In a large company, the inbox is both a workplace and a trap. An invoice arrives. A password warning follows. Someone appears to have sent a meeting invitation. The employee makes a tiny decision, often while thinking about something else. In that setting, a yearly security lecture is a distant memory. A test email can be useful, but only if someone actually sends it.
Payoneer, the payments company, had already bought a phishing simulation tool when its security chief Yaron Weiss found the problem in plain sight. During a full year, the previous program had generated just two email campaigns for 1,200 employees. The team lacked the time and specialist training expertise to run more. The result was a familiar corporate paradox: the software existed, but the habit it was meant to build did not.
The short version
- CybeReady sells cloud-based security training that sends tailored phishing and SMS drills, short lessons and progress reports.
- Its distinguishing move is to automate the rhythm of practice: select, send, teach and measure, then repeat.
- In a CybeReady case study, Payoneer reported more than twelve simulations per employee each year and a sevenfold increase in its own resilience score over two years.
- The useful lesson for any security team is simple: count how often the program actually reaches people, not merely whether a tool has been purchased.
The expensive part was the empty calendar
CybeReady was founded in Tel Aviv in 2015 by Mike Polatsek and Omer Taran. The method, according to a 2019 account in SecurityWeek, grew out of work on phishing recognition for Israeli critical infrastructure. Instead of immediately raising venture capital, the founders spent four years refining the product with European customers. By the time a $5 million round led by Baseline Ventures funded a U.S. expansion in 2019, the company already had 130 European customers, the report said.
This origin matters because the product is less a library of clever fake emails than a machine for making the next lesson happen. There are hundreds of simulation templates, but the platform picks among them using employee and department behavior. It spreads deliveries through the month, routes people who click to feedback, updates risk groups and prepares reports. A security team can approve suggested campaigns or switch on an autopilot setting. What looks like an email in an employee’s inbox is the visible tip of a scheduling operation.

At Payoneer, the appeal was immediate. CybeReady’s case study says Weiss switched within a week of a demonstration. Integration involved exporting the company address book, allowing a short list of sending domains and approving the first campaign. The company estimates the setup took an hour. That is a vendor-reported account, but it captures the real purchase: fewer hours spent inventing exercises, and more exercises reaching the workforce.
A wrong click can be a productive one
A phishing simulation can turn ugly if its only purpose is to expose a careless colleague. CybeReady’s design depends on a different sequence. When an employee clicks a simulated malicious link, a lesson appears at once, tailored to the message that fooled them. The next drill can change in difficulty and subject. The company also measures the people who click repeatedly, a group that can hide inside a flattering average.
The approach owes something to ordinary skill building. You would not expect to become a good driver by watching one annual presentation about traffic signs. You need repeated decisions, timely feedback and situations that gradually change. A fake password reset or invoice supplies the practice field. Machine learning may choose the scenario, but the human lesson is about slowing down for a moment before a plausible request becomes a costly action.
The monthly loop
The sequence describes the platform workflow, not a guaranteed outcome for every organization.
Payoneer reported that its Employee Resilience Score more than tripled in six months and rose more than sevenfold over two years, while serial clickers fell to almost zero as a share of staff. Those are the company’s own measures, published in a CybeReady case study, rather than an independent experiment. Weiss also said the same program cost Payoneer as much as its previous vendor. No public list price tells a prospective buyer whether that comparison would hold elsewhere. The stronger observation is operational: the old budget bought two campaigns in a year; the new arrangement supported at least monthly contact.
“The most important factor to success is continuity.”Yaron Weiss, Payoneer security leader, in CybeReady’s case study
The bank changed the rhythm
NatWest offers a larger, messier version of the same problem. A security awareness manager at the bank described moving from quarterly phishing exercises, familiar to staff for about five years, to monthly practice across the workforce. CybeReady’s account says simulations went out in 35 languages under the bank’s branding. The manager liked the ability to examine results by location, management level and team. She also described conversations about how to make the transition without simply sending impossibly hard traps to everyone.
That detail is more revealing than a triumphant chart. A training program can be technically automated and still need judgment about tone, difficulty and trust. NatWest’s manager said the method felt more constructive when employees were helped after a mistake instead of being scolded. CybeReady’s current catalog extends beyond the fake inbox: SMS phishing drills, monthly Security Bites, courses, a suspicious-email reporting button called PhishCage and an AuditReady policy-signoff workflow. In 2025 it moved broader training decks into the platform, initially in 13 languages. The product is trying to sit where education, compliance and daily security operations meet.

The scale explains why automation is attractive. The company now says it serves thousands of customers in 80 countries; its website names or profiles Payoneer, NatWest, SodaStream, Wizz Air, Teva, Ericsson and Medicover. An enterprise with new hires, multiple time zones and many working languages cannot reasonably ask one analyst to handcraft every exercise. CybeReady’s features page says training materials are human translated into 42 languages, while newer marketing pages advertise 44 supported languages. The difference is best treated as a changing product count, not a precise measure of what every module supports.
What a buyer can copy
Before shopping, audit the calendar. Count actual drills sent per employee, then look at repeat clickers and reporting behavior over several months. Pair every failed simulation with a short, specific lesson. Give staff a way to report suspicious messages. If the program serves multiple languages, check the material employees really receive rather than a brochure’s language total.
The business of making practice repeatable
CybeReady is a business-to-business software company with a managed layer of training expertise. Security leaders buy the platform; employees encounter its work as messages and lessons. It also recruits resellers and managed service providers, who can bundle the program with their own services. This places it in the security awareness and human-risk market alongside companies such as KnowBe4, Hoxhunt, Cofense and Proofpoint. Its pitch is a narrow one: the content should adapt, and the machinery should spare a stretched security team from running a permanent campaign by hand.
There are limits to what a fake message proves. A person who spots a simulation may still fall for a real attack; a lower click rate does not itself show that breaches have fallen. Automation also depends on correct employee lists, email delivery, sensible training difficulty and a culture in which reporting a suspicious message feels safe. CybeReady’s own move into SMS, reporting buttons and broader lessons is an acknowledgment that phishing email is only one part of the problem.
Still, the old Payoneer calendar is hard to forget. Two emails in a year were enough to say a program existed, and too few to make it a practice. CybeReady’s insight was to turn the dullest task in security training - doing it again next month - into the product itself.