BadgerQuest
Play a roundWhy it sticksFor managersWho it's forLearnDocsPricingSign in
For municipalities, agencies and public bodies

The sector where the most breaches involve a person, and an unusual share come from inside

Security awareness training for government departments, municipalities and public bodies, whose largest exposure is the sheer volume of correspondence they send.

Government departments, municipalities and other public bodies handle personal data at a scale most companies never touch, under obligations most companies never face, with correspondence going out all day to people who have every reason to open it.

That shows up in the data as an unusual profile. Public administration has the highest human-element share of any major sector, and by some distance the highest share of breaches involving its own people rather than outsiders.

Talk to us about a public sector rolloutStart free

The evidence, and where it comes from

Every figure below links to the source it came from. We have quoted what each number counts, because a percentage without its denominator is not evidence, it is decoration.

69%

of public administration breaches involved the human element, the highest of any major sector in the report.[1]

44%

of its breaches involved internal actors, against 12% in financial services and 1% in retail. The report attributes much of that to misdelivery, correspondence reaching the wrong recipient, driven by sheer volume.[1]

80%

of the sector's breaches come from three patterns: System Intrusion, Miscellaneous Errors and Privilege Misuse. Two of those three are about what people do, not what was exploited.[1]

What this does not say

Internal-actor figures are shaped by disclosure rules. Public bodies are obliged to report things a private company would never have to publish, which lifts their internal share relative to sectors under lighter scrutiny, and the report says as much about comparing industries. It does not mean public sector staff are less careful.

Aimed at where the exposure actually is

Misdelivery is a habit, not a knowledge gap

Scenarios cover the everyday version, the wrong autocomplete and the wrong attachment, alongside the forged sender. An annual module does not touch a reflex that fires forty times a day.

Departments scored separately

Records, finance and frontline teams fail in different ways. One organisation-wide average hides the team that needs the attention.

An audit log and an evidence trail

Every privileged action in the console is logged, exports are yours, and certificates carry a verifiable serial. Built for somebody who will be asked to show their work.

Residency answered before you buy

Where data lives and how long it is kept is a conversation we are happy to have in detail up front, rather than a checkbox you discover afterwards.

Priced against your procurement, not a price list

The list price is $4 CAD per person per month. Public bodies are priced case by case, and we will put it in the form your purchasing process needs.

What your people will practise, explained free

These are the same scams this page is about, written for the person who has to spot one on a Tuesday morning. No account needed to read them.

How to spot a phishing emailFake invoices and "our bank details have changed"Strong passwords, passkeys, and MFA, without the headache

What is true in every sector

62%

of breaches involved the human element, up from 60% the year before, across more than 22,000 confirmed breaches in 145 countries.[1]

31%

of breaches began with vulnerability exploitation, which this year overtook credential abuse (down to 13%) as the single most common way in. People are involved in most breaches, but they are not the most common entry point, and we are not going to tell you otherwise.[1]

16%

of breaches came through social engineering, the third most common pattern. In simulations, the median click rate for voice and text lures runs 40% higher than for email.[1]

And the uncomfortable part, which we would rather you heard from us

One of the largest field studies of phishing training ever published followed roughly 19,500 staff at a large health system through ten simulated campaigns over eight months. It did not flatter the industry we are in.

2 points

was the entire effect of embedded phishing training on the likelihood of clicking a phishing link. Having recently completed annual mandatory security training showed no significant relationship with falling for phishing at all.[2]

75%

of the people who landed on the training page spent a minute or less on it, and about a third closed it immediately. That is a finding about attention, not about people being careless.[2]

We read that as the strongest argument for how BadgerQuest is built, not against it. What the study measured is the industry standard: an annual module, an ambush simulation, and a training page served to somebody who has just been told they failed. Nobody reads that page. Training that gets skimmed for forty seconds is not a smaller dose of training that works, it is a different thing entirely.

So the daily round is two minutes and it is a game, because that is the version people voluntarily finish. We do not send simulated phishing to real inboxes, because being ambushed by your own IT department is what produces the closed tab. Nobody is shamed for a wrong call, and what we train is the judgement to tell the two apart rather than a reflex to flag everything. Topics somebody keeps missing come back around instead of being marked complete.

The study's authors also recommend refocusing on technical countermeasures, specifically two-factor authentication and password managers that only fill on the correct domain. They are right, and those will stop more attacks than any training will. Do them first. We will say the same on a sales call. Training is for the part those controls do not cover, and it should be honest about being exactly that.

Sources

Read them yourself. That is the entire habit we are trying to teach, and it would be a strange thing for us to ask of your staff and not of ourselves.

  1. [1]Verizon Business. 2026 Data Breach Investigations Report, Executive Summary 19th edition, published May 2026. More than 31,000 security incidents, of which more than 22,000 were confirmed data breaches, across organisations in 145 countries. Figures quoted here are from the executive summary PDF.https://www.verizon.com/business/resources/executivebriefs/2026-dbir-executive-summary.pdf
  2. [2]Ho et al., University of Chicago, UC San Diego and UC San Diego Health. Understanding the Efficacy of Phishing Training in Practice 46th IEEE Symposium on Security and Privacy, May 2025. Roughly 19,500 staff at UC San Diego Health, ten simulated campaigns over eight months. Findings summarised by UC San Diego Today, 17 September 2025.https://today.ucsd.edu/story/cybersecurity-training-programs-dont-prevent-employees-from-falling-for-phishing-scams

Talk to us about a public sector rollout

Free for individuals, forever. Teams start at $4 CAD per person per month, month to month with no minimum. Pooled and agreed-term arrangements are quoted, and the terms are the ones we write down together.

Talk to us about a public sector rolloutStart free

Not quite your sector?

MSPsSmall businessNon-profitsHealthcareSchools & collegesCard paymentsLaw firmsAccounting firmsAll of them
BadgerQuest by CyberBadger
Who it's forLearnDocsAPIHelpCheck a certificatePrivacyTermsMade in Canada