Following an evaluation of an enterprise security awareness program, a security analyst notes that while annual training completion rates reach 98%, employees rarely notify the security team when encountering suspicious messages. To improve human risk detection, the organization wants to establish a key performance indicator (KPI) that specifically measures proactive employee engagement in threat detection during phishing simulations. Which of the following metrics best evaluates this proactive reporting behavior?
- The phishing reporting rate, measured by the percentage of simulated phishing emails reported by employees using an automated reporting toolCevap
- BThe volume of external spam and phishing attempts filtered out by the email security gateway
- CThe completion percentage of mandatory compliance modules on general security policies
- DThe percentage of user accounts automatically locked out immediately after failing a simulated phishing test
Cevap
The phishing reporting rate, measured by the percentage of simulated phishing emails reported by employees using an automated reporting tool
Tracking the phishing reporting rate using an automated reporting tool measures active user behavior and practical threat detection skills during simulated campaigns. It provides empirical data on how effectively employees act as a human defense layer by identifying and escalating suspected social engineering attacks.
Adım Adım Çözüm
Anahtar Kavram
Security Awareness Program Metrics and Reporting Behavior
Tahmini Süre:1m 15s