Hero Gradient Shape
Customer Story:
Customer Story: Changing Lives

Clear, %%real-time reporting%% for ISO 27001 compliance with Phishing Tackle

%%Real-time%% reporting on policy compliance

With Phishing Tackle, Changing Lives can now track security policy acknowledgements in real time — a key requirement for ISO 27001:2022.

%%Confident%%, trained employees

Staff are better able to identify and report phishing emails, and the IT team knows exactly who needs additional training.

Real-time reporting for %%ISO 27001%% compliance

Automated tracking and evidence make audits like ISO 27001 certification much easier to manage.
Hero Background
Company size
201–500 employees
Industry
Charity / Social Services
About
Changing Lives is a UK-based national charity that supports more than 14,000 people every year through services spanning homelessness, domestic abuse, addiction recovery, long-term unemployment, and more. Their mission is to help people reach their potential and build better futures — and in the modern world, that includes staying safe online.
%%"%%If other organisations are aiming for ISO 27001, I’d absolutely recommend Phishing Tackle, even just for the policy reporting. It’s that important.%%"%%
Adam Delaney
Head of Technology for Changing Lives

Changing Lives supports thousands of vulnerable people across the UK, but in today’s digital world, threats aren’t just physical. Cybersecurity has become a frontline issue for the charity, especially as they handle sensitive information every day.

Adam Delaney, Head of Technology at Changing Lives, knew the organisation needed a way to strengthen its cyber defences, particularly around phishing attacks and policy compliance.

Although they already had strong technical protections in place, including a 24/7 Security Operations Centre (SOC), Network Operations Centre (NOC), endpoint protection, and cloud-managed networks — one major vulnerability remained: human error.

%%“%%Phishing Tackle helps us build user confidence in spotting and reporting scam emails. That’s crucial, because no matter how strong your systems are, you need people who know what to do.%%”%%
Adam Delaney
Head of Technology for Changing Lives

Before Phishing Tackle, Changing Lives relied heavily on outsourced security services. While this ensured constant monitoring, it lacked internal visibility around how staff responded to phishing attempts and whether they understood and followed company security policies.

That’s where Phishing Tackle came in.

With simulated phishing emails, real-time reporting, and automated training nudges, Adam’s team gained clear insights into which users might need extra support and who was already phishing-savvy.

Phishing Tackle’s built-in policy management tools also made it simple to distribute, track, and report on staff acknowledgements, a critical capability, especially as Changing Lives transitioned to the 2022 standard of ISO 27001, which now requires monitoring of policy compliance.

How Phishing Tackle Helps Changing Lives Stay %%Cyber-Safe%%

Spotting risks early

The platform helps highlight which staff members need more training, so Adam’s team can proactively address issues before they become problems.

Policy compliance made simple

Security policies are sent, acknowledged, and tracked directly in the platform, no chasing or spreadsheets required.

Evidence for audits

Whether for internal governance or external certifications like ISO 27001, the team now has clear, accessible proof of their compliance and training efforts.

Targeted training

Short, focused training modules are sent automatically to staff who fall for phishing simulations, ensuring learning happens right when it’s needed most.

Ellipse Image

Get human risk management and security awareness training. Free for 14 days.

Scroll To Top Arrow