How Coegi Cloud cut security awareness tickets to zero with usecure
Table of contents
Subscribe to newsletter
KEY TAKEAWAYS
They're not hacking in, they're logging in: how a Nordic MSP rebuilt security awareness
As Nordic phishing became harder to spot, Coegi Cloud needed a security awareness service it could run across its whole client base without adding work.
Coegi Cloud has been an MSP since 2004, working with around 400 customers from Gothenburg and Stockholm and operating as part of a wider Nordic group across Sweden, Norway, and Finland. Until a couple of years ago, phishing in the region had a credibility problem.
Attacks were lifted from English-language campaigns and run through translation tools that mangled every line. The threat felt abstract, even faintly ridiculous. As Patrik Kekonius, Director of Sales at Coegi Cloud, puts it: "all the phishing attempts that they saw, they were just hilarious. Nobody would click on anything."
That made security awareness a hard sell. The danger looked like someone else's problem.
Then the attacks changed.
When phishing stopped being a punchline
The messages got better. Localization improved. Attackers started impersonating trusted brands and senior colleagues, and the goal shifted from ransomware toward identity theft.
"They might look like they're coming from Microsoft or their CEO or the CFO. And it's pretty scary," Patrik says.
The most important change is the one that doesn't trigger an alarm. When an attacker has valid credentials, they don't force their way in. As Patrik describes it: "they're not hacking into our customers' environments. They're actually logging in, which means that it doesn't raise any alerts." A legitimate login from a stolen identity looks exactly like a real one.
The attackers do their homework too, researching roles on LinkedIn to time their approach for when someone is most likely to be stressed and click, and increasingly using AI to sharpen the bait. The old warning signs, broken grammar and odd domains, are mostly gone.
Patrik saw how real this had become when the owner of one client called him, shaken. One of her own customers, a large pharmaceutical business, had received a convincing email from what looked like her staff. On investigation, eight of that customer's managers had clicked a link from a domain they thought they recognized. The fix on the technical side was phishing-resistant MFA. But the wider lesson was clear: telling people to be careful was no longer enough.
A platform technicians and end users both adopt
What sold Patrik on usecure was not a single feature. It was how little friction it created on both sides of the desk, which rarely happens with security tooling. "In this case they both like it and I love how easy it is to use," he says.
The simplicity reached into setup. Patrik leads sales, not engineering, yet he could connect a client tenant himself and get users syncing without a technical project around it. "I can't even remember if it took an hour. The whole platform is so self-explanatory." Users onboard and offboard automatically as each customer's tenant changes, which takes admin out of scaling the service.
More than phishing simulations
Coegi Cloud wanted more than a standalone phishing tool, and usecure put several parts of a human risk program in one place:
- uLearn for security awareness training and knowledge gap analysis
- uPhish for phishing simulations
- uBreach for dark web exposure monitoring
- uPolicy for digital policy distribution and sign-off
The training library also solved a specific regional problem. A client heading into ISO 27001 certification was told by its auditors to complete a Swedish course called DISA (Digital Information Security Training for All). Rather than send those employees outside the platform, a usecure rep pointed Patrik to the library, where the course already lived. He could push it to all users, make it mandatory, and track completion and pass rates in one place. "They were so happy. I got tons of emails just saying thank you after that."
Policy management landed the same way. Getting acknowledgments used to mean chasing people for signatures. As Patrik puts it: "you had to have some poor guy or girl walking around, gathering those signatures." Moving that into uPolicy turned a manual job into tracked, real-time compliance evidence, which matters most for customers under a specific regulation.
There is also a prospecting angle he values as a salesperson: a uBreach domain scan almost always surfaces something, which gives him a genuine reason to open a conversation with a new prospect.
In every package, by design
Coegi Cloud does not reserve usecure for premium accounts. It sits in every service tier, entry level included. "It doesn't matter if you're the basic level, entry level, you still get usecure. That's how much we love that service," Patrik says, adding that he thinks the platform is priced well below the value it delivers.
For an MSP, that consistency is the point. A security awareness service is far easier to scale when it deploys the same way across the base rather than being sold, configured, and managed differently for every account.
The proof: a live comparison across the customer base
Patrik does not need a survey to see the difference, because his own base gives him two groups to compare: customers running usecure and customers who are not.
When he isolates the usecure group in his support data, the tickets about phishing, policies, and courses drop away. "You pull out the ones using usecure, they don't have any tickets anymore." The customers outside that group keep raising them. It is not a controlled experiment, but as an operational signal it is hard to argue with, and the difference has stuck.
More than 350 users now run on usecure across Coegi Cloud's customers, added and removed automatically through their tenants, with training and simulations running as part of the ongoing program. For Patrik, that comes back to the purpose of the service: "mission accomplished, because that's what we're trying to achieve, making them more security aware."
Asked what he would tell another Nordic MSP weighing it up, he does not hedge: "I would definitely recommend them to contact usecure."
Make security awareness easier to scale
For MSPs, the challenge is not offering another security product. It is delivering a service consistently across customers without growing the work needed to support it. Coegi Cloud's experience shows what that looks like when training, phishing simulations, policy management, and credential monitoring run through one platform built for MSPs.
See how usecure can help you scale human risk management across your customers without scaling the workload. Book a demo to see the platform in action.
BOOK A DEMO
See usecure in action
A 30-minute walkthrough of how to cut human risk across your users, tailored to MSPs and IT teams.
Subscribe to newsletter
Erfahren Sie, wie Unternehmen im Bereich Professional Services mit usecure menschliche Risiken reduzieren
Erfahren Sie, wie IT-Teams in Professional-Services-Unternehmen usecure nutzen, um sensible Kundendaten zu schützen, Compliance-Anforderungen zu erfüllen und ihre Reputation zu wahren — ohne abrechenbare Arbeit zu beeinträchtigen.
Related posts
Explore more insights, updates, and resources from usecure.




