How Lake City Bank Keeps Phishing Failure Rates at Half the Industry Average

~9 in 10
employees report suspicious email themselves
87%
reduction in phishing failure rate, in a matter of months
Roughly half
of the financial-services industry failure-rate benchmark
“I'm already telling peers that Adaptive is the best in breed right now.”
About Lake City Bank
Lake City Bank, a $7 billion community bank headquartered in Warsaw, Indiana, was founded in 1872 and serves Central and Northern Indiana communities with 55 branch offices and a robust digital banking platform. Lake City Bank's community banking model prioritizes building in-market long-term customer relationships while delivering technology-forward solutions for retail and commercial clients. The bank is the single bank subsidiary of Lakeland Financial Corporation (Nasdaq Global Select/LKFN).
Challenge
A mature awareness program that wanted to keep pace with real-world attacks
Lake City Bank's security awareness program was already strong before Adaptive. It is led by Paul Dausman, the bank's VP and Information Security Officer, who has spent four years running information security at the bank after standing up a program from scratch in healthcare. He describes a team that moved past the basics long ago and now measures itself against what attackers are actually doing.
We've got a pretty mature security awareness program, so our focus now is training people on the active threats our peers and our sector are actually seeing. Every campaign we run is something that's already been spotted in the wild.

Paul Dausman
VP and Information Security Officer, Lake City Bank
The team had already gotten strong results out of a conventional phishing tool, and that was the problem. A mature program needs somewhere left to go. As attackers began leaning on AI to make lures more convincing and to move beyond email into voice and video, the bank wanted a platform that could keep giving its people new ground to cover rather than the same tests in a new wrapper.
The Turning Point
Betting on a platform that keeps innovating
For a team this far along, the deciding factor was not a better version of what they already had. It was how fast Adaptive shipped genuinely new capability, and how much of it was built for AI-era attacks. Beyond phishing simulations, the bank could generate training content with AI and put emerging threats like synthetic voice and AI-driven impersonation in front of employees directly. That headroom, the sense that the platform would keep pace with attackers rather than fall a step behind, is what won them over.
As soon as we brought Adaptive on, we dug into everything it did differently from our old phishing platform, and the AI-powered training creation was a big one for us.

Noah Blakesley
Information Security Analyst, Lake City Bank
Solution
Training on every test, reporting from day one, and a program that runs with far less effort
Lake City Bank runs its phishing program on Adaptive, and the results rest on a principle the team refuses to bend on. They never test without teaching first. Every simulation is paired with a short training piece up front so employees know what to look for, which turns each test into a lesson rather than a trap.
When asked whether that pairing of training and testing was behind the results, Paul credited it fully. It is the discipline he points to first when explaining how the numbers got where they are.
The reporting culture starts before an employee ever sees a phishing test. New hires meet the security team within their first hour at the bank, and they learn where the Phish Alert Button is on day one.
From there, the simulations grow more sophisticated as employees gain tenure, so the program never goes stale, and no one is left practicing on scenarios they have already outgrown. The team also builds its tests around the specific vendors and platforms employees use every day, and pushes beyond simple link-click simulations into multi-step scenarios that replicate how real credential-harvesting attacks actually work.
Just as important as what the program does is how little effort it takes to run. This is where Adaptive quietly gave the team its time back. Noah points to how much faster the day-to-day work became, from standing up a campaign to editing a template to managing users through dynamic groups that automatically move employees who need more frequent testing onto the right track without anyone doing it by hand.
What immediately stood out was how easy the platform is to use. Setting up a campaign, editing a template, managing users with dynamic groups that flag people for more frequent testing, all of it is just easier.

Noah Blakesley
Information Security Analyst, Lake City Bank
The bigger efficiency win came from Adaptive's AI training creation, which changed how the security team works with the rest of the bank. Building employee training used to mean dropping raw policy text into plain slide decks by hand. Now, the team turns a policy into a polished, engaging training in a fraction of the time, and the training is better than what the manual process ever produced. That combination, less effort and a stronger result, is what made the security team look like heroes to the people who used to own that work.
We were rock stars with our HR team. They no longer had to turn our policies into plain PowerPoint decks, and building far more engaging training with less effort was a huge win.

Paul Dausman
VP and Information Security Officer, Lake City Bank
Results
A workforce that reports, a steep drop in failures, and time back for the team
The clearest sign of the culture Lake City Bank has built is that nearly 9 in 10 employees now report suspicious email themselves using the Phish Alert Button. Reporting has become second nature across the bank, exactly the reflex the security team works to build from an employee's first hour on the job, and it is the outcome Adaptive is designed to produce.
That vigilance shows up in the failure numbers too. Employees fall for phishing simulations 87% less often than they did a few months earlier, and the drop is more impressive than it looks on its own, because it happened while the tests were getting harder rather than easier. The team was moving employees onto more sophisticated, multi-step scenarios the whole time. People are not just failing less; they are failing less against tougher attacks. That performance puts the bank's failure rate at roughly half the financial-services industry benchmark.
The program also gave the security team real time back. The hours saved on campaign setup, template edits, and user management freed the team to focus elsewhere, and the shift to AI-generated training turned what used to be a slide-deck chore into a capability other departments now notice. A lean team is running a program that looks like it takes far more people to operate.
For a bank, the real return is the incident that never happens. A workforce that reports early and fails rarely is the difference between catching an attack in progress and explaining a breach to customers who have trusted the institution for generations.
Get started with Adaptive Security
Get started