View/Export Results
Manage Existing Surveys
Create/Copy Multiple Surveys
Collaborate with Team Members
Sign inSign in with Facebook
Sign inSign in with Google

Phishing survey: 14 questions about the last suspicious message

An anonymous phishing awareness survey employees answer about one real event: the last message at work they suspected, whether it was a real attack or a company test. It asks how they spotted it, what they did, and whether reporting felt quick and safe.

  • 14questions
  • about 4 minto answer
  • Anonymousno names or teams
  • 1 messagethe last one they remember
Phishing Survey · answer to move through it
Use this template
Question 1 of 14 The message
Think of the last message at work you suspected was phishing, real or a company test. When did it arrive?
In the last week
In the last month
1 to 3 months ago
More than 3 months ago
I cannot remember one
Question 2 of 14 The message
How did it reach you?
Work email
A chat app such as Teams or Slack
A text message
A phone call or voicemail
Something else
Question 3 of 14 Spotting it
What made you suspicious? Tick all that apply.
The sender or address looked wrong
It pushed me to act quickly
It asked for a password, code or payment
A link or attachment I was not expecting
It did not sound like the person it claimed to be
Our email system warned me
A colleague warned me
Question 4 of 14 Spotting it
I was sure it was phishing before I did anything with it.
Strongly agree
Agree
Neither agree nor disagree
Disagree
Strongly disagree
Question 5 of 14 What you did
What did you do first?
Reported it with the report button or channel
Told my manager or a colleague
Deleted or ignored it
Opened a link or attachment, then reported it
Opened a link or attachment and did not report it
I am not sure
Question 6 of 14 What you did
If you reported it: reporting took me less than a minute.
Strongly agree
Agree
Neither agree nor disagree
Disagree
Strongly disagree
Question 7 of 14 What you did
If you reported it: somebody told me what happened next.
Strongly agree
Agree
Neither agree nor disagree
Disagree
Strongly disagree
Question 8 of 14 Reporting safely
I could report a message I had already clicked without worrying about getting into trouble.
Strongly agree
Agree
Neither agree nor disagree
Disagree
Strongly disagree
Question 9 of 14 Reporting safely
I know what to do in the first few minutes if I have typed a password into a page I should not have.
Strongly agree
Agree
Neither agree nor disagree
Disagree
Strongly disagree
Question 10 of 14 Training and tests
The phishing training I have had looks like the messages I actually receive.
Strongly agree
Agree
Neither agree nor disagree
Disagree
Strongly disagree
Question 11 of 14 Training and tests
If your company runs phishing tests: they feel like practice rather than a trap.
Strongly agree
Agree
Neither agree nor disagree
Disagree
Strongly disagree
Question 12 of 14 Next time
If a convincing message arrived tomorrow, I would report it even if I was not sure.
Strongly agree
Agree
Neither agree nor disagree
Disagree
Strongly disagree
Question 13 of 14 In your words
What one change would make you more likely to report a suspicious message?
Question 14 of 14 Overall
Overall, how prepared do you feel to handle a phishing message at work?
Very well prepared
Well prepared
Somewhat prepared
Not very prepared
Not at all prepared

What this phishing survey measures

Not whether people can spot a phish in a quiz, but what they did the last time one arrived.

One real message, not a hypothetical. Asked how careful they are, everybody is careful. Asked about the last suspicious message they got, people describe what they did. Question 1 fixes that message, and every answer after it is about the same event.

Reporting is the behaviour that matters. In a 15-month study of more than 14,000 employees, asking staff to flag suspicious messages worked as an early warning across the company.[2] So most of these questions are about what happened after the message was noticed. All fourteen are ready to edit in the free survey builder.

What it is not. Not a year-long review of security habits, which is what the cyber security questionnaire for employees covers.

An isometric inbox tray of plain envelopes with one lifted out on a fishing hook, beside a shield, a checklist on a clipboard and a large report button with a flag
One message caught, one button pressed. The survey asks what happened between the two.

The 14 phishing survey questions

Every question, the scale it takes, and what a low score points at. Copy one group or the whole set.

Plain text, one question per line, with the answer scale.

The message

One remembered event, so the answers describe what happened rather than how careful people think they are.

  1. Think of the last message at work you suspected was phishing, real or a company test. When did it arrive?Pick one of 5"I cannot remember one" is an answer, not a failure. A lot of them in one group is worth checking against what your mail filter catches.
  2. How did it reach you?Pick one of 5Messages by chat, text or phone are often outside the report button entirely.

Spotting it

What tipped them off, and how sure they were.

  1. What made you suspicious? Tick all that apply.Tick all that applyIf "Our email system warned me" dominates, people are relying on the filter. Kinds of warning sign only; no example messages.
  2. I was sure it was phishing before I did anything with it.Strongly agree to strongly disagreeLow agreement with a report at question 5 is fine: unsure and reported is the behaviour you want.

What you did

The behaviour itself, then whether reporting was quick and answered.

  1. What did you do first?Pick one of 6The key question. Anybody who opened a link and did not report it is the risk; how many there are matters more than the click count.
  2. If you reported it: reporting took me less than a minute.Strongly agree to strongly disagree, optionalSlow reporting usually means no button, or a button people cannot find on their phone.
  3. If you reported it: somebody told me what happened next.Strongly agree to strongly disagree, optionalSilence after a report teaches people that reporting is pointless.

Reporting safely

Whether owning up is safe, and whether people know what to do after a mistake.

  1. I could report a message I had already clicked without worrying about getting into trouble.Strongly agree to strongly disagreeDisagreement here predicts the dangerous answer at question 5. It is a culture finding, not a training one.
  2. I know what to do in the first few minutes if I have typed a password into a page I should not have.Strongly agree to strongly disagreeThe first minutes after a typed password are the ones that matter. A low score is fixed with one clear instruction.

Training and tests

Whether the training and tests match what people actually receive.

  1. The phishing training I have had looks like the messages I actually receive.Strongly agree to strongly disagreeTraining built on generic examples scores low where attacks arrive by chat or text.
  2. If your company runs phishing tests: they feel like practice rather than a trap.Strongly agree to strongly disagree, optionalIf tests feel like a trap, people stop reporting anything they are not sure about.

Next time, in their words, then the verdict

The outcome, one change in their own words, and one rating.

  1. If a convincing message arrived tomorrow, I would report it even if I was not sure.Strongly agree to strongly disagreeThe headline number: the share who would report even when unsure.
  2. What one change would make you more likely to report a suspicious message?Long textOne change, not a list, so the answers can be counted and ranked.
  3. Overall, how prepared do you feel to handle a phishing message at work?Pick one of 5High confidence with a poor question 5 is the gap to close.

Eight items share one agree scale: Strongly agree, Agree, Neither agree nor disagree, Disagree, Strongly disagree. Questions 6, 7 and 11 start with "If" and are optional, so people who did not report, or whose company runs no tests, can skip them.

What the phishing survey results tell you

Two numbers first, then the blocks that explain them.

The headline. The share who agree or strongly agree with question 12: they would report a convincing message even when unsure. Put it next to question 5, the share whose first move was to report.

The risk group. Count the answers of "Opened a link or attachment and did not report it". Then read question 8 for the same period: if people fear getting into trouble, that group will not shrink by itself. The UK National Cyber Security Centre puts it plainly: "Users who fear reprisals will not report mistakes promptly, if at all."[1]

No benchmark. Compare your own results over time, before and after a change.

If this is lowIt usually meansWhat to change
Spotting it (Q4)People act before they are sureTeach one habit: stop and report when unsure
Reporting (Q6 to Q7)No quick report button, or no reply after a reportA one-click button and an acknowledgement
Reporting safely (Q8 to Q9)Fear of blame, or no plan after a mistakeSay clicking then reporting is welcome; publish the first steps
Training and tests (Q10 to Q11)Training that does not match real attacks, or tests that feel like trapsExamples from your own channels; tests followed by thanks, not blame

Sending the phishing questionnaire

Who answers, when, and how to keep it honest.

Everyone who gets work messages, anonymously. Collect no names and do not cut the results into groups so small that an answer points at a person. Never match answers to phishing test results.

Send it within a week of a test or a real wave of attacks, while people remember the message. Otherwise twice a year is enough.

Close the loop. The same guidance asks whether reporting is "clear, simple and quick to use" and says to feed back what was done.[1] Tell staff what you changed after the last round.

Then the right follow-up. If the awareness course is the problem, judge it with a post training survey. To decide what to buy next, use a training needs assessment survey. If getting help after a mistake is slow, the IT survey questions for employees cover support. If a message led to a real breach, review it with a crisis management survey.

Phishing survey FAQ

What questions should a phishing survey ask?

What happened the last time somebody met a suspicious message: how it arrived, what gave it away, what they did first, and whether reporting was quick and safe. Add whether training matches what they receive, then one open question about what would make reporting easier.

How is a phishing survey different from a phishing test?

A test sends a message and records who clicks. A survey asks people what they noticed, what they did and why, which explains the test results. This page carries only the survey.

Should a phishing survey be anonymous?

Yes. Question 5 asks whether somebody opened a link and kept quiet, and nobody answers that honestly with their name attached. Do not match answers to test results by person.

How often should you run it?

Within a week of a phishing test or a real wave of attacks, while the message is fresh. Otherwise twice a year is enough to see whether a change to training or the report button worked.

What is survey phishing?

A scam that poses as a survey, often with a prize, to collect passwords or card details. A real survey never needs your password. This one asks for no names, logins or personal details at all.

Michael Hodge, survey methodology and questionnaire design · Updated 22 September 2026 · How templates are reviewed

Sources (2)
  1. UK National Cyber Security Centre. "Phishing attacks: defending your organisation." ncsc.gov.uk
  2. Lain, D., Kostiainen, K. and Capkun, S. "Phishing in Organizations: Findings from a Large-Scale and Long-Term Study." IEEE Symposium on Security and Privacy, 2022. arxiv.org

Fourteen questions written for this page and anchored to one remembered event, so the answers describe behaviour rather than self-image. The weight on reporting follows a 15-month study of more than 14,000 employees.[2] The questions on blame and feedback follow UK national guidance.[1] No item comes from a licensed or published questionnaire. Security behaviour scales that are not licensed for reuse here are not used, and no usability scale or adoption model is reproduced. Two short quotations from the UK National Cyber Security Centre are attributed.[1]

Send it while the last message is still fresh

Fourteen questions, about four minutes, anonymous. Add your own report button name and send it.

Use this template