Security Awareness Survey Scores
Measurement of employee security knowledge and attitudes
Current Value
87.3%
+5.8% from previous period
Industry average: 78%
Calculation Method
Average score from security awareness assessments and simulated phishing campaigns, tracked across departments and roles
Significance
This KPI measures how well employees understand security best practices and their likelihood of making secure decisions, indicating the effectiveness of your security awareness program.
Definition
Security Awareness Survey Scores measure employee knowledge, attitudes, and behaviors related to cybersecurity. This KPI evaluates the effectiveness of security awareness training by assessing how well employees understand security best practices, recognize threats, and make security-conscious decisions.
Significance
Employees remain the primary target for cyberattacks, with phishing and social engineering involved in over 85% of security breaches. Even the strongest technical controls can be bypassed when users make insecure decisions or fall victim to manipulation.
This KPI helps organizations assess the human element of their security program, identifying knowledge gaps and measuring improvements in security awareness over time. It also helps identify departments or roles that may require additional targeted training.
Calculation Method
This metric is typically calculated from multiple sources:
- Knowledge assessments: Multiple-choice questionnaires testing security knowledge
- Simulated phishing results: Success rates in avoiding simulated phishing campaigns
- Security behavior surveys: Self-reported security practices and attitudes
- Observation exercises: Structured observations of security behaviors (e.g., clean desk audits)
Scores are typically weighted and combined into an overall security awareness score, with greater weight given to demonstrated behaviors over theoretical knowledge.
Current Performance
Our security awareness scores have improved from 81.5% to 87.3% over the past 12 months.
• Knowledge assessment average: 91.2%
• Phishing simulation success: 84.7%
• Security behavior compliance: 86.2%
• Department with highest score: IT (94.8%)
• Department with lowest score: Sales (79.6%)
Benchmark
Industry average: 78% awareness score
Best practice target: >85% overall awareness score; >90% for high-risk roles