Turning real phishing reports into a human sensor program.
Problem
Employees were primarily measured through simulated failures, while real-world detection success received little visibility or reinforcement.
Approach
Designed a Phishing as a Bug Bounty model with eligibility rules, validation, recognition, measurement, and abuse controls.
Result
The program reframed employees as active defenders and created measurable visibility into threats that bypassed technical controls.