Todos os modelos
Operations & Data

Employee Phishing Readiness & Security Behavior Assessment

Measures employee phishing detection confidence, reporting behavior, and security practices to identify organizational risk gaps and prioritize awareness training investments.

Perguntas de exemplo

Uma prévia do que há no modelo. Todas as perguntas podem ser editadas antes de publicar.

23 perguntas · ~10 min
Q01
Mensagem

Welcome to the Phishing Readiness & Security Behavior Survey. This survey asks about your experiences with suspicious messages, your security habits, and your ideas for improvement. It should take approximately 6–8 minutes to complete. Your participation is completely voluntary and you may stop at any time. There are no right or wrong answers—we are interested in your honest experiences and opinions. All responses are confidential and will be reported only in aggregate. Please click 'Next' to begin.

Q02
Múltipla escolha

To the best of your knowledge, did you receive any message you considered suspicious (email, SMS/text, or chat) in the past 30 days?

  • Yes
  • No
  • Not sure
Q03
Escala de opinião

In the past 60 days, how often did you hover over or inspect links before clicking them in emails or messages?

Escala: 15
Mín:NeverMáx:Always
Q04
Escala de opinião

How confident are you that you could handle a suspicious message appropriately?

Escala: 15
Mín:Not at all confidentMáx:Extremely confident
Q05
Múltipla escolha

What is your most common way to report a suspected phishing message?

  • Report Phish button/add-in in email
  • Security email alias
  • IT helpdesk ticket
  • Messaging app bot
  • Tell my manager
  • I don't report them
  • I'm not sure how to report
Q06
Lista suspensa

When did you last complete security awareness training?

  • Within the last 30 days
  • 31–90 days ago
  • 3–6 months ago
  • More than 6 months ago
  • I have not completed it
  • I don't remember
Q07
Lista suspensa

What is your primary role?

  • Engineering/IT
  • Operations
  • Finance/Accounting
  • Sales/Marketing
  • HR/People
  • Legal/Compliance
  • Product/Design
  • Customer Support/Success
  • Executive/Leadership
  • Other
Q08
Texto longo

Based on your responses in this survey, please share any additional thoughts about what would help you handle phishing attempts more effectively.

Q09
Lista suspensa

Approximately how many suspicious or phishing-like messages did you notice in the past 30 days?

  • 1–2
  • 3–5
  • 6–10
  • 11–20
  • More than 20
Q10
Escala de opinião

In the past 60 days, how often did you verify the sender's identity before acting on a request (e.g., checking the email address or calling the person)?

Escala: 15
Mín:NeverMáx:Always
Q11
Ordenação

When judging whether an email is legitimate, rank these cues from most to least important to you.

  1. Sender domain and address
  2. Link URL on hover
  3. Urgent or threatening tone
  4. Unexpected attachments or requests for credentials
Arraste para ordenar
Q12
Lista suspensa

When you do report a suspicious message, approximately how long does it typically take from the moment you notice it?

  • Within 5 minutes
  • 5–30 minutes
  • 30–60 minutes
  • 1–4 hours
  • More than 4 hours
  • I typically don't report suspicious messages
Q13
Ordenação

Rank the following areas by where investment would most improve phishing readiness for your team, from highest to lowest priority.

  1. Better reporting tools and integrations
  2. More frequent simulated phishing exercises
  3. Improved training content and refreshers
  4. Faster feedback after reports
  5. Just-in-time guidance in email apps
  6. Manager reinforcement and team nudges
Arraste para ordenar
Q14
Lista suspensa

How long have you been with the company?

  • Less than 6 months
  • 6–12 months
  • 1–3 years
  • 3–5 years
  • More than 5 years
Q15
Entrevista com IA

We'd like to understand more about how you handle suspicious messages. Imagine a senior executive emails you requesting urgent gift card codes. Walk us through what you would do and why.

Q16
Escala de opinião

In the past 60 days, how often did you report suspicious messages through your organization's official reporting channel?

Escala: 15
Mín:NeverMáx:Always
Q17
Múltipla escolha

Which of the following actions are recommended when you suspect a message is a phishing attempt? Select all that apply.

  • Use the report button or security alias
  • Avoid clicking links or opening attachments
  • Verify the request through a known, separate channel
  • Share the suspicious email in a public chat
  • Forward to personal email to check later
  • Reply to the sender asking if it's legitimate
  • Delete without reporting
Q18
Múltipla escolha

What are the biggest things that slow you down or stop you from reporting suspicious messages? Select up to 3.

  • Not sure what information to include in a report
  • Unsure which channel to use
  • Worried about reporting a false alarm
  • Too busy or it takes too long
  • Reporting tools are hard to find or use
  • No feedback after reporting
  • I resolve it myself instead of reporting
  • None of the above
Q19
Lista suspensa

In which region do you primarily work?

  • Americas
  • EMEA
  • APAC
  • Multiple regions
  • Other
Q20
Mensagem

Thank you for completing this survey. Your responses will be analyzed in aggregate to identify training priorities and strengthen our organization's security posture. All answers are confidential.

Q21
Escala de opinião

In the past 60 days, how often did you check a URL or website address before entering login credentials?

Escala: 15
Mín:NeverMáx:Always
Q22
Lista suspensa

What is your typical work setting?

  • Primarily in-office
  • Hybrid
  • Primarily remote
Q23
Múltipla escolha

Which of the following security practices do you currently use on your primary work devices? Select all that apply.

  • Multi-factor authentication (MFA)
  • Password manager for work accounts
  • Automatic OS and browser updates enabled
  • Lock screen when stepping away
  • VPN on public networks
  • Unique passwords for each service
  • Phishing-report add-in/button installed
  • None of these

O que está incluído

  • Acompanhamento com IA

    Sondagens adaptativas nas respostas abertas que revelam detalhes que um formulário estático deixaria passar.

  • Verificações de atenção

    Proteções integradas contra respostas apressadas e participantes de baixa qualidade.

  • Textos escritos por IA

    Redação, ordem e ramificações escritas pela IA, ajustadas ao seu objetivo de pesquisa.

  • Relatório automático

    Temas, citações e um resumo em linguagem simples se escrevem sozinhos assim que as respostas chegam.

Como se compara

Analisamos os modelos mais parecidos de outras ferramentas de pesquisa. Veja o que elas fazem bem e onde este modelo vai além.

Por que este modelo

  • Includes adaptive opinion-scale questions on link-hovering, sender verification, and reporting frequency over the past 60 days, plus a ranking exercise on which email cues matter most
  • Goes beyond static self-report by including a scenario-based AI follow-up interview asking respondents to imagine and describe handling a suspicious message in their own words
  • Captures organizational context (role, tenure, region, work setting) alongside behavioral and confidence metrics, enabling segmentation of risk gaps by group
  • Asks a second ranking question on where security investment would most improve readiness, directly supporting prioritization of awareness training spend

Jotform

Cyber Security Risk Assessment Checklist Form Template

This is a static checklist-style form aimed at general cyber security risk assessment rather than phishing-specific employee behavior. It's fielding-ready for basic checkbox-driven audits but not built around adaptive questioning or behavioral depth. Useful as a broad IT risk inventory rather than a targeted phishing readiness survey.

O que faz bem

  • Simple checklist format that's quick for respondents to complete
  • Drag-and-drop form builder typical of Jotform's platform
  • Can be embedded or shared easily as part of broader IT audit workflows

Onde deixa a desejar

  • Static checklist with no adaptive follow-up probing into individual responses
  • No mechanism to assess phishing-specific behaviors like reporting speed or link-checking habits
  • No transparent scoring methodology or automated report generation described

SurveySparrow

Information Security Risk Assessment Questionnaire

A general information security risk questionnaire rather than a phishing-focused behavioral assessment. It appears to be a fielding-ready template covering broad security risk topics, but lacks the granularity around phishing detection confidence and reporting friction. Best suited for organizations wanting a wide security posture snapshot rather than a targeted awareness-training diagnostic.

O que faz bem

  • Conversational survey format typical of SurveySparrow's UI
  • Covers broad information security risk topics beyond just phishing
  • Fielding-ready template that can be launched quickly

Onde deixa a desejar

  • No adaptive AI follow-up interviewing to probe inconsistent or interesting answers
  • No per-response quality scoring to flag unreliable answers
  • Does not appear to include phishing-specific behavioral metrics like time-to-report or reporting channel used

SurveyMonkey

Security Awareness Survey Template

This is the closest direct competitor, targeting general security awareness among employees. It's a fielding-ready static template, likely covering knowledge and attitudes, but without behavioral granularity like phishing cue ranking or training-recency segmentation. Good for a quick pulse-check but not designed to surface prioritized investment areas.

O que faz bem

  • Well-established survey platform with strong distribution and analytics tooling
  • Template likely covers general security awareness topics accessibly for HR/IT teams
  • Easy to customize using SurveyMonkey's standard question library

Onde deixa a desejar

  • Static question set with no adaptive AI-driven follow-up interviewing
  • No scenario-based interview component to observe how employees reason through a suspicious message
  • No transparent per-response quality scoring or automated gap-prioritization reporting

Perguntas frequentes

Quais perguntas estão no modelo “Employee Phishing Readiness & Security Behavior Assessment”?

O modelo inclui 23 perguntas prontas para usar, começando por: “Welcome to the Phishing Readiness & Security Behavior Survey. This survey asks about your experiences with suspicious m…” · “To the best of your knowledge, did you receive any message you considered suspicious (email, SMS/text, or chat) in the p…” · “In the past 60 days, how often did you hover over or inspect links before clicking them in emails or messages?”. O conjunto completo aparece acima e todas as perguntas podem ser editadas.

Quanto tempo leva para responder a esta pesquisa?

Os participantes normalmente terminam as 23 perguntas em cerca de 10 minutos.

Posso personalizar este modelo?

Sim: cada pergunta, cada opção de resposta e a ordem podem ser editadas antes de publicar. Você pode adicionar ou remover perguntas, ou pedir ao editor com IA para refazer a pesquisa em torno do seu objetivo.

Este modelo é gratuito?

Sim. Abra no editor e comece a personalizar agora: não é preciso criar conta para testar, e o plano gratuito cobre a publicação da sua pesquisa.

Pronto para publicar?

Abra este modelo no editor. Tudo é seu para mudar antes de o primeiro participante ver.

Modelos relacionados

Mais estudos sobre temas semelhantes.

Ver todos
Operations & Data

Pesquisa sobre Clima de Segurança e Comunicação nas Operações de E-commerce

Mede comportamentos de segurança, confiança para comunicar ocorrências, riscos ambientais e apoio da liderança nas equipes de fulfillment de e-commerce, a fim de identificar prioridades específicas para redução de riscos.

Ver modelo
Operations & Data

Pesquisa sobre Conscientização em Segurança e Comportamento diante de Phishing

Mede o quão bem os colaboradores reconhecem ameaças, seguem a política de segurança e realmente se comportam quando algo parece suspeito — não apenas quais treinamentos eles fizeram. Uma entrevista de acompanhamento com IA explora um momento real e recente de hesitação ou dúvida para revelar as lacunas que as auditorias de política deixam passar.

Ver modelo
Operations & Data

Pesquisa de Eficácia e Feedback de Simulação de Phishing

Mede as percepções dos colaboradores sobre o realismo das simulações de phishing, respostas comportamentais, mudanças de confiança e preferências de treinamento para ajudar as equipes de segurança a otimizar seus programas de conscientização.

Ver modelo
Operations & Data

Pesquisa de Conscientização e Comportamento em Segurança da Informação dos Funcionários

Mede como os funcionários realmente lidam com senhas, autenticação multifator, atualizações e mensagens suspeitas no dia a dia — não apenas o que sabem em teoria. Desenvolvida para equipes de TI e segurança que auditam programas de conscientização, com um acompanhamento por IA que reconstrói um incidente ou quase-incidente real em vez de um hipotético.

Ver modelo
Operations & Data

Avaliação de Engajamento dos Colaboradores e Cultura Organizacional

Mede o engajamento dos colaboradores, a segurança psicológica, o apoio e a satisfação no trabalho para identificar os principais fatores de retenção e da saúde da cultura organizacional. Desenvolvida para implementação em toda a organização, com relatórios anônimos e agregados.

Ver modelo
Operations & Data

Avaliação de Cultura Organizacional e Confiança dos Colaboradores

Mede como os colaboradores realmente vivenciam os valores declarados da empresa no dia a dia — confiança, segurança psicológica, reconhecimento e o exemplo dado pelos gestores — além de uma entrevista de acompanhamento com IA que revela os momentos específicos por trás de notas baixas de confiança ou segurança. Desenvolvida para equipes de RH, People Ops e liderança que realizam auditorias de cultura anuais ou de pulso.

Ver modelo