Security Awareness Survey Scores

Measurement of employee security knowledge and attitudes

Current Value

87.3%

+5.8% from previous period

Industry average: 78%

Calculation Method

Average score from security awareness assessments and simulated phishing campaigns, tracked across departments and roles

Significance

This KPI measures how well employees understand security best practices and their likelihood of making secure decisions, indicating the effectiveness of your security awareness program.

Definition

Security Awareness Survey Scores measure employee knowledge, attitudes, and behaviors related to cybersecurity. This KPI evaluates the effectiveness of security awareness training by assessing how well employees understand security best practices, recognize threats, and make security-conscious decisions.

Significance

Employees remain the primary target for cyberattacks, with phishing and social engineering involved in over 85% of security breaches. Even the strongest technical controls can be bypassed when users make insecure decisions or fall victim to manipulation.

This KPI helps organizations assess the human element of their security program, identifying knowledge gaps and measuring improvements in security awareness over time. It also helps identify departments or roles that may require additional targeted training.

Calculation Method

This metric is typically calculated from multiple sources:

  • Knowledge assessments: Multiple-choice questionnaires testing security knowledge
  • Simulated phishing results: Success rates in avoiding simulated phishing campaigns
  • Security behavior surveys: Self-reported security practices and attitudes
  • Observation exercises: Structured observations of security behaviors (e.g., clean desk audits)

Scores are typically weighted and combined into an overall security awareness score, with greater weight given to demonstrated behaviors over theoretical knowledge.

Current Performance

Our security awareness scores have improved from 81.5% to 87.3% over the past 12 months.
• Knowledge assessment average: 91.2%
• Phishing simulation success: 84.7%
• Security behavior compliance: 86.2%
• Department with highest score: IT (94.8%)
• Department with lowest score: Sales (79.6%)

Benchmark

Industry average: 78% awareness score

Best practice target: >85% overall awareness score; >90% for high-risk roles

Related KPIs

Phishing Simulation Failure
Security Training Completion
Security Incident Rate