Testing employees for security awareness helps organizations identify who understands security protocols and who remains a vulnerability risk. Key methods include phishing simulations, password audits, knowledge assessments, and USB drop tests.
Testing Organizational Security
Wouldn't it be great if we delivered training and the first time people heard something they just automatically understood it, and also followed through with whatever we're asking them to do? Unfortunately we live in the real world and that's not the case, and so what we need to do is test these individuals to make sure that they are doing what we're asking them to do.
Within the organisations that I've worked with, what I've found is that there's going to be some people within the organisation that already know what they need to do. They already are security aware, they're security conscious, they're going to do the right things and understand what they need to do. Then there's going to be people that just don't really know any better, and you're going to instruct them and then they will start doing whatever you're asking them to do and it's not going to be a problem — they just weren't aware of it, and now you've made them aware of it. Then I find that there's certain individuals within the organisation that are going to fall for the same social engineering and tactics over and over again. They're just not understanding what the risk is, and for some reason they keep falling for it.
So we need to create awareness in all of these individuals, and specifically target these individuals. The problem is it takes just that one person to leave the gate open, so to speak, where maybe they are susceptible to social engineering and a scammer calls them and figures out how to leverage them to get into the network. Once they're in the network, then it exposes everything in that network, all the resources within the network. So despite everybody else doing their job and making sure things are secure, it takes just that one person to ruin it for everyone. So somehow we need to identify those within the company that are highest risk, and then be able to figure out how to get them up to speed and make sure that they are secure.
There are quite a few different ways that we can go through this testing to make sure that they are up to speed. One of the ways is just to test them on the material — at the end of delivery, test them to see if they actually understand the information that was delivered during training.
We could also run things like fake phishing campaigns, where we send out fake phishing to our employees to see if they open up the email, if they click a link. Then we can actually track to see how they treat this email, and if they report it or not. So we can start testing our employees by sending them these fake phishing emails, and there's software that will do this for us.
Another thing that I've done before is test the passwords. So I'll take the encrypted password database and I'll run password cracking software against it and see if it cracks the software. If it does crack the software, then we know that they're practising insecure password habits, and we'll ask them to correct that. We'll maybe re-educate them and then ask them to correct that. So that's another way that we could do some testing to see if they are susceptible to certain vulnerabilities or not.
We've also run USB drop tests, where you put software on a USB drive and you leave it around the office. Then if somebody were to take this and plug it into their machine, it would activate some sort of — well, in this case it would be malware we installed on it — it would activate that, and then we'd be able to see who plugged this into their laptop.
TechKnowSurge builds IT and cybersecurity professionals through hands-on, concept-first training built around real understanding — not memorization. Free interactive tools, structured programs, and 25+ years of real-world experience, all in one place.
Explore free tools and programs →