Open cardosec

Case 2F8D78 · GRC · L3 Applied

Security Awareness Metrics

Practise as: Explain it
  1. 01 What is it?
  2. 02 How is it abused?
  3. 03 How do you stop it?
What a strong answer covers

Try it out loud first. Then check yourself:

  1. Phish click rate alone is gameable by template difficulty; report rate and time-to-first-report matter more.
  2. Compare reporting rate with click rate per campaign (more reporters than clickers is good), tracked by department over time.
  3. Tie to real outcomes: real phish reported vs missed, credential resets after compromise, SOC triage time.
  4. Completion percentage of training is a compliance metric, not a behavior metric; report both, trust behavior.
  5. Segment high-risk roles (finance, execs, helpdesk) with targeted simulations like BEC and MFA-reset vishing.

If the interviewer pushes back

  • How would you show the board that awareness spending reduced risk rather than just moved a vanity metric?

cardosec draws a security topic and gives you a clock: explain it out loud with no notes, then see what you covered and what you missed. Free during early access.