TechKnowSurge
CompTIA Security+ 5.6 EC-Council CEH 4.2 ISC2 CISSP 1.12 NIST 800-53 AT-2 NIST CSF PR.AT-01
VideoSecurityFree

Awareness Testing

Testing employees for security awareness helps organizations identify who understands security protocols and who remains a vulnerability risk. Key methods include phishing simulations, password audits, knowledge assessments, and USB drop tests.

Complete this video to capture a CTF flag worth 1 point.

About this video

Security awareness training is only effective when paired with consistent testing to verify that employees are actually applying what they have learned. Within any organization, staff tend to fall into three groups: those who are already security-conscious, those who simply lacked awareness and correct their behavior once trained, and those who repeatedly fall for the same social engineering tactics regardless of prior instruction. That last group represents the most significant organizational risk, because a single employee who can be manipulated by a scammer or phishing attempt can expose the entire network, regardless of how well everyone else performs. To identify and address these vulnerabilities, several testing approaches are commonly used in practice. Simulated phishing campaigns send realistic but fake phishing emails to employees and track whether they open attachments, click links, or report the message to the security team. Password auditing involves running cracking tools against the encrypted password database to identify accounts with weak credentials, followed by targeted re-education for those users. USB drop tests involve leaving drives loaded with tracking software in common areas to see whether employees plug unknown devices into company machines. Together, these methods give security teams a clearer picture of where human risk is concentrated and which individuals need additional training or intervention.

What you'll learn

What's covered

Testing Organizational Security

Aligned to

CompTIA Security+
5.6 Given a scenario, implement security awareness practices.
EC-Council CEH
4.2 Social Engineering
ISC2 CISSP
1.12 Establish and maintain a security awareness, education, and training program
NIST 800-53
AT-2 Literacy Training and Awareness
NIST CSF
PR.AT-01 Personnel are provided with awareness and training so that they possess the knowledge and skills to perform general tasks with cybersecurity risks in mind.

Key terms

Phishing
A social engineering attack that uses deceptive emails or messages to trick users into revealing sensitive information.
Social Engineering
A manipulation technique that exploits human psychology to trick individuals into revealing confidential information.
Vulnerability
A weakness in a system, application, or process that can be exploited by a threat actor.
Phishing Simulation
A controlled exercise that sends fake phishing emails to employees to test and reinforce their ability to recognize and report phishing attempts.
Password Audit
The process of running password-cracking tools against an organization's encrypted password database to identify weak or insecure passwords.
USB Drop Test
A physical security test in which USB drives loaded with tracking or simulated malware are left in common areas to see if employees plug them into their devices.
Security Awareness Training
An ongoing program that educates employees about cybersecurity threats, safe practices, and organizational policies to reduce human-based risk. Effective training covers topics like phishing recognition, password hygiene, and social engineering.

Topics

Security Awareness Phishing Simulations Social Engineering Password Audits Cybersecurity Insider Threats

Transcript

Why We Test People

Wouldn't it be great if we delivered training and the first time people heard something they just automatically understood it, and also followed through with whatever we're asking them to do? Unfortunately we live in the real world and that's not the case, and so what we need to do is test these individuals to make sure that they are doing what we're asking them to do.

Within the organisations that I've worked with, what I've found is that there's going to be some people within the organisation that already know what they need to do. They already are security aware, they're security conscious, they're going to do the right things and understand what they need to do. Then there's going to be people that just don't really know any better, and you're going to instruct them and then they will start doing whatever you're asking them to do and it's not going to be a problem — they just weren't aware of it, and now you've made them aware of it. Then I find that there's certain individuals within the organisation that are going to fall for the same social engineering and tactics over and over again. They're just not understanding what the risk is, and for some reason they keep falling for it.

So we need to create awareness in all of these individuals, and specifically target these individuals. The problem is it takes just that one person to leave the gate open, so to speak, where maybe they are susceptible to social engineering and a scammer calls them and figures out how to leverage them to get into the network. Once they're in the network, then it exposes everything in that network, all the resources within the network. So despite everybody else doing their job and making sure things are secure, it takes just that one person to ruin it for everyone. So somehow we need to identify those within the company that are highest risk, and then be able to figure out how to get them up to speed and make sure that they are secure.

Ways to Test

There are quite a few different ways that we can go through this testing to make sure that they are up to speed. One of the ways is just to test them on the material — at the end of delivery, test them to see if they actually understand the information that was delivered during training.

We could also run things like fake phishing campaigns, where we send out fake phishing to our employees to see if they open up the email, if they click a link. Then we can actually track to see how they treat this email, and if they report it or not. So we can start testing our employees by sending them these fake phishing emails, and there's software that will do this for us.

Another thing that I've done before is test the passwords. So I'll take the encrypted password database and I'll run password cracking software against it and see if it cracks the software. If it does crack the software, then we know that they're practising insecure password habits, and we'll ask them to correct that. We'll maybe re-educate them and then ask them to correct that. So that's another way that we could do some testing to see if they are susceptible to certain vulnerabilities or not.

We've also run USB drop tests, where you put software on a USB drive and you leave it around the office. Then if somebody were to take this and plug it into their machine, it would activate some sort of — well, in this case it would be malware we installed on it — it would activate that, and then we'd be able to see who plugged this into their laptop.

About TechKnowSurge

TechKnowSurge builds IT and cybersecurity professionals through hands-on, concept-first training built around real understanding — not memorization. Free interactive tools, structured programs, and 25+ years of real-world experience, all in one place.

Explore free tools and programs →