CompTIA CySA+ (CS0-003)Reporting and CommunicationMedium
A security analyst is reviewing the effectiveness of the organization's security awareness training program. The CISO wants to see how well employees are resisting social engineering attacks. Which of the following KPIs would BEST demonstrate the program's success in this area?
- APhishing click-through rate in simulated attacks
- BAverage time to remediate critical vulnerabilities
- CNumber of security incidents reported by employees
- DPercentage of employees completing security training modules
Show answer & explanationAnswer & explanation
Correct answer: A. Phishing click-through rate in simulated attacks
The phishing click-through rate in simulated attacks directly measures employee susceptibility to social engineering, which is a key indicator of the effectiveness of security awareness training in building resistance to such attacks.
Why the other options are wrong
- B. This measures vulnerability management efficiency, unrelated to security awareness training effectiveness.
- C. This measures incident reporting, not directly the resistance to social engineering.
- D. This measures training completion, not the actual behavioral change or resistance to attacks.
Security Awareness Training Effectiveness KPI
A metric used to evaluate the success of security awareness programs in changing employee behavior and improving their ability to identify and resist cyber threats, particularly social engineering attacks.
- Measures behavioral changes, not just completion rates.
- Often uses simulated attacks (e.g., phishing) to test effectiveness.
- Aims to reduce employee susceptibility to common attack vectors.
Memory trick: Awareness means fewer 'clicks' on the 'phishing' hook.