모든 템플릿

Red Team Program Effectiveness Assessment

Collects structured stakeholder feedback on red-team risk coverage, report quality, and remediation follow-through to identify actionable program improvements across security, engineering, and leadership functions.

샘플 질문

템플릿에 포함된 내용을 미리 확인해 보세요. 모든 질문은 설문 공개 전에 자유롭게 수정할 수 있습니다.

질문 33개 · 약 14분
Q01
메시지

Welcome! This survey (approximately 14 minutes) asks about your experience with our red-team program over the past 12 months. Your participation is voluntary, and you may stop at any time. There are no right or wrong answers—we want your honest perspective based on direct experience. All responses are confidential and will be reported only in aggregate to improve the program.

Q02
객관식

Which best describes your primary involvement with red-team exercises in the past 12 months?

  • Consume findings to make decisions
  • Implement technical fixes
  • Defensive operations / blue team
  • Product or operations stakeholder
  • Compliance / governance
  • Executive / leadership sponsor
  • Other
Q03
메시지

The following questions ask how well red-team exercises covered key areas in the past 12 months. If you lack direct experience with an area, select the midpoint.

Q04
드롭다운

What reporting cadence do you prefer for red-team results and trends?

  • After each exercise
  • Quarterly rollup
  • Biannual
  • Annual
  • On-demand only
  • Not sure
Q05
의견 척도

In your experience, how quickly are teams typically able to act on red-team findings after report delivery?

척도: 17
최소:Very slowly최대:Very quickly
Q06
의견 척도

How would you rate the overall maturity of our red-teaming program today?

척도: 15
최소:Very early stage최대:Best-in-class
Q07
장문형

Based on your responses in this survey, please share any additional thoughts or suggestions about the red-team program that we haven't covered.

Q08
객관식

Which best describes your primary organizational function?

  • Engineering / Development
  • Security (including blue team)
  • IT / Infrastructure
  • Product / Operations
  • Compliance / Risk / GRC
  • Executive / Leadership
  • Other
Q09
메시지

Thank you for your time. Your input directly informs how we improve red-team coverage, reporting, and overall program impact.

Q10
드롭다운

Approximately how many red-team exercises have you directly engaged with in the past 12 months?

  • 0 (aware but not directly engaged)
  • 1–2
  • 3–5
  • 6–10
  • More than 10
Q11
의견 척도

How well did red-team exercises cover application-layer security (web, mobile, APIs)?

척도: 15
최소:Not at all well최대:Extremely well
Q12
순위 매기기

Please rank the following elements of a red-team report from most to least valuable to your work.

  1. Executive summary with business impact
  2. Attack narrative / timeline
  3. Evidence and impact detail
  4. Reproduction steps / proof-of-concept
  5. Exploitability / likelihood rationale
  6. Prioritized remediation plan
드래그하여 순위 지정
Q13
객관식

What most commonly hinders follow-through on red-team findings? (Select up to 3)

  • Limited engineering bandwidth
  • Disagreement on risk or severity
  • Unclear ownership of findings
  • Tooling or visibility gaps
  • Vendor or third-party dependency
  • Competing priorities
  • Budget constraints
  • Other (please specify)
Q14
장문형

If you could change one thing about the red-team program for the next cycle, what would it be?

Q15
드롭다운

What is your role level?

  • Individual contributor
  • Manager
  • Senior manager
  • Director
  • VP / C-level
  • Other / Prefer not to say
Q16
의견 척도

How well did red-team exercises cover infrastructure and cloud environments?

척도: 15
최소:Not at all well최대:Extremely well
Q17
의견 척도

Red-team reports are delivered in a timely manner relative to exercise completion.

척도: 17
최소:Strongly disagree최대:Strongly agree
Q18
장문형

Please share one example from the past 12 months where a red-team finding led to a meaningful improvement or fix. If none comes to mind, you may skip this question.

Q19
AI 인터뷰

You've shared thoughts on improving the red-team program. Could you elaborate on what specific changes would have the greatest impact on your team's security posture?

Q20
드롭다운

How long have you been in your current role at this organization?

  • Less than 1 year
  • 1–2 years
  • 3–5 years
  • 6–10 years
  • More than 10 years
Q21
의견 척도

How well did red-team exercises cover identity and access management (authentication/authorization)?

척도: 15
최소:Not at all well최대:Extremely well
Q22
의견 척도

Red-team reports clearly communicate business impact alongside technical findings.

척도: 17
최소:Strongly disagree최대:Strongly agree
Q23
드롭다운

Where are you primarily located?

  • Americas
  • EMEA
  • APAC
  • Prefer not to say
Q24
의견 척도

How well did red-team exercises cover third-party and supply-chain risks?

척도: 15
최소:Not at all well최대:Extremely well
Q25
의견 척도

Remediation recommendations in red-team reports are specific and actionable.

척도: 17
최소:Strongly disagree최대:Strongly agree
Q26
의견 척도

How well did red-team exercises cover social engineering and human factors?

척도: 15
최소:Not at all well최대:Extremely well
Q27
의견 척도

Red-team reports contain the right level of technical detail for my needs.

척도: 17
최소:Strongly disagree최대:Strongly agree
Q28
의견 척도

How well did red-team exercises cover physical security?

척도: 15
최소:Not at all well최대:Extremely well
Q29
의견 척도

Findings in red-team reports are prioritized effectively by risk severity.

척도: 17
최소:Strongly disagree최대:Strongly agree
Q30
의견 척도

Overall, how confident are you that red-teaming is currently focused on our highest-risk areas?

척도: 15
최소:Not at all confident최대:Extremely confident
Q31
의견 척도

Overall, how valuable are red-team findings to your work?

척도: 15
최소:Not at all valuable최대:Extremely valuable
Q32
순위 매기기

Please rank the following areas by where additional red-team focus would most reduce organizational risk over the next 6 months (top = highest priority).

  1. Application layer (web, mobile, APIs)
  2. Infrastructure and cloud
  3. Identity and access management
  4. Third parties and supply chain
  5. Social engineering and human factors
  6. Physical security
드래그하여 순위 지정
Q33
객관식

In your view, which specific areas are most under-tested relative to their potential business impact? (Select up to 3)

  • Crown-jewel applications
  • Secrets management
  • Privilege escalation paths
  • Data exfiltration routes
  • Human factors / social engineering
  • Third-party integrations
  • Cloud control plane
  • Lateral movement
  • Other (please specify)

포함된 기능

  • AI 후속 질문

    정형화된 설문이 놓치는 세부 내용을, 주관식 답변에 맞춰 AI가 심층 질문으로 끌어냅니다.

  • 주의력 확인 장치

    성의 없는 답변과 저품질 응답자를 걸러내는 내장 안전장치입니다.

  • AI가 작성한 문안

    문구, 질문 순서, 분기 로직까지 AI가 연구 목표에 맞춰 작성합니다.

  • 자동 리포트

    응답이 모이면 주요 주제, 인용문, 이해하기 쉬운 요약이 자동으로 작성됩니다.

설문을 공개할 준비가 되셨나요?

이 템플릿을 편집기에서 열어 보세요. 첫 응답자가 보기 전에 모든 부분을 원하는 대로 바꿀 수 있습니다.