An organization recently transitioned from mandatory annual security awareness video training to monthly role-based microlearning simulations tailored to high-risk personnel. The Chief Information Security Officer (CISO) wants to evaluate whether this new program effectively mitigates human risk rather than just satisfying compliance requirements. Which of the following metrics provides the most direct evidence of behavioral risk reduction among staff?
- An increase in the prompt reporting rate of simulated phishing emails paired with a decrease in credential submission rates on landing pagesAnswer
- BA 100% completion rate of monthly training modules verified by automated Learning Management System attendance logs
- CThe successful deployment of automated network access control policies to isolate unauthorized personal devices
- DA reduction in the total volume of spam messages delivered to user inboxes by email gateway filters
Answer
An increase in the prompt reporting rate of simulated phishing emails paired with a decrease in credential submission rates on landing pages
The correct response highlights metrics that directly observe employee actions when presented with a simulated attack. Increasing user reporting of suspicious emails while decreasing actions that compromise credentials demonstrates improved security culture and active mitigation of human risk.
Step-by-Step Solution
Key Concept
Measuring Security Awareness Effectiveness and Human Risk Metrics