Search

Hongke's latest articles

HongKe

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Ut elit tellus, luctus nec ullamcorper mattis, pulvinar dapibus leo.

[Hongke Case Study] From Reactive Firefighting to Proactive Defense: Servers Australia Implements KnowBe4 to Achieve a 90% Training Completion Rate—A Practical Report on the Transformation of Its Cybersecurity Culture

Company Profile

Servers Australia is Australia’s leading provider of cloud hosting infrastructure services, headquartered in Wyong on the Central Coast of New South Wales, with nine data centers operating across the country. The company provides enterprise clients with private cloud, virtual data center, bare-metal server, and colocation services, and is committed to helping organizations optimize their IT infrastructure, enhance operational resilience, and support continued business growth.
As a technology partner deeply integrated into our clients’ mission-critical business systems, Servers Australia understands that cybersecurity is not just a technical issue—it is the cornerstone of our clients’ trust.

Challenges Faced: A Lagging Cybersecurity Culture; A Reactive Approach Is Insufficient to Counter Increasingly Severe Threats

In recent years, Australia’s cybersecurity situation has continued to deteriorate. According to the *Annual Cyber Threat Report* published by the Australian Signals Directorate:
  • Cybersecurity incidents in Australia increased by 12% between 2023 and 2024
  • On average, a cyberattack occurs every 6 minutes
  • An attack involving approximately 20% is spreading via email
What is even more alarming is that more than 11% of attacks are linked to insiders or insider threats. This means that the human factor has become both the most vulnerable and the most critical link in an organization’s information security system.
As a managed service provider, Servers Australia has a deep understanding of this risk. Jaden Roberts, the company’s Network Operations Manager, recalls that for some time, the company’s approach to handling cybersecurity incidents tended to be reactive—only rushing to remedy the situation after an incident had already occurred.
Because employees lack systematic cybersecurity training, they are often at a loss when faced with threats, which leads to:
  • Chaotic Incident Handling Process
  • The team is under tremendous pressure
  • Has a negative impact on employee morale
Roberts said, “Dealing with cybersecurity incidents can sometimes be a traumatic experience. I’ve witnessed firsthand the impact it has on organizations and individuals. That’s why I want to change employees’ mindset toward cybersecurity—shifting from a reactive approach to a proactive one, and truly establishing a culture of cybersecurity.”
He realized that technical defenses alone could not solve the underlying problem. Servers Australia must raise cybersecurity awareness among its employees from within, so that every employee becomes a “human firewall” for the organization.

Solution: Implement KnowBe4 to establish a systematic cybersecurity awareness training program

After evaluating several vendors, Roberts ultimately chose the KnowBe4 cybersecurity awareness training platform.
KnowBe4 is the world’s leading cybersecurity awareness training and simulated phishing platform, currently serving over 70,000 organizations. The platform’s training content was designed in collaboration with the late renowned hacker Kevin Mitnick and is based on real-world social engineering attack techniques, making it highly relevant to real-world scenarios.
The KnowBe4 platform offers:
  • Information Security Awareness Training Course
  • Simulated Phishing Attack Testing
  • Information Security Culture Assessment
  • Employee Risk Analysis
These features align very well with Servers Australia's needs.
Roberts said, “KnowBe4 is very intuitive to use; employees can get started easily, and administrators can effortlessly create and manage training campaigns. With its clear interface and modular features, we were able to complete the deployment and go live very quickly.”

A rich repository of content and smart tools drive efficient training

After deploying the platform, Roberts immediately set out to develop a targeted cybersecurity training program, with the primary goal of helping employees understand the real-world cybersecurity threats facing the industry. Using KnowBe4’s content library, he was able to easily access a wide range of ready-made courses.
The KnowBe4 platform offers hundreds of thousands of training modules covering a wide range of cybersecurity topics, including phishing attacks, ransomware, and social engineering. Organizations can quickly launch cybersecurity training campaigns without having to create training content from scratch.
Roberts said, “KnowBe4 integrates training and reporting into a single platform, significantly reducing training management costs. In the past, we had to manually compile and distribute training materials; now, the entire training process can be completed with just a few clicks.”
As the training program has continued, employees’ cybersecurity awareness has begun to improve significantly. Roberts also places particular emphasis on KnowBe4’s cybersecurity newsletter feature—the platform sends employees weekly updates on the latest threats, keeping cybersecurity topics front and center in their daily work environment and effectively extending cybersecurity awareness from “training sessions” to “everyday habits.”

Industry Alert: A Real Attack from Within

Just as Servers Australia was working to foster a culture of cybersecurity, an incident that drew widespread attention occurred in the global cybersecurity industry—KnowBe4 itself nearly became the target of a state-sponsored cyberattack.
A North Korean spy posing as a software engineer successfully navigated multiple rounds of the recruitment process by using AI-generated photos and a stolen identity. Upon receiving a Mac workstation shipped by the company, the spy immediately attempted to install malware. The KnowBe4 cybersecurity team detected the anomaly within 25 minutes and successfully thwarted the attack, preventing any data breach.
"If this can happen to us, it can happen to any organization," said Stu Sjouwerman, CEO of KnowBe4. For Servers Australia, this incident further underscores that, in addition to technical defenses, employees’ ability to recognize social engineering attacks is equally essential.

Significant Results: Training completion rate exceeded 90%, and human-related risks were significantly reduced

Just a few months after implementing KnowBe4, Servers Australia’s cybersecurity culture underwent a marked transformation. Roberts described it as “a complete turnaround.”
  • Training Completion Rate Exceeds 90%: Employee Engagement Remains at a High Level
  • Human-related risks have decreased significantly: Employees’ ability to identify phishing emails and proactively report them has improved substantially.
  • Cybersecurity awareness continues to take root: Employees are beginning to proactively discuss the latest threats and preventive measures in their daily conversations.
Roberts said, “KnowBe4 has significantly raised awareness of cybersecurity throughout the organization. It has helped us address a large number of potential security vulnerabilities while keeping our employees informed about global cybersecurity trends.”

From a Reactive Approach to a Proactive Cybersecurity Mindset

The most profound change lies in the shift in employees’ mindset. In the past, cybersecurity was often a reactive measure taken after an incident occurred; today, employees are beginning to proactively consider security issues as part of their daily work. Roberts has observed that employees instinctively ask themselves, “Is this email suspicious?” and “Is this link safe?”
This shift in behavior is precisely the core outcome of building a cybersecurity culture. Cybersecurity is no longer just the responsibility of the IT department; it has become a daily task in which all employees participate.

Why "Human Defense" Has Become a Key Component of Modern Cybersecurity Systems

The primary methods of cyberattacks are gradually shifting from exploiting technical vulnerabilities to targeting human weaknesses. Phishing and ransomware have become the two major threats facing businesses, with attackers bypassing technical defenses by tricking employees into clicking links, opening attachments, or revealing their credentials.
Even if a company has implemented the following security measures, a single accidental click can still trigger a serious cybersecurity incident:
  • Multifactor Authentication (MFA)
  • Email Security Gateway (SPF / DKIM / DMARC)
  • Endpoint Detection and Response (EDR)
KnowBe4’s “Next-Generation Cybersecurity Awareness Training” was developed specifically to address this issue. Through ongoing simulated phishing tests and behavioral training, employees can gradually develop an intuitive response to cybersecurity threats. The platform also uses employee behavioral data to create a cybersecurity risk profile—which includes phishing email click-through rates, email reporting rates, and training completion rates—enabling high-risk employees to receive more targeted training or control measures. Through positive incentives and cultural development, companies can encourage employees to proactively report suspicious behavior rather than conceal mistakes—which is crucial for defending against business email compromise (BEC), ransomware attacks, and social engineering attacks.

Conclusion: Information Security Culture Has Become a Core Competitive Advantage for Enterprises

The partnership between Servers Australia and KnowBe4 was more than just the implementation of a tool; it was a comprehensive transformation of the organization’s culture. In less than a year, the company completed a comprehensive upgrade from “passive cybersecurity → proactive cybersecurity” and from “the IT department shouldering the burden alone → shared responsibility across the entire organization.”
Roberts concluded, “Cybersecurity is a very real threat. With KnowBe4, our employees are constantly thinking about cybersecurity and factoring security into every decision they make.” He added, “I would wholeheartedly recommend KnowBe4 to any organization looking to reduce human-related risks.”
Servers Australia’s experience demonstrates that only by combining technical defenses with employee cybersecurity awareness can companies maintain true security resilience in an ever-evolving threat landscape.

Other Articles

Hongke Case

HongKe Solutions] Observability Budget Busting: How Redis + Grafana Saved Hong Kong Banks $1.4 Million in 2 Years?

Hong Kong Bank, troubled by the high license cost of Dynatrace, adopted Redis+Grafana to build an open source observable architecture in accordance with the TM-E-1 regulatory standards of the Hong Kong Monetary Authority. By adopting a hierarchical strategy of APM for the core system and metrics monitoring for the rest of the services, the bank maintains 70% of the monitoring performance, saving US$1.4 million in monitoring expenses over two years, and the report data can also satisfy the monitoring requirements.

Read more

Contact Hongke to help you solve your problems.

Let's have a chat