View/Export Results
Manage Existing Surveys
Create/Copy Multiple Surveys
Collaborate with Team Members
Sign inSign in with Facebook
Sign inSign in with Google

The cyber security questionnaire for employees, and what to ask

Fourteen questions about what people do and what stops them. Not a test with right answers, and not a control audit. Answer them below, copy any block, or open the lot in the editor.

  • 14questions
  • About 4 minto complete
  • 3on the reporting path
  • Noright answers
Employee Cyber Security Survey · answer to move through it
Use this template
Question 1 of 14 Who is answering
Which of these is closest to the work you do?
Finance, payroll or paying invoices
Sales, marketing or dealing with customers
HR, legal or administration
Engineering, development or IT
Operations, production or field work
Management or leadership
Something else
Question 2 of 14 Who is answering
Which of these are a normal part of your working week?
Handling customer or staff personal data
Approving or making payments
Access to systems most colleagues do not have
Choosing or installing my own software
Working from a personal device
None of these
Question 3 of 14 The reporting path
If a message arrived today that looked like an attempt to trick you, where would you send it?
A report button in my email or chat app
An address or channel I already know
I would tell my manager
I would ask a colleague what they think
I would delete it and say nothing
I do not know
Question 4 of 14 The reporting path
In the last 90 days, have you reported anything that looked suspicious?
Yes, once
Yes, more than once
No, nothing came up
No, something came up and I let it go
I cannot remember
Question 5 of 14 The reporting path
What would slow you down before reporting something?
Not being sure it is really a problem
Worrying that I caused it
Not knowing who to tell
Thinking it is not worth anyone's time
Being too busy at that moment
Reporting before and hearing nothing back
Nothing would slow me down
Question 6 of 14 What the day asks of you
I know which of the things I work with count as sensitive.
1
2
3
4
5
Strongly disagreeStrongly agree
Question 7 of 14 What the day asks of you
I can check that an unexpected request is genuine before I act on it.
1
2
3
4
5
Strongly disagreeStrongly agree
Question 8 of 14 What the day asks of you
Signing in to work systems is quick enough that I never look for a way round it.
1
2
3
4
5
Strongly disagreeStrongly agree
Question 9 of 14 What the day asks of you
I know what to do if a work device of mine goes missing.
1
2
3
4
5
Strongly disagreeStrongly agree
Question 10 of 14 What the day asks of you
How often do you use a password manager for your work accounts?
Always
Most of the time
Sometimes
Rarely
Never
We do not have one
Question 11 of 14 Where the rules bend
Which of these have you seen happen where you work?
A login shared instead of access being requested
A work file sent to a personal address or personal cloud
An app used that nobody approved
A password written somewhere it can be seen
A security prompt turned off to get on with a job
None of these
Question 12 of 14 Where the rules bend
When I ask for help with a security tool, I get an answer soon enough to keep working.
1
2
3
4
5
Strongly disagreeStrongly agree
Question 13 of 14 Training and the open box
The security training I have had is about the work I actually do.
1
2
3
4
5
Strongly disagreeStrongly agree
Question 14 of 14 Training and the open box
What is the one security rule or tool that most gets in the way of your work?

Three different documents get called a cyber security questionnaire

A control audit, a knowledge test and a staff survey. Different respondents, different outputs, and the search results mix all three.

The control audit. A register of assets, threats and controls, scored for likelihood and impact by whoever runs the systems. It is a spreadsheet, it is what a risk assessment template means, and no opinion goes in it.

The knowledge test. Right answers and a score per person. It records who read the training, a different measurement from whether the rule survives a deadline, so it cannot say why a control gets worked around.

The staff survey. What people do, what they can see and what gets in their way. No right answers, no score against a person, and the only one of the three that can name an unworkable rule.

Three document panels side by side: a grid of small checkboxes, a card showing a tick and a cross, and a panel of rating scales highlighted in coral
A control register, a test with right answers, and a survey of the people.
Control auditKnowledge testThis survey
Who answersWhoever runs the system.Each member of staff, individually.Everybody who uses the systems.
What comes outA register of gaps with owners.A pass mark per person.Percentages by group, and written answers.
Cannot seeWhat people do when the control is slow.Whether the rule holds on a busy day.The state of any system.
Where to get oneA risk register or controls workbook.A quiz tool.The fourteen below.

The argument for running the third one at all. In the most recent UK national statistics, phishing was the most prevalent kind of breach or attack, reported by 38 per cent of businesses in the previous twelve months, while only 19 per cent of businesses had given staff any form of cyber security training in the same period.[3] The attack that arrives most is the one aimed at people, and most of those organizations were not yet measuring how their people handle it.

The 14 cyber security survey questions, and what each answer tells you

Every question, its scale, and how to read it. Copy one block, copy all fourteen, or open the survey and rename the tools.

Plain text, one question per line, with the answer scale.

Who is answering, in two taps

Two cheap questions first, because a security answer is unreadable without them. A field engineer on a shared tablet and an accounts payable clerk approving invoices are not asked to do the same things, and one average hides both.

  1. Which of these is closest to the work you do?Choose oneThe one cut worth making before any average is read. Put your own function names in, and merge any group small enough that an answer would give away who wrote it.
  2. Which of these are a normal part of your working week?Tick all that applyExposure, described by the person rather than inferred from a job title. Anyone ticking payments or elevated access is a group to read on its own.

The reporting path

Three of the fourteen sit here because this is the part an organization can change inside a fortnight. Knowing the route, having used it, and what would stop you are three separate facts, and the third names the fix.

  1. If a message arrived today that looked like an attempt to trick you, where would you send it?Choose oneThe destination, as the respondent understands it today. The last three options are failures of the path rather than of the person, and they are the number to watch.
  2. In the last 90 days, have you reported anything that looked suspicious?Choose oneBehaviour rather than intention, in a window short enough to remember. Read it against question 3, which separates people who never knew the route from people who knew it and did not use it.
  3. What would slow you down before reporting something?Tick all that applyThe one item that hands you a fix per option, mapped below the bank.

What the working day actually asks of you

Five statements on one 5-point agree scale, about what a person is expected to manage without help: what counts as sensitive, an odd request, signing in, a missing device, and where credentials live.

  1. I know which of the things I work with count as sensitive.5-point agree, Strongly disagree to Strongly agreeClassification, asked about this person's own work rather than about a policy document they may never have opened.
  2. I can check that an unexpected request is genuine before I act on it.5-point agree, Strongly disagree to Strongly agreeVerification, framed as a capability rather than a rule. A low score from people who ticked payments in question 2 is the one to act on first.
  3. Signing in to work systems is quick enough that I never look for a way round it.5-point agree, Strongly disagree to Strongly agreeFriction at the front door, and the partner of question 11: a control people cannot live with is where a workaround comes from.
  4. I know what to do if a work device of mine goes missing.5-point agree, Strongly disagree to Strongly agreeThe one event where minutes matter. If this scores low, the fix is a card in the joiner pack, not a training module.
  5. How often do you use a password manager for your work accounts?Choose one, six worded levelsOne concrete habit, with an option for the case where nobody was given the tool. Rule that option out before reading anything as a personal failing.

Where the rules bend, and why

Two items about the gap between the policy and the day. The first asks what the respondent has SEEN, not what they did: somebody asked to admit a breach under their own department label answers with silence, and the useful answer is the barrier, not the culprit.

  1. Which of these have you seen happen where you work?Tick all that applyPrevalence, gathered without asking anybody to incriminate themselves. A high count describes your controls, not your colleagues.
  2. When I ask for help with a security tool, I get an answer soon enough to keep working.5-point agree, Strongly disagree to Strongly agreeThe support side of the same coin: a workaround and a slow answer to a request for help are one event seen from two ends.

Training, and one open box

One item on whether the training matched the job, and one box for what the other thirteen missed. It is last and optional, so the survey ends at a tap.

  1. The security training I have had is about the work I actually do.5-point agree, Strongly disagree to Strongly agreeRelevance rather than satisfaction. Somebody can enjoy a session about a threat with nothing to do with their work, and satisfaction would score it well.
  2. What is the one security rule or tool that most gets in the way of your work?Open text, optionalRead these first. This is where the specific tool, screen or rule gets named.

All fourteen run in the preview above, so a free online questionnaire opens them in a couple of minutes, wording yours to change.

Three subjects deliberately left out. One simulated phishing campaign has its own instrument, and the phishing survey questions template scores that campaign rather than the year. Doors, passes and premises are a walk-round, not a questionnaire. And where people route around one screen rather than one rule, the thing to score is the interface, which the usability survey template does properly. Satisfaction with the IT service itself is a third instrument, and the it satisfaction survey questions template deliberately asks no security question at all.

Why three of the fourteen are about reporting

The part of this subject a survey can measure honestly and an organization can change inside a fortnight.

A click rate is a property of the email, not of the workforce. When NIST built a scale for rating how hard a phishing message is to spot, it applied it to ten workplace training exercises inside one organization, and the click rates ran from 3.2 per cent, two people out of 63, to 49.3 per cent, 36 out of 73.[1] One organization, one programme, a fifteenfold spread, because the messages differed. A number that moves that far on the bait is not a verdict on the people.

What a reported message tells you instead. The UK national cyber security authority puts the reason in one line: "metrics express an organisation's values, and if you appear to value the absence of reports of problems, you incentivise people to keep quiet about issues", and it asks organizations running simulations to "focus on how many people reported it".[2] A report is an action somebody chose to take, and every part of that choice is changeable: the route, whether it seems worth using, and what happens to them afterwards.

Which is why blame is expensive. The same guidance is blunt about it: "Don't reprimand users who are struggling to recognise phishing emails. Users who fear reprisals will not report mistakes promptly, if at all."[2] That is why question 5 offers "worrying that I caused it" as an option to tick, and why nothing here asks for a confession.

Small message shapes converging into a funnel, several diverted away along dotted lines, the rest passing a gate and arriving stacked on a coral panel
Every message that falls out of the funnel does so for a reason somebody can name. Question 5 collects them.
If people tick this in question 5What it points atThe smallest fix
Not being sure it is really a problemA bar so high that only certainties get sent.Say in writing that a wrong guess is welcome.
Worrying that I caused itBlame, real or expected.One published line on what happens to somebody who reports their own mistake.
Not knowing who to tellA route that exists in a policy nobody reads.One address or one button, named in the same place every time.
Thinking it is not worth anyone's timeReports treated as noise rather than as signal.Tell people what the volume gets used for.
Being too busy at that momentA route that costs more than the moment allows.One action, not a forwarded email with an explanation.
Reporting before and hearing nothing backA one-way channel.An acknowledgement, then a monthly note on what came in.

One thing worth knowing before you attach this to a simulation. A study running fifteen months across more than 14,000 employees found that training delivered at the moment somebody failed a simulated phish left them more susceptible rather than less, while asking employees to flag suspicious messages proved practical and sustainable at that scale.[4] So send this on its own cycle rather than stapled to the next campaign, and keep the reporting block the deepest part of it.

How to read what comes back, and how to send it

Three numbers, one rule about groups, one sentence for the invitation.

Start with the open box, then the reporting funnel. Read question 14 before any average: it is the only place a specific tool or rule gets named. Then put question 3 next to question 4, because people who know the route and still let something go need the opposite fix to people who never had one.

Then percent favourable, by theme, not by item. Questions 6 to 9, 12 and 13 sit on one 5-point agree scale, so count the share choosing agree or strongly agree, per theme. A theme built on three or four items survives one badly worded question; a headline built on one item does not. If question 13 is the theme that scores worst, the next thing to establish is which groups need what, which the training needs assessment questions template does.

Question 11 is prevalence, not guilt. A high count on shared logins is a statement about how access requests are handled, and a high count on turned-off prompts is a statement about how the prompt behaves at three o'clock on a deadline. Route it to whoever owns the control, not to whoever owns the people.

Groups, and the one line for the invitation. This template asks for no name and no email address, and the answers arrive in the account that published the survey, so say exactly that and promise nothing further. Question 1 is the only thing that could narrow anybody down: merge functions until every reported group is comfortably large. Send it once a year, or twice if something changed, on the same wording each time.

Employee cyber security survey FAQ

What should a cyber security questionnaire for employees ask?

Five things, none with a right answer. Who is answering and what they touch; where they would send something suspicious and whether they have; what would slow them down before reporting; what the day asks of them on classification, verification, sign-in, a missing device and credentials; and one open box.

Is this a cyber security risk assessment template?

No. A risk assessment is a register of assets, threats and controls, scored by likelihood and impact, completed by whoever runs the systems. This is a survey of the people who use them. If you need the register, start from a controls instrument such as the compliance survey questions template and treat this one as the human half a register cannot see.

How many cyber security survey questions for employees is enough?

Fourteen here, against lists of twenty to twenty-nine elsewhere. Every one is running in the survey above with a stated reason and a stated way to read it. To go longer, add depth to the reporting block rather than breadth across new subjects.

Should an employee cyber security survey be anonymous?

This template asks for no name and no email address, and the answers arrive in the account that published it, so whoever administers the survey can see them. Say that in the invitation and promise nothing more. Question 1 is the only thing that could narrow somebody down, so merge small groups first.

What should we never ask staff about security?

Passwords, one-time codes, security question answers, the details of a specific incident, or anything that makes a person identify themselves as the cause of one. Question 11 is the alternative: it asks what somebody has seen, not what they did.

Does this cover the awareness training our auditors ask about?

It covers the measurement half. Awareness requirements sit in ISO/IEC 27001:2022 and in NIST Special Publication 800-50 Revision 1, which frames a learning programme around behaviour change and offers metrics for it.[5] Neither is reproduced here and neither is a survey. This gives you a repeatable measure to put against whichever one your auditor works from.

Michael Hodge, survey methodology and questionnaire design · Updated 9 September 2026 · How templates are reviewed

Sources (5)
  1. Steves, M., Greene, K. and Theofanos, M. Categorizing human phishing difficulty: a Phish Scale. Journal of Cybersecurity 6(1), 2020, tyaa009. academic.oup.com. Written by US Government employees and in the public domain in the US.
  2. National Cyber Security Centre (UK). Phishing attacks: defending your organisation. ncsc.gov.uk
  3. Department for Science, Innovation and Technology and Home Office. Cyber security breaches survey 2025/2026, published 30 April 2026. Fieldwork August to December 2025; 2,112 UK businesses and 1,085 UK registered charities. gov.uk. Contains public sector information licensed under the Open Government Licence v3.0.
  4. Lain, D., Kostiainen, K. and Capkun, S. Phishing in Organizations: Findings from a Large-Scale and Long-Term Study. IEEE Symposium on Security and Privacy, 2022. arXiv:2112.07498. arxiv.org
  5. Merritt, M., Hansche, S., Ellis, B., Sanchez-Cherry, K., Snyder, J.N. and Walden, D. Building a Cybersecurity and Privacy Learning Program. NIST Special Publication 800-50 Revision 1, September 2024. csrc.nist.gov

Putting three of the fourteen questions on the reporting path, and treating a click rate as a property of the message rather than of the workforce, rests on NIST's phishing difficulty work and its ten measured exercises[1] and on the UK national authority's guidance about what to measure and what not to punish.[2] The case for running the survey at all uses the most recent UK national statistics on breach types and staff training.[3] Running it on its own cycle rather than stapled to a simulation follows a study of more than 14,000 employees.[4] Framing an awareness programme around behaviour change follows current NIST guidance.[5] Every question here was written for this page and is free to copy, edit and send anywhere. Nothing reproduces a licensed, paid or standardised instrument. Four candidates were checked against their primary licence text on 9 September 2026 and all four refused: ISO/IEC 27001:2022 and its Annex A awareness control, sold per user with no free licence readable; the CIS Critical Security Controls, offered under a Creative Commons Attribution-NonCommercial-NoDerivatives licence that rules out a commercial site and any reworking of control text into questions; the HAIS-Q, whose copyright statement grants use to educational and non-profit institutions only; and SeBIS, for which no free licence could be read. NIST publications are not subject to copyright in the United States, and even so no NIST text is reprinted here.

Fourteen questions, about four minutes

Open it in the editor, rename the functions in question 1, put your own reporting route into question 3, and pick the month.

Use this template