Resilience to phishing and suspicious messages

This survey assesses employees’ resilience to phishing and suspicious messages: how often they encounter such attempts, how confident they are in recognizing risks, what actions they take, how clear and convenient the reporting/escalation process is, and which measures would best reduce risk (training, prompts, tools, communications).

The Resilience to phishing and suspicious messages survey helps you gauge how prepared your team is for social-engineering attacks. It reveals how often employees run into suspicious emails and messages, how confident they feel spotting them, and how they react. The results show where awareness is strong and where a single click could open the door to an incident.

What the “Resilience to phishing and suspicious messages” survey measures

The survey maps the full phishing exposure chain: how frequently people meet suspicious messages and through which channels (email, corporate messengers, SMS, calls, social networks, collaboration tools), how confident they are at recognizing an attack before clicking a link, opening a file, or entering data, and which red flags they actually notice — urgency and pressure, credential requests, odd sender domains, unexpected attachments, shortened links, typos, or requests to bypass the normal process. It also captures real behavior when something looks off, how clear and convenient the reporting flow is, what stops people from escalating, and which countermeasures they would prioritize.

Who the “Resilience to phishing and suspicious messages” template is for

It fits security and IT teams, CISOs, and awareness-program owners who need a baseline before or after training and phishing simulations. HR and internal-communications leads can use it to shape messaging, while managers of distributed or high-turnover teams get a read on where the human layer is weakest. It works for companies of any size, from a single office to multiple locations and remote staff.

How to adapt the template to your needs

Swap the channel list to match the tools you actually use, and rename “Security/IT” to your real reporting alias or button. If you run phishing simulations, add a question about recent simulation results; for regulated industries, add items on data-handling rules. You can drop the frequency question for very small teams, tighten the red-flag list, or add branching so that people who say they “don’t know where to report” are shown a follow-up about what would make reporting easier.

Questions and answer options

Question type: single choice.
Answer options:
— Almost daily
— Several times a week
— About once a week
— Several times a month
— Less often
— I haven’t noticed any
Question type: multiple choice.
Answer options:
— Work email
— Corporate messengers/chats
— SMS/text messages
— Calls/voice messages
— Social networks/public messengers
— Collaboration tools (tasks, documents, tickets)
Question type: multiple choice.
Answer options:
— Urgency and pressure (“urgent”, “otherwise your access will be blocked”)
— A request to enter a login/password/verification code
— A suspicious sender address or domain
— Unexpected attachments or a request to download a file
— The link leads to an unusual or shortened address
— Typos, errors, or odd wording
— A request to bypass the usual process (pay, change bank details, share access)
— The message topic doesn’t match your role/tasks
Question type: multiple choice.
Answer options:
— don’t open attachments or click links
— I check the sender and the link address (domain/URL)
— I verify the request via another channel (message/call the sender)
— I report it to Security/IT via the official channel
— I mark it as spam/phishing (if that option exists)
— delete the message
— I ask colleagues/manager what to do
Question type: multiple choice.
Answer options:
— I don’t know where/how to report
— It takes too long / is too complicated to file a report
— I’m not sure it’s really phishing
— I’m afraid it will be a “false alarm”
— I don’t have time to look into it
— I don’t see results or feedback after reporting
— There is no convenient button/tool to submit a report
Question type: ranking.
Answer options:
— A short guide with phishing examples and “what to do”
— A “Report phishing” button in email/messenger
— Fast feedback on reported messages (status/result)
— Regular short trainings/simulations (5–10 minutes)
— A clear single reporting channel (chat/form) and promoting it
— Additional technical filters and warnings for links/attachments
— Clear rules: what data must not be shared and how to act on such requests

Similar survey templates

Frequently asked questions

It lists the signals employees say tip them off: urgency and pressure, requests for logins, passwords, or verification codes, suspicious sender addresses and domains, unexpected attachments, unusual or shortened links, typos and odd wording, requests to bypass the usual process, and topics that don’t match the person’s role.
Yes. One question specifically asks in which channels suspicious messages show up — work email, corporate messengers and chats, SMS, calls and voice messages, social networks, and collaboration tools like task or ticket systems — so you see where attacks land, not just in the inbox.
A rating question measures how clear and convenient reporting feels, and a separate question surfaces what blocks people: not knowing where to report, the process being too slow, uncertainty about whether it’s really phishing, fear of a false alarm, no time, no feedback after reporting, or the lack of a convenient report button.
The final question asks employees to pick the measures to implement first — a phishing guide, a “Report phishing” button, fast feedback on reports, short regular simulations, a single clear reporting channel, technical filters, or clear data-sharing rules — so you can align spending with what staff would actually use.