Industry case study

How LyondellBasell turned phishing practice into a reporting habit

A chemicals manufacturer used tailored exercises and immediate feedback to help employees recognize and report suspicious messages.

Source publisherHoxhunt
Source publishedPublication date not disclosed
Last checked

Independent Cactera analysis of publicly documented work. Cactera was not involved in this work. Company names identify the subjects, not Cactera clients or partners.

Customer simulation results reported by Hoxhunt

1,200 → 8,000+reported phishing simulations across successive quarters

Read Hoxhunt’s account
Comparison
Simulation report counts before and after the increase
Scope
Employees participating in LyondellBasell's program
Timeframe
First two quarters of the rollout; account references Q2 2025
The published work

The problem.

The team's existing awareness program had reached a plateau, with limited reporting and repeated simulation failures.

What changed.

Personalized simulations, short follow-up lessons and multilingual content made practice more relevant to employees.

As described by Hoxhunt.

Customer simulation results reported by Hoxhunt

What was reported.

Hoxhunt reports simulation reports increasing from 1,200 to over 8,000, alongside fewer repeat failures. Source: Hoxhunt

What the evidence can tell us

These are vendor-reported training outcomes. The report count is not a count of attacks stopped, and changing exercise difficulty can affect comparisons. The undated article describes a program with 2025 results.

Cactera analysis

What we take from it.

A useful exercise teaches the next action as well as the warning sign. Recognizing urgency or an unfamiliar sender is only part of the task. An employee needs to know how to verify a request, preserve the message and contact the right team. We would rehearse that complete sequence with examples from the roles taking part, using fictional company data.

A reporting button needs a working response behind it. Before inviting more reports, agree who receives them, what deserves urgent escalation and how employees hear back. Someone who has already clicked should be able to say so promptly. A calm response keeps attention on containing the issue and collecting the information needed for a decision.

Track whether skills carry into an unfamiliar situation. Keep the audience, exercise difficulty and reporting window visible when comparing results. Review reports per delivered simulation alongside response time and repeat mistakes. Then check real incident records separately. That gives the team a way to improve its training without turning a simulation score into a promise about future security.

A proposed method for your business

How to evaluate a similar idea.

Start with your situation and a question you can test. These are evaluation steps we would discuss before choosing an implementation.

  1. 01

    Choose a familiar decision

    Practice a supplier change, document request or access prompt that the participating team actually encounters.

  2. 02

    Teach the complete response

    Rehearse independent verification, reporting and what to do after an accidental click.

  3. 03

    Make feedback useful

    Explain the missed signal and offer a fresh example, with support in the employee's working language.

  4. 04

    Compare like with like

    Record audience size, exercise difficulty and reporting time alongside the training results.

Industry case study / Source notes

Sources & credits.

Work credited to
LyondellBasell's cybersecurity team and employees
Technology / platform
Hoxhunt
Analysis & explanation
Cactera. Company wordmarks identify the article subjects.

Independent Cactera analysis of publicly documented work. Cactera was not involved in this work. Company names identify the subjects, not Cactera clients or partners.

A relevant next step

Bring the right question.
Let’s make it specific.

Explore how security awareness training could fit the work you have in mind.

Get a quote