Employee awareness assessment • 2026 edition
\( S = \left(\frac{C}{N}\right) \times 100 \)
Where:
Additional risk factors adjust the base score:
Example: If an employee correctly identifies 8 out of 10 phishing emails:
\( S = \left(\frac{8}{10}\right) \times 100 = 80\% \)
With additional risk adjustments, the final score might be adjusted to 75% if the phishing emails were particularly sophisticated or targeted.
| Metric | Value | Status |
|---|---|---|
| Tests Taken | 10 | Complete |
| Correct Identifications | 7 | Good |
| Training Hours | 8 | Average |
| Risk Factor | Medium | Attention needed |
Focus on identifying social engineering tactics
Complete advanced phishing simulation module
Retake test in 30 days
Phishing awareness refers to an individual's ability to recognize and respond appropriately to phishing attempts. This includes identifying suspicious emails, websites, and other social engineering tactics designed to steal sensitive information. High awareness significantly reduces organizational risk.
The basic phishing detection score is calculated as:
Where:
Several factors influence phishing susceptibility:
Deceptive attempt to obtain sensitive information.
\(S = \left(\frac{C}{N}\right) \times 100\)
Where S=score, C=correct, N=tests.
Evaluation of phishing vulnerability levels.
Which type of phishing attack specifically targets high-level executives or prominent individuals?
The answer is B) Whaling. Whaling is a specific type of spear phishing that targets high-profile individuals such as executives, celebrities, or politicians. The term comes from fishing for "big fish" and involves highly personalized and sophisticated attacks designed to trick victims into revealing sensitive information or performing actions that benefit the attacker. These attacks often involve extensive research about the target to make the phishing attempt appear legitimate.
Students should understand the different levels of phishing sophistication. While general phishing casts a wide net, spear phishing targets specific individuals with personalized information. Whaling is the most targeted form, focusing on high-value individuals who have access to sensitive corporate information or financial resources. The terminology helps categorize the level of sophistication and target specificity.
Whaling: Highly targeted phishing attack aimed at executives or high-profile individuals
Spear Phishing: Targeted phishing attack using personal information about the recipient
Smishing: Phishing via SMS/text messages
• Whaling targets high-value individuals with greater authority
• These attacks often involve extensive research
• Remember: Whaling = "Big Fish" (executives)
• Executives should receive specialized training
• Verify unusual requests through separate channels
• Confusing whaling with general spear phishing
• Underestimating the sophistication of executive-targeted attacks
• Not implementing additional protections for high-value targets
Calculate the phishing detection score for an employee who correctly identified 18 out of 20 simulated phishing emails. Show your work.
Using the formula: \(S = \left(\frac{C}{N}\right) \times 100\)
Given:
Step 1: Calculate the ratio = \(\frac{C}{N} = \frac{18}{20} = 0.9\)
Step 2: Convert to percentage = \(0.9 \times 100 = 90\%\)
Therefore, the phishing detection score is 90%, indicating a high level of awareness.
This calculation demonstrates how simple metrics can quantify security awareness. A 90% score indicates strong phishing detection skills, though organizations typically aim for 95%+ to minimize risk. The score provides a measurable metric for tracking improvement over time and comparing performance across teams or departments.
Phishing Detection Score: Percentage of correctly identified phishing attempts
Correct Identification: Recognizing and appropriately responding to phishing attempts
Simulation Testing: Controlled testing environment to assess awareness
• Scores above 95% indicate excellent awareness
• Scores between 70-94% suggest moderate awareness with room for improvement
• Scores below 70% indicate significant training needs
• Use the formula: (Correct / Total) × 100
• Track scores over time to measure improvement
• Compare departmental averages to identify high-risk areas
• Forgetting to multiply by 100 to get percentage
• Miscounting correct vs incorrect responses
• Not considering the context of the phishing sophistication level
A company's finance department has 25 employees who took a phishing test. The average score was 65%, with 3 employees scoring below 50%. The IT department has 20 employees with an average score of 85%, and only 1 employee scored below 50%. If the company considers scores below 70% as high risk, which department needs more immediate training intervention and why?
Finance Department Analysis:
IT Department Analysis:
The finance department needs more immediate training intervention because: 1) The average score is below the 70% safety threshold, 2) A significant percentage of employees scored extremely low, and 3) Finance departments are common targets for financial fraud schemes.
This example demonstrates risk-based security planning. While both departments have some vulnerabilities, the finance department presents a higher aggregate risk. Organizations should prioritize training for departments with lower average scores, especially those that handle sensitive financial information. The combination of low scores and high-risk job functions creates a critical security gap.
Risk Threshold: Minimum acceptable security awareness level
Aggregate Risk: Combined risk from multiple factors
Targeted Training: Focused education for high-risk groups
• Prioritize training based on both scores and job risk
• Consider both average scores and distribution of low performers
• Factor in department-specific threat models
• Allocate training resources based on combined risk
• Focusing only on average scores without considering distribution
• Ignoring department-specific risk factors
• Not prioritizing training based on business impact
An organization conducted phishing tests before and after a 10-hour security training program. Before training, 100 employees averaged 60% on phishing tests. After training, the same group averaged 82%. If the cost of a successful phishing attack is estimated at $50,000, and the training cost was $2,000 per employee, calculate the ROI of the training program assuming the same number of simulated attacks.
Before training:
After training:
Training cost: 100 × $2,000 = $200,000
Risk reduction: $2,000,000 - $900,000 = $1,100,000
ROI: \(\frac{1,100,000 - 200,000}{200,000} = 4.5\) or 450%
The training program had an ROI of 450%, preventing $1.1 million in expected losses for a $200,000 investment.
This calculation demonstrates the significant financial return on security awareness training. The 22% improvement in detection rate resulted in a 55% reduction in expected successful attacks. This quantifies the business value of security training, showing how a relatively modest investment can prevent substantial losses. Organizations can use these calculations to justify security training budgets.
Return on Investment (ROI): Financial benefit relative to cost
Risk Reduction: Decrease in probability or impact of security incidents
Expected Loss: Probability of incident multiplied by potential impact
• Quantify security investments in financial terms
• Calculate both direct and indirect benefits
• Consider long-term impact of training programs
• Document baseline metrics before training
• Measure improvements consistently
• Include both quantitative and qualitative metrics
• Not measuring baseline performance
• Failing to track improvements over time
• Underestimating the cost of security incidents
Which of the following is NOT a common indicator of a phishing email?
The answer is C) Perfect spelling and grammar. While traditional phishing emails often contained spelling and grammar errors, modern phishing attacks are increasingly sophisticated and professionally crafted. Attackers now invest in creating emails that appear legitimate, with proper spelling and grammar. Therefore, perfect spelling and grammar are no longer reliable indicators of legitimacy and should not be used as the sole criterion for identifying phishing attempts.
Students must understand that phishing techniques are evolving. Early phishing emails were often easily identifiable due to poor language quality, but attackers have adapted their methods. Modern phishing can be extremely convincing, incorporating legitimate branding, personalized information, and professional presentation. This emphasizes the need for comprehensive security awareness that goes beyond simple indicators.
Social Engineering: Psychological manipulation to perform actions or divulge information
Phishing Sophistication: The level of effort and skill in crafting phishing attempts
Security Indicators: Signs that help identify potential security threats
• Don't rely solely on obvious signs like poor grammar
• Verify unexpected requests through alternative channels
• Hover over links before clicking to check URLs
• Look for domain mismatches in email addresses
• Be wary of urgent or threatening language
• Contact senders directly through verified methods
• Assuming professional appearance indicates legitimacy
• Clicking links without verifying sender authenticity
• Not questioning unexpected but well-formatted requests
Q: How often should organizations conduct phishing tests?
A: Organizations should conduct phishing tests regularly, typically on a quarterly basis. The frequency depends on several factors:
Research shows that consistent, regular testing with immediate feedback is more effective than sporadic, high-pressure campaigns. The goal is to reinforce good habits rather than create anxiety.
Q: What score should we consider acceptable for our organization?
A: Security awareness benchmarks vary by industry and risk tolerance, but general guidelines are:
Most organizations aim for 90%+ average scores across all employees. However, high-risk departments (finance, HR, executive) may require 95%+ due to their elevated targeting risk. The key is continuous improvement rather than achieving a perfect score immediately.