Resilience to phishing and suspicious messages
The Resilience to phishing and suspicious messages survey helps you gauge how prepared your team is for social-engineering attacks. It reveals how often employees run into suspicious emails and messages, how confident they feel spotting them, and how they react. The results show where awareness is strong and where a single click could open the door to an incident.
What the “Resilience to phishing and suspicious messages” survey measures
The survey maps the full phishing exposure chain: how frequently people meet suspicious messages and through which channels (email, corporate messengers, SMS, calls, social networks, collaboration tools), how confident they are at recognizing an attack before clicking a link, opening a file, or entering data, and which red flags they actually notice — urgency and pressure, credential requests, odd sender domains, unexpected attachments, shortened links, typos, or requests to bypass the normal process. It also captures real behavior when something looks off, how clear and convenient the reporting flow is, what stops people from escalating, and which countermeasures they would prioritize.
Who the “Resilience to phishing and suspicious messages” template is for
It fits security and IT teams, CISOs, and awareness-program owners who need a baseline before or after training and phishing simulations. HR and internal-communications leads can use it to shape messaging, while managers of distributed or high-turnover teams get a read on where the human layer is weakest. It works for companies of any size, from a single office to multiple locations and remote staff.
How to adapt the template to your needs
Swap the channel list to match the tools you actually use, and rename “Security/IT” to your real reporting alias or button. If you run phishing simulations, add a question about recent simulation results; for regulated industries, add items on data-handling rules. You can drop the frequency question for very small teams, tighten the red-flag list, or add branching so that people who say they “don’t know where to report” are shown a follow-up about what would make reporting easier.
Questions and answer options
Answer options:
— Almost daily
— Several times a week
— About once a week
— Several times a month
— Less often
— I haven’t noticed any
Answer options:
— Work email
— Corporate messengers/chats
— SMS/text messages
— Calls/voice messages
— Social networks/public messengers
— Collaboration tools (tasks, documents, tickets)
Answer options:
— Urgency and pressure (“urgent”, “otherwise your access will be blocked”)
— A request to enter a login/password/verification code
— A suspicious sender address or domain
— Unexpected attachments or a request to download a file
— The link leads to an unusual or shortened address
— Typos, errors, or odd wording
— A request to bypass the usual process (pay, change bank details, share access)
— The message topic doesn’t match your role/tasks
Answer options:
— don’t open attachments or click links
— I check the sender and the link address (domain/URL)
— I verify the request via another channel (message/call the sender)
— I report it to Security/IT via the official channel
— I mark it as spam/phishing (if that option exists)
— delete the message
— I ask colleagues/manager what to do
Answer options:
— I don’t know where/how to report
— It takes too long / is too complicated to file a report
— I’m not sure it’s really phishing
— I’m afraid it will be a “false alarm”
— I don’t have time to look into it
— I don’t see results or feedback after reporting
— There is no convenient button/tool to submit a report
Answer options:
— A short guide with phishing examples and “what to do”
— A “Report phishing” button in email/messenger
— Fast feedback on reported messages (status/result)
— Regular short trainings/simulations (5–10 minutes)
— A clear single reporting channel (chat/form) and promoting it
— Additional technical filters and warnings for links/attachments
— Clear rules: what data must not be shared and how to act on such requests