Employee Phishing Readiness & Security Behavior Assessment
Measures employee phishing detection confidence, reporting behavior, and security practices to identify organizational risk gaps and prioritize awareness training investments.
設問の例
テンプレートの内容をプレビューできます。すべての設問は公開前に自由に編集できます。
To the best of your knowledge, did you receive any message you considered suspicious (email, SMS/text, or chat) in the past 30 days?
- Yes
- No
- Not sure
In the past 60 days, how often did you hover over or inspect links before clicking them in emails or messages?
How confident are you that you could handle a suspicious message appropriately?
What is your most common way to report a suspected phishing message?
- Report Phish button/add-in in email
- Security email alias
- IT helpdesk ticket
- Messaging app bot
- Tell my manager
- I don't report them
- I'm not sure how to report
When did you last complete security awareness training?
- Within the last 30 days
- 31–90 days ago
- 3–6 months ago
- More than 6 months ago
- I have not completed it
- I don't remember
What is your primary role?
- Engineering/IT
- Operations
- Finance/Accounting
- Sales/Marketing
- HR/People
- Legal/Compliance
- Product/Design
- Customer Support/Success
- Executive/Leadership
- Other
Based on your responses in this survey, please share any additional thoughts about what would help you handle phishing attempts more effectively.
Approximately how many suspicious or phishing-like messages did you notice in the past 30 days?
- 1–2
- 3–5
- 6–10
- 11–20
- More than 20
In the past 60 days, how often did you verify the sender's identity before acting on a request (e.g., checking the email address or calling the person)?
When judging whether an email is legitimate, rank these cues from most to least important to you.
- Sender domain and address
- Link URL on hover
- Urgent or threatening tone
- Unexpected attachments or requests for credentials
When you do report a suspicious message, approximately how long does it typically take from the moment you notice it?
- Within 5 minutes
- 5–30 minutes
- 30–60 minutes
- 1–4 hours
- More than 4 hours
- I typically don't report suspicious messages
Rank the following areas by where investment would most improve phishing readiness for your team, from highest to lowest priority.
- Better reporting tools and integrations
- More frequent simulated phishing exercises
- Improved training content and refreshers
- Faster feedback after reports
- Just-in-time guidance in email apps
- Manager reinforcement and team nudges
How long have you been with the company?
- Less than 6 months
- 6–12 months
- 1–3 years
- 3–5 years
- More than 5 years
We'd like to understand more about how you handle suspicious messages. Imagine a senior executive emails you requesting urgent gift card codes. Walk us through what you would do and why.
In the past 60 days, how often did you report suspicious messages through your organization's official reporting channel?
Which of the following actions are recommended when you suspect a message is a phishing attempt? Select all that apply.
- Use the report button or security alias
- Avoid clicking links or opening attachments
- Verify the request through a known, separate channel
- Share the suspicious email in a public chat
- Forward to personal email to check later
- Reply to the sender asking if it's legitimate
- Delete without reporting
What are the biggest things that slow you down or stop you from reporting suspicious messages? Select up to 3.
- Not sure what information to include in a report
- Unsure which channel to use
- Worried about reporting a false alarm
- Too busy or it takes too long
- Reporting tools are hard to find or use
- No feedback after reporting
- I resolve it myself instead of reporting
- None of the above
In which region do you primarily work?
- Americas
- EMEA
- APAC
- Multiple regions
- Other
Thank you for completing this survey. Your responses will be analyzed in aggregate to identify training priorities and strengthen our organization's security posture. All answers are confidential.
In the past 60 days, how often did you check a URL or website address before entering login credentials?
What is your typical work setting?
- Primarily in-office
- Hybrid
- Primarily remote
Which of the following security practices do you currently use on your primary work devices? Select all that apply.
- Multi-factor authentication (MFA)
- Password manager for work accounts
- Automatic OS and browser updates enabled
- Lock screen when stepping away
- VPN on public networks
- Unique passwords for each service
- Phishing-report add-in/button installed
- None of these
含まれる機能
AIによる深掘り
自由回答に合わせてAIが追加で質問し、固定のフォームでは拾えない具体的な内容を引き出します。
注意確認設問
急いだ回答や質の低い回答者を除外する仕組みを標準で備えています。
AIが作成する設問文
文言、設問の順序、条件分岐をAIが調査の目的に合わせて作成します。
自動レポート
回答が集まると、テーマ、引用、わかりやすい要約が自動で作成されます。
他ツールとの比較
ほかのアンケートツールで最も近いテンプレートを調べました。それぞれの優れている点と、このテンプレートがさらに踏み込んでいる点をまとめています。
このテンプレートを選ぶ理由
- Includes adaptive opinion-scale questions on link-hovering, sender verification, and reporting frequency over the past 60 days, plus a ranking exercise on which email cues matter most
- Goes beyond static self-report by including a scenario-based AI follow-up interview asking respondents to imagine and describe handling a suspicious message in their own words
- Captures organizational context (role, tenure, region, work setting) alongside behavioral and confidence metrics, enabling segmentation of risk gaps by group
- Asks a second ranking question on where security investment would most improve readiness, directly supporting prioritization of awareness training spend
Jotform
Cyber Security Risk Assessment Checklist Form TemplateThis is a static checklist-style form aimed at general cyber security risk assessment rather than phishing-specific employee behavior. It's fielding-ready for basic checkbox-driven audits but not built around adaptive questioning or behavioral depth. Useful as a broad IT risk inventory rather than a targeted phishing readiness survey.
優れている点
- Simple checklist format that's quick for respondents to complete
- Drag-and-drop form builder typical of Jotform's platform
- Can be embedded or shared easily as part of broader IT audit workflows
物足りない点
- Static checklist with no adaptive follow-up probing into individual responses
- No mechanism to assess phishing-specific behaviors like reporting speed or link-checking habits
- No transparent scoring methodology or automated report generation described
SurveySparrow
Information Security Risk Assessment QuestionnaireA general information security risk questionnaire rather than a phishing-focused behavioral assessment. It appears to be a fielding-ready template covering broad security risk topics, but lacks the granularity around phishing detection confidence and reporting friction. Best suited for organizations wanting a wide security posture snapshot rather than a targeted awareness-training diagnostic.
優れている点
- Conversational survey format typical of SurveySparrow's UI
- Covers broad information security risk topics beyond just phishing
- Fielding-ready template that can be launched quickly
物足りない点
- No adaptive AI follow-up interviewing to probe inconsistent or interesting answers
- No per-response quality scoring to flag unreliable answers
- Does not appear to include phishing-specific behavioral metrics like time-to-report or reporting channel used
SurveyMonkey
Security Awareness Survey TemplateThis is the closest direct competitor, targeting general security awareness among employees. It's a fielding-ready static template, likely covering knowledge and attitudes, but without behavioral granularity like phishing cue ranking or training-recency segmentation. Good for a quick pulse-check but not designed to surface prioritized investment areas.
優れている点
- Well-established survey platform with strong distribution and analytics tooling
- Template likely covers general security awareness topics accessibly for HR/IT teams
- Easy to customize using SurveyMonkey's standard question library
物足りない点
- Static question set with no adaptive AI-driven follow-up interviewing
- No scenario-based interview component to observe how employees reason through a suspicious message
- No transparent per-response quality scoring or automated gap-prioritization reporting
よくあるご質問
「Employee Phishing Readiness & Security Behavior Assessment」テンプレートにはどのような設問が含まれていますか?
すぐに使える設問が23問含まれており、最初の設問は次のとおりです:「Welcome to the Phishing Readiness & Security Behavior Survey. This survey asks about your experiences with suspicious m…」・「To the best of your knowledge, did you receive any message you considered suspicious (email, SMS/text, or chat) in the p…」・「In the past 60 days, how often did you hover over or inspect links before clicking them in emails or messages?」。すべての設問は上でプレビューでき、自由に編集できます。
このアンケートの回答にはどのくらい時間がかかりますか?
回答者は通常、23問を約10分で回答し終えます。
テンプレートは編集できますか?
はい。公開前であれば、すべての設問、選択肢、順序を編集できます。設問の追加や削除のほか、調査の目的に合わせた作り直しをAIエディターに依頼することもできます。
このテンプレートは無料で使えますか?
はい。エディターで開けば、すぐに編集を始められます。お試しにアカウントは不要で、無料プランでアンケートを公開できます。
公開の準備はできましたか?
このテンプレートをエディターで開いてみてください。最初の回答者が目にする前に、すべてを自由に変更できます。
関連テンプレート
似たテーマのほかの調査もご覧ください。