case study

How Bühler Cut Phishing Failures 10×—With Zero Operational Burden

Client logo
About

Organization: Bühler Group

Industry: Industrial technology and manufacturing

Headquarters: Uzwil, Switzerland

Scale: 12,090 employees in more than 140 countries

Featured leader: Patrick Zimmermann, Information Security Expert

Challenge

Overcome a persistent phishing failure-rate plateau by increasing the frequency and quality of training—without overwhelming the security team with operational burden or alienating a diverse global workforce.

Solution

Hoxhunt’s automated, adaptive phishing simulations, instant microtraining, gamification and one-click threat reporting gave Bühler continuous practice, with almost no recurring admin burden, which altogether produced a 10x reduction in phishing failure rate.

Key takeaways:
Featured image
  • 10× lower phishing failure rate
  • Expanded from quarterly manual campaigns to roughly three learning experiences per month
  • Reduced recurring awareness operations from approximately 12 working days a year (3 days/campaign) to nearly zero, even with 8X more learning moments
  • Automated targeted coaching for repeat clickers while preserving customized training for priority groups
  • Turned employee reports into incident-response signals that can help remove malicious emails from every affected inbox

With Hoxhunt, the Swiss industrial technology leader, Bühler, replaced four labor-intensive security awareness campaigns a year with continuous, gamified micro-trainings in local languages that require negligible operational time commitment, while turning the subsequent flood of employee threat reports into real-time cyber defense.

A Global Industrial Leader Faces Phishing at Machine Speed

Bühler technology touches daily life on a remarkable scale. Two billion people consume foods produced with Bühler processes, while half of the world’s new cars contain die-cast components made using its technology. Supporting that reach are 12,090 employees in more than 140 countries, including engineers, manufacturing specialists, IT professionals and apprentices.

That scale creates a broad attack surface. Verizon’s 2026 Data Breach Investigations Report recorded 2,713 confirmed breaches in manufacturing. The human element was present in 56%, and phishing provided initial access in 13%. IBM’s 2026 research puts the average cost of a data breach in the industrial sector at $5.5 million, up 10% in one year.

Patrick Zimmermann has watched phishing become better written and designed, and more targeted with the rise of AI. Bühler employees have even received phishing emails in Swiss German—a language common in personal conversations but rare in official business communication.

“Today, the scenarios have perfect design and perfect language. We even receive phishing emails written in Swiss German, most likely because the attacker simply prompted an AI tool to create one. A traditional phishing training approach is not sufficient to skill up people against this threat.”
— Patrick Zimmermann

The Old Program Had Reached Its Production Limit

Bühler’s security team previously created 3-4 phishing campaigns each year with a traditional phishing training tool. Employees who clicked were sent to a static web page explaining the warning signs they had missed. Failure rates fell from an early double-digit percentage but then stalled.

It wasn’t an interesting or engaging user experience. The team believed more frequent practice could restart improvement, but each campaign required about three working days to build, support and analyze. Four annual campaigns consumed roughly 12 days. Matching Hoxhunt’s cadence manually—about three learning experiences a month—would have required approximately 108 working days a year.

Bühler needed to increase the frequency and realism of training without multiplying its workload.

“We were stuck at a a reduced but still high click rate. We were sure that to reduce it, we needed to increase the intensity of the training and improve the attractiveness of the content. But with the old solution, doing that 20 times a year would have multiplied the effort beyond what was practical.”
— Patrick Zimmermann

Hoxhunt Put Continuous Practice on Autopilot

Bühler wanted a modern, engaging experience with as little maintenance as possible. The team tested Hoxhunt with approximately 120 employees from across the organization. The response was entirely positive, and put to rest any concerns that gamification might feel childish or weaken the seriousness of security.

Rollout was smooth and easy. Bühler deployed the Hoxhunt reporting button, shared instructions on its global intranet and let automated onboarding take over. Employees synchronize through Microsoft Entra ID, and new users begin training automatically.

Recurring operations are now so light that Zimmermann cannot meaningfully measure them. He reviews adoption, simulations and management data when needed; Hoxhunt handles user synchronization, onboarding, simulation delivery and ongoing training. It generates reports, too.

“Implementation was as smooth as it could be. We deployed the button, announced Hoxhunt on the global intranet, and the rest was more or less automated.”
— Patrick Zimmermann

Shattering the Performance Plateau

The change first appeared in conversations. Employees approached the security team to say they liked Hoxhunt. Colleagues compared simulations and stars at the coffee machine. Some even worried that a long vacation would cause them to miss an exercise.

Bühler carried that positive framing into management reporting. Monthly reports recognize locations with the strongest performance, prompting managers in lower-ranked locations to ask how they can reach the top 20. Security improvement became something teams actively pursued.

More importantly, the failure rate fell to roughly one-twentieth of its early high and one-tenth below the plateau of the previous program. When Bühler introduced harder coworker simulations, performance briefly declined before quickly recovering. Employees were learning to handle more realistic social engineering, not simply passing easy tests.

“We were stuck at a plateau with our previous tool and with Hoxhunt we immediately saw improvement, about 10x. We also saw a similar improvement with our simulation reporting rate and our real threat reports. All that shows it worked—the numbers prove it.”
— Patrick Zimmermann

One Good Decision Can Protect 50 Inboxes

The Hoxhunt button made reporting suspicious messages simple. Those reports also revealed threats that had passed through existing email controls, turning employee behavior into a source of security intelligence. Visibility into their threat environment enabled Bühler to make strategic security investments into their security stack.

Bühler now routes Hoxhunt reports into an additional email-security layer. When one employee reports a message, the system can identify everyone else who received it. If the message is malicious, it can be removed from every affected mailbox, and the reporter learns that the action helped protect colleagues.

Zimmermann described one malicious email that reached 50 people. Previously, the team would have investigated the report, conducted an e-discovery search and manually purged the message—a process that could take hours. Now, the workflow is largely automated and completed in few seconds.

“It would be very bad if you were breached because someone clicked an email that somebody else had already reported, when you have the capability to automatically remove the whole campaign. You have to use that information to remove the threat.”
— Patrick Zimmermann

Automation Enables Meaningful Work

Automation lets Bühler reserve human attention for the people and situations that need it. Employees who fail repeatedly within a defined time range automatically receive additional phishing training. The team can also create context-specific campaigns. Before instructor-led security training for apprentices, for example, Bühler sends engaging similations to the training audience and uses the results during the classroom training.

After three years, the program continues to evolve. Bühler is working to increase reporting in regions where employees identify suspicious messages but delete them instead of reporting them. Yet the core result is established: continuous practice, stronger performance, useful threat reporting and almost no recurring administration.

“I would recommend Hoxhunt without any disclaimer, any doubt or any ‘yes, but.’ There is no ‘but’ in my eyes. It’s simple and easy.”
— Patrick Zimmermann

Want to match these results?
Hoxhunt adaptive phishing training dramatically increases training engagement and security resilience.
Request a demo