
Key Takeaways
- A simulation platform delivers a lure to 1 mailbox and records 1 person's click, and a shared shift credential breaks that chain
- IBM's 2026 X-Force index puts manufacturing at the top of the target list for the 5th year, at 27.7% of observed incidents
- Verizon's 2026 DBIR manufacturing snapshot makes social engineering the 2nd-largest breach pattern in the sector at 17%
- Provision an individual domain account, or use a badge tap or PIN at the kiosk, so the completion record names a person
- Run 2 tracks and report them together, with simulation for the named accounts and a mobile awareness track for everybody else
The campaign brief reads simply enough, which is to run a phishing simulation across the plant. The problem arrives when your L&D team opens the plant roster and finds most of the production floor has no individual corporate mailbox. Security awareness training software assumes a mailbox per person, and roughly 3 in 4 people on that roster do not have one.
Those operators reach the ERP, the time-and-attendance system, and the safety reporting portal through a shared kiosk, signing in with a shift credential that 3 rotations use in turn. A simulation platform delivers a lure to 1 address and records whether that credential's owner clicked, which is a chain running from address to person. On the floor, that chain stops at the terminal.
That terminal logs a click against a shared login, which tells your security team which shift account was open at 06:14. It does not name which of the 3 operators was using it. Telling those 3 apart is where phishing training for deskless workers starts, because everything downstream depends on shared terminal attribution.
Why a Standard Simulation Misses the Production Floor
What a Shared Terminal Does to Click Attribution
That attribution is an assumption simulation platforms rest on and rarely state, which is 1 person to 1 inbox. Under that assumption the lure arrives in an individual mailbox, the click is recorded against it, and the microlearning fires for whoever authenticated the session. All 3 of those outputs depend on the click belonging to 1 person.
A production floor breaks that pairing, because it runs on a different credential model. Under that model, line operators clock in on a department account, check task assignments, and file safety observations through the terminal the previous shift used an hour earlier. That account identifies them as members of a shift, so a lure delivered to it produces no individual signal at all.
That signal gap is invisible in the dashboard, which is what makes it survive. The campaign reports a click rate, and it reports nothing for the floor.
A campaign dashboard shows 3 numbers and hides the 4th:
- A click rate for the accounts that received a lure
- A report rate for those same accounts
- A department breakdown of both
- Nothing at all for the workers who never received one
Why the Platforms Have Not Solved It
That 4th number is missing because phishing simulation was built for offices, and 1 assumption traveled with it. That assumption, a named mailbox at an assigned workstation, held for the financial services, healthcare, and professional services firms that drove early adoption. A shared-terminal plant falls outside what most platforms are built to configure.
Your exposure to that gap is proportional to the size of the floor. Where production operators are the majority of headcount, the training gap covers that same majority. A plant of 800 with 600 on the line is running security awareness for 200 people and reporting it for 800. The program that looks complete in the dashboard is, in practice, a security awareness program for supervisors, engineers, and administrative staff at assigned desks.

What the Attribution Gap Costs a Plant
The Risk When Nobody Can Be Named
Manufacturing topped the target list for the 5th year in IBM's 2026 X-Force Threat Intelligence Index, accounting for 27.7% of the incidents X-Force observed, with data theft the most common outcome.
That 27.7% is the sector you operate in, and Verizon's 2026 DBIR manufacturing snapshot puts social engineering at 17% of breaches, second only to system intrusion. Both figures describe attacks that reach a person before they reach a network. A plant with no training layer for the floor has an untrained floor. That is the majority of the people an attacker will try.
A program that cannot attribute a click produces results that read complete and are hollow. Your security team receives click rates organized by department or shift account. They cannot name who clicked or who finished the assigned microlearning.
Social engineering in a plant also takes forms no email campaign can test. Those forms bypass the mailbox entirely:
- A phone call asking for process detail or a supplier contact
- Tailgating at a secured door behind somebody with a badge
- A USB drop in the break room or the car park
A floor that has had no security awareness training is unprepared for all 3 routes, and the simulation dashboard will never say so.
Safety Training Already Solved This
Your plant has built individual training records at a shared terminal before. 29 CFR 1910.178(l)(6) requires a certification naming each powered industrial truck operator trained, along with the training date and the evaluator. That naming requirement is what funded individual sign-in at the kiosk in the first place.
Workers tap a badge or enter a personal PIN before a module starts, and the record attaches to the person. That badge is the same credential a simulation platform needs. Nothing about it has to change for a phishing campaign.
That badge infrastructure is what makes a safety record defensible in an inspection, and it is what security awareness can run on, at no extra cost and with no extra hardware. The shared terminal is the standard delivery environment for compliance training across manufacturing, and you have already solved attribution for 1 category of it. Adding a second category to it is a provisioning decision.
How to Restore Per-User Attribution Before You Run a Campaign
Individual Domain Accounts
The cleanest route to simulation-eligible attribution is provisioning individual domain accounts with mailboxes. It is real infrastructure work, and it is the configuration the platform was built around. Nothing else gets you a per-person click record. Workers with their own accounts receive lures, generate per-person click records, and trigger the microlearning that fires after a simulated click.
Many plants extended that identity to the floor years ago. A worker signing in for a safety observation already holds that identity. What is usually missing is the mailbox, and adding 1 address to an existing account is often the whole provisioning step. IT can do it in an afternoon for a shift.
Delivery Alternatives That Keep the Record Individual
For workers still off the domain account track, 3 alternatives keep the record individual:
- SMS-delivered awareness: Send content to the personal mobile number on record in the HR system, and track completion against that number.
- QR code at the kiosk: Post a code at the terminal linking to a module, so the worker scans on a personal device and completes under their own identity.
- Kiosk sign-in with a PIN or badge tap: Authenticate the worker before the shared session opens, so the record attaches to the individual identifier.
None of the 3 delivers what a live lure in a named inbox delivers. They are awareness mechanisms, and the distinction matters when you define what coverage means. A worker who finishes a module about recognizing a phishing attempt has received instruction. Somebody who clicks a lure and gets microlearning 10 seconds later has had a behavioral event.
Name Every Click on the Plant Floor
Run simulations for the named-account population and see the click and report rate by team, department, and role.
Which Workers a Simulation Reaches, and Which Need Another Track
Workers with individual mailboxes get that behavioral event, as full participants in the simulation. Those workers receive lures on the schedule your security team sets, and a click assigns microlearning matched to the lure type within seconds. The same click updates the risk score that follows them across the next 4 campaigns. Repeat clickers roll into refresher paths with no chasing from L&D.
That named-account population is usually larger than a floor-only count suggests, often by 20 points. Management, supervisors, engineers, quality staff, procurement, maintenance planners, and administrators commonly hold addresses. Provisioning accounts for floor leads and shift supervisors adds the segment that talks to both the floor and to outside contacts, which is the segment a spear-phishing attempt targets.
Worker segment | Individual mailbox | Track | What gets recorded |
|---|---|---|---|
Management, engineering, procurement, administration | Yes | Phishing simulation | Per-person click rate, risk score, microlearning completion |
Floor leads and shift supervisors | Yes, once provisioned | Phishing simulation | Per-person click rate, risk score, microlearning completion |
Line operators on shared terminals | No | Mobile awareness course track | Module completion, assessment score, individual record |
Contract and temporary workers | Depends on the assignment | Assess at onboarding and route accordingly | Completion against the contractor identifier |
The No-Mailbox Segment
Row 3 of that table is the segment outside the simulation loop, and the honest answer is a structured awareness track on infrastructure those workers already use. A mobile app that works on a personal device and supports offline completion reaches them on the bus home, where the kiosk on the floor never could. The content covers the same threats, and the completion record is still individual.
That track differs in delivery and matches on the audit trail. Workers learn to recognize social engineering across channels, handle a suspicious request for process detail, and report anomalous behavior on the floor. A program built from both tracks closes the coverage without overstating what either one delivers.
How KC Phishing Covers the Named-Account Half
KC Phishing covers 1 of those 2 tracks, auto-assigning a short, relevant lesson within seconds of every simulated click. Repeat clickers roll straight into refresher paths with no chasing. Completion is written to the same record as the simulation, ready for audit. Per-employee risk scores build from every simulation and every lesson taken.
Click and report rates break down by team, department, and role, so you can spot the departments trending the wrong way before an attacker does. A one-click Report Phishing button in Outlook, Gmail, Slack, and Teams routes real reports straight to the security queue for triage, and reporters get instant positive feedback so the habit sticks.
For the floor, cybersecurity and compliance courses from KC Library assign and track through the learning platform, which gives no-mailbox workers a completion record in the same audit trail. Plants in manufacturing and energy report both sets under 1 program, and the coverage question stops being about the mailbox.
Decide to treat both segments as 1 initiative, report their coverage together, and give both populations the individual records an audit needs. Plants that make that decision stop asking whether the simulation covers everybody. They start measuring whether everybody was reached, by whichever mechanism that segment's infrastructure supports.
Frequently Asked Questions
1. Why does a phishing simulation not work on a shared plant terminal?
A simulation delivers a lure to 1 mailbox and records the click against that mailbox. A shared shift credential identifies a rotation rather than a person, so a click logged against it tells you which account was open and nothing about who was using it. Per-employee risk scoring and repeat-clicker detection both depend on that pairing.
2. How do plants restore per-user attribution?
The cleanest route is provisioning an individual domain account with a mailbox, which puts the worker on the simulation track directly. Where that is not near-term, a badge tap or a personal PIN at the kiosk before the session opens attaches the completion record to the individual. Many plants already have that identity infrastructure for ERP access and OSHA recordkeeping, and the missing piece is only the mailbox.
3. Is awareness training an adequate substitute for simulation?
It covers the same threats and produces an individual completion record, and it is a different mechanism. A worker who finishes a module has received instruction. A worker who clicks a simulated lure and receives microlearning seconds later has had a behavioral event, which is what changes future behavior. Define coverage separately for each segment instead of reporting them as the same thing.
4. How exposed is manufacturing compared with other sectors?
IBM's 2026 X-Force Threat Intelligence Index put manufacturing at the top of the target list for the 5th year, accounting for 27.7% of observed incidents, with data theft the most common outcome. Verizon's 2026 DBIR manufacturing snapshot ranks social engineering as the second-largest breach pattern in the sector at 17%, behind system intrusion.
5. What does OSHA have to do with security awareness records?
29 CFR 1910.178(l)(6) requires a certification naming each powered industrial truck operator trained, with the training date and the evaluator. That requirement is what funded individual sign-in at shared kiosks in most plants. Security awareness training can run on the same identity infrastructure, which is why the attribution problem is usually already solved and simply not connected.
References
- IBM. IBM 2026 X-Force Threat Index.
- IBM X-Force. X-Force Threat Intelligence Index 2026.
- Verizon. 2026 Data Breach Investigations Report, Manufacturing Snapshot.
- Cybersecurity and Infrastructure Security Agency, NSA, FBI and MS-ISAC. Phishing Guidance: Stopping the Attack Cycle at Phase One.
- Legal Information Institute. 29 CFR 1910.178, Powered industrial trucks.