Case 2F8D78 · GRC · L3 Applied
Security Awareness Metrics
Practise as: Explain it
- 01 What is it?
- 02 How is it abused?
- 03 How do you stop it?
What a strong answer covers
Try it out loud first. Then check yourself:
- Phish click rate alone is gameable by template difficulty; report rate and time-to-first-report matter more.
- Compare reporting rate with click rate per campaign (more reporters than clickers is good), tracked by department over time.
- Tie to real outcomes: real phish reported vs missed, credential resets after compromise, SOC triage time.
- Completion percentage of training is a compliance metric, not a behavior metric; report both, trust behavior.
- Segment high-risk roles (finance, execs, helpdesk) with targeted simulations like BEC and MFA-reset vishing.
If the interviewer pushes back
- How would you show the board that awareness spending reduced risk rather than just moved a vanity metric?
cardosec draws a security topic and gives you a clock: explain it out loud with no notes, then see what you covered and what you missed. Free during early access.