How UK-Based Village Bakery Cut Phishing Failure by 70% with Adaptive Security

70%
reduction in phishing failure rate in a quarter
2x
the rate of employees reporting suspicious email themselves
~95%
completion of assigned remediation training
“We've taken the time we've saved and put it into higher-value work. We run more training, send more simulations, and even send security newsletters now. We use training more widely across the business than we ever would have before.”
About Village Bakery
Village Bakery has been baking in North Wales since 1934, and for most of that time it has been a family business. What began as a single local bakery has grown into one of the UK's most recognized independent bakers, employing over 1,000 people across a cluster of modern facilities that turn out everything from traditional breads and pastries to a large dedicated gluten-free range. The company invests heavily in its craft and its people, and it holds a King's Award for its overseas trade, a mark of how far a Welsh bakery's products now travel. As its profile has risen, so has its exposure to modern cyber threats, and its IT leadership decided to get ahead of that rather than wait for a problem to force the issue.
Challenge
A lean UK team wanted a program its people would use, and a partner that could keep up internationally
Village Bakery's IT function is small and hands-on. The security awareness program is run by a single IT technician, Cameron Warburton, and the program he was using wasn't engaging users, with low completion rates.
The legacy provider's content was dated and cartoon-based, and employees had quietly checked out of it. People were skipping to the end of modules rather than engaging with them, which is the quiet failure mode of security awareness training.
The platform we had before was a bit stale. It was cartoons, it wasn't very engaging, and we were getting feedback that people were just skipping to the end.

Cameron Warburton
IT Technician, Village Bakery
For a workforce that spans office staff and a busy factory floor, the team needed a program varied and engaging enough to hold attention across very different roles, and modern enough to prepare people for AI-era attacks rather than the phishing of a decade ago.
There was also a practical question of support. A platform is only as useful as the help behind it, and a lean UK team needed to know that onboarding, day-to-day questions, and response times would keep pace with its own working day rather than leaving it waiting.
The Turning Point
A more complete, more modern package than anything else on the table
Cameron ran an evaluation, taking demos from several vendors. Adaptive stood out because it did more, and did it in a way employees would engage with. Adaptive's impressive advanced phishing simulations were a deciding factor, and phish triage was another. Where the incumbent simply logged a reported email as a ticket, Adaptive scanned it and returned a confidence level on whether it was spam or malicious, which gave the team something to act on rather than another item in a queue.
The training also closed the gap that had sunk the old program. Adaptive's content library was refreshed regularly, and the platform let the team build their own modules with AI, including turning an existing PowerPoint into a training module without specialist skills. Taken together, it was simply a stronger package than the alternatives, and one built for the way attacks look now.
Solution
First, responsive support on UK time
That question has been answered in practice. Onboarding and day-to-day help have kept pace, and Adaptive's London office has made UK-specific questions quick to resolve on local time, so a lean team is never left waiting on support.
Day to day, I haven't found any difficulty being in the UK.

Cameron Warburton
IT Technician, Village Bakery
Personalized simulations, training that people finish, and a reporting habit that spread on its own
With that confidence in place, Village Bakery built out its program. It now runs simulations, training, remediation, and employee reporting together, where the simulations expose risk and the targeted training, easy reporting, and engagement features around them are what actually moved behavior across the business.
The phishing simulations are the foundation, and Adaptive's AutoPhish feature is what made them scale for a lean team. Cameron used to hand-pick three or four scenario combinations for each round, which was slow and had a built-in weakness, since word about a specific lure would get around the office and blunt the test. AutoPhish now selects a scenario suited to each person's role and department automatically, so the simulations are both more relevant and harder to pre-empt, and they take far less of Cameron's time to run. They are also built to mirror the sophistication of real AI-era attacks, so people are tested against what attackers actually send, not a softer stand-in.
It's been really useful, and it's saved a lot of time.

Cameron Warburton
IT Technician, Village Bakery
When someone does click, remediation is assigned automatically and built around the exact mistake they made, so the lesson lands while it still matters. With roughly 95% of assigned remediation finished, people are not just exposed to harder attacks; they are taught to recognize them, and that pairing of tougher simulation and targeted training is what changed how employees behave, not just the failure rate.
The team also solved the engagement problem head-on. For experienced staff who found standard modules repetitive, test-out lets them prove they already know the material and move on, which keeps the program from wasting the time of the people most likely to disengage. AI-built content also lets non-technical colleagues, including HR, create their own training. A leaderboard the team never even formally promoted was picked up organically once people spotted the chance to compete.
Reporting became a habit the same way. The team put the Phish Alert Button in front of people by adding it to IT email signatures and steering ticket submissions toward it. After a while, using it became second nature. It helps that reporting now feels worthwhile, because employees get an immediate acknowledgement thanking them and then feedback on whether the message was a genuine threat, which turns a one-click report into a small moment of learning.
Results
A workforce trained to spot sophisticated attacks, and a sharp drop in failure
The goal was never simply a lower number on a dashboard. Village Bakery put its people in front of harder, more realistic lures, then used the training that followed to teach them to recognize what a modern attack looks like. Over the life of the program, that combination cut how often employees fall for phishing by 70%. The team now reports that improvement up to leadership in the board pack as evidence the program is working.
The change in day-to-day behavior is just as real. Employee reporting of suspicious email through the Phish Alert Button has doubled, and security has become something people actually talk about across the business rather than a box the IT team ticks. The reporting itself could have created a manual burden, but automated triage and remediation absorb it.
For a small to medium-sized business with a lean IT team, the clearest return is not a line of saved hours but where the team's attention now goes. Rather than banking small time savings, Village Bakery has reinvested them in a bigger, better program, running more simulations, producing a regular security newsletter, and extending training more widely across the business than it could have before.
It's been a massive success. People are reporting emails a lot more, cyber security is a big subject across the business now, and we put those reports into the board pack to show how the failure rate has come down.

Cameron Warburton
IT Technician, Village Bakery
The program has delivered at home, on UK time, with responsive support close at hand. Underneath the numbers, the risk picture has improved too. A workforce that engages with realistic training, reports what looks wrong, and completes its remediation is a smaller target with fewer openings for an attacker to find, which is exactly what a growing exporter wants as its profile rises.
Looking ahead, the team expects to keep finding new uses for the platform as it grows.
The platform's ever-growing. There are more features and more areas we can put to use, and the AI tools keep getting more integrated, so it gets easier and easier.

Cameron Warburton
IT Technician, Village Bakery