customize campaigns natively, and she could generate AI profiles that let her run realistic deepfake practice for the team.

The top reasons were the ability to fully customize campaigns natively, and the AI-generated profiles that let us run realistic deepfake practice scenarios for our team.
Natalie Zelman

Natalie Zelman

GRC Lead, Fireworks

Solution

One platform a lean team can actually run

For a GRC function of their size, how easy the platform is to operate matters as much as what it can do. Setup and configuration were fast, and the program now runs with very little manual overhead, which is what lets a small, new team cover a growing company.

What stands out most is how easy the platform is to set up and configure. The UI is really customer-forward.
Natalie Zelman

Natalie Zelman

GRC Lead, Fireworks

On the phishing side, the team runs varied, realistic simulations drawn from the everyday tools employees actually use, from collaboration apps to document sharing to AI services, so no two campaigns feel like the same obvious test. Alongside them, AI-generated deepfake scenarios give employees direct practice against the kind of synthetic impersonation that a company at the center of the AI industry has every reason to prepare for.

The training itself is built to be tailored rather than generic, which is a large part of why people actually complete it. New hires are onboarded into security awareness by department, and continuous training runs throughout the year rather than as a single annual push.

Results

Training people finish, and a program that runs itself

The clearest proof is completion. Across the company's compliance trainings, roughly 96% of assigned modules were completed, and continuous cybersecurity training reaches 100% completion. New-hire onboarding lands in the same range, which means the lessons are reaching people rather than sitting unopened.

Just as important for a team this lean is how little the program demands to keep running. Once configured, it largely runs itself, freeing a four-month-old GRC function to operate a full security awareness program without it becoming a full-time job for anyone. That near-automation is the return Natalie points to first.

The behavior change is starting to show, too. Employees are more cautious with their inboxes and more willing to raise a hand when something looks off.

We've noticed people are much more cautious in reviewing emails and will reach out to us directly if something looks suspicious.
Chris Ulrich

Chris Ulrich

Director of Security & Trust, Fireworks

Get started with Adaptive Security

Get started

Human security for the AI era.