Phishing survey: 14 questions about the last suspicious message
An anonymous phishing awareness survey employees answer about one real event: the last message at work they suspected, whether it was a real attack or a company test. It asks how they spotted it, what they did, and whether reporting felt quick and safe.
- 14questions
- about 4 minto answer
- Anonymousno names or teams
- 1 messagethe last one they remember
What this phishing survey measures
Not whether people can spot a phish in a quiz, but what they did the last time one arrived.
One real message, not a hypothetical. Asked how careful they are, everybody is careful. Asked about the last suspicious message they got, people describe what they did. Question 1 fixes that message, and every answer after it is about the same event.
Reporting is the behaviour that matters. In a 15-month study of more than 14,000 employees, asking staff to flag suspicious messages worked as an early warning across the company.[2] So most of these questions are about what happened after the message was noticed. All fourteen are ready to edit in the free survey builder.
What it is not. Not a year-long review of security habits, which is what the cyber security questionnaire for employees covers.
The 14 phishing survey questions
Every question, the scale it takes, and what a low score points at. Copy one group or the whole set.
The message
One remembered event, so the answers describe what happened rather than how careful people think they are.
- Think of the last message at work you suspected was phishing, real or a company test. When did it arrive?"I cannot remember one" is an answer, not a failure. A lot of them in one group is worth checking against what your mail filter catches.
- How did it reach you?Messages by chat, text or phone are often outside the report button entirely.
Spotting it
What tipped them off, and how sure they were.
- What made you suspicious? Tick all that apply.If "Our email system warned me" dominates, people are relying on the filter. Kinds of warning sign only; no example messages.
- I was sure it was phishing before I did anything with it.Low agreement with a report at question 5 is fine: unsure and reported is the behaviour you want.
What you did
The behaviour itself, then whether reporting was quick and answered.
- What did you do first?The key question. Anybody who opened a link and did not report it is the risk; how many there are matters more than the click count.
- If you reported it: reporting took me less than a minute.Slow reporting usually means no button, or a button people cannot find on their phone.
- If you reported it: somebody told me what happened next.Silence after a report teaches people that reporting is pointless.
Reporting safely
Whether owning up is safe, and whether people know what to do after a mistake.
- I could report a message I had already clicked without worrying about getting into trouble.Disagreement here predicts the dangerous answer at question 5. It is a culture finding, not a training one.
- I know what to do in the first few minutes if I have typed a password into a page I should not have.The first minutes after a typed password are the ones that matter. A low score is fixed with one clear instruction.
Training and tests
Whether the training and tests match what people actually receive.
- The phishing training I have had looks like the messages I actually receive.Training built on generic examples scores low where attacks arrive by chat or text.
- If your company runs phishing tests: they feel like practice rather than a trap.If tests feel like a trap, people stop reporting anything they are not sure about.
Next time, in their words, then the verdict
The outcome, one change in their own words, and one rating.
- If a convincing message arrived tomorrow, I would report it even if I was not sure.The headline number: the share who would report even when unsure.
- What one change would make you more likely to report a suspicious message?One change, not a list, so the answers can be counted and ranked.
- Overall, how prepared do you feel to handle a phishing message at work?High confidence with a poor question 5 is the gap to close.
Eight items share one agree scale: Strongly agree, Agree, Neither agree nor disagree, Disagree, Strongly disagree. Questions 6, 7 and 11 start with "If" and are optional, so people who did not report, or whose company runs no tests, can skip them.
What the phishing survey results tell you
Two numbers first, then the blocks that explain them.
The headline. The share who agree or strongly agree with question 12: they would report a convincing message even when unsure. Put it next to question 5, the share whose first move was to report.
The risk group. Count the answers of "Opened a link or attachment and did not report it". Then read question 8 for the same period: if people fear getting into trouble, that group will not shrink by itself. The UK National Cyber Security Centre puts it plainly: "Users who fear reprisals will not report mistakes promptly, if at all."[1]
No benchmark. Compare your own results over time, before and after a change.
| If this is low | It usually means | What to change |
|---|---|---|
| Spotting it (Q4) | People act before they are sure | Teach one habit: stop and report when unsure |
| Reporting (Q6 to Q7) | No quick report button, or no reply after a report | A one-click button and an acknowledgement |
| Reporting safely (Q8 to Q9) | Fear of blame, or no plan after a mistake | Say clicking then reporting is welcome; publish the first steps |
| Training and tests (Q10 to Q11) | Training that does not match real attacks, or tests that feel like traps | Examples from your own channels; tests followed by thanks, not blame |
Sending the phishing questionnaire
Who answers, when, and how to keep it honest.
Everyone who gets work messages, anonymously. Collect no names and do not cut the results into groups so small that an answer points at a person. Never match answers to phishing test results.
Send it within a week of a test or a real wave of attacks, while people remember the message. Otherwise twice a year is enough.
Close the loop. The same guidance asks whether reporting is "clear, simple and quick to use" and says to feed back what was done.[1] Tell staff what you changed after the last round.
Then the right follow-up. If the awareness course is the problem, judge it with a post training survey. To decide what to buy next, use a training needs assessment survey. If getting help after a mistake is slow, the IT survey questions for employees cover support. If a message led to a real breach, review it with a crisis management survey.
Phishing survey FAQ
What questions should a phishing survey ask?
What happened the last time somebody met a suspicious message: how it arrived, what gave it away, what they did first, and whether reporting was quick and safe. Add whether training matches what they receive, then one open question about what would make reporting easier.
How is a phishing survey different from a phishing test?
A test sends a message and records who clicks. A survey asks people what they noticed, what they did and why, which explains the test results. This page carries only the survey.
Should a phishing survey be anonymous?
Yes. Question 5 asks whether somebody opened a link and kept quiet, and nobody answers that honestly with their name attached. Do not match answers to test results by person.
How often should you run it?
Within a week of a phishing test or a real wave of attacks, while the message is fresh. Otherwise twice a year is enough to see whether a change to training or the report button worked.
What is survey phishing?
A scam that poses as a survey, often with a prize, to collect passwords or card details. A real survey never needs your password. This one asks for no names, logins or personal details at all.
Michael Hodge, survey methodology and questionnaire design · Updated 22 September 2026 · How templates are reviewed
Sources (2)
- UK National Cyber Security Centre. "Phishing attacks: defending your organisation." ncsc.gov.uk
- Lain, D., Kostiainen, K. and Capkun, S. "Phishing in Organizations: Findings from a Large-Scale and Long-Term Study." IEEE Symposium on Security and Privacy, 2022. arxiv.org
Fourteen questions written for this page and anchored to one remembered event, so the answers describe behaviour rather than self-image. The weight on reporting follows a 15-month study of more than 14,000 employees.[2] The questions on blame and feedback follow UK national guidance.[1] No item comes from a licensed or published questionnaire. Security behaviour scales that are not licensed for reuse here are not used, and no usability scale or adoption model is reproduced. Two short quotations from the UK National Cyber Security Centre are attributed.[1]
Send it while the last message is still fresh
Fourteen questions, about four minutes, anonymous. Add your own report button name and send it.
Use this template