# Employee Security Awareness Assessment

> From $15K · Compliance & GRC · https://cisomarketplace.services/services/employee-security-awareness-assessment

Comprehensive assessment of employee security awareness levels to identify training needs and security culture gaps.

## In scope

- Security awareness surveys
- Phishing simulation tests
- Knowledge assessments
- Behavior analysis
- Culture evaluation

## Deliverables

- Awareness assessment report
- Training needs analysis
- Culture improvement recommendations
- Awareness program roadmap
- Metrics and benchmarks

## Tiers

### Small Organization Assessment: $15K

Awareness assessment for up to 100 employees at 1 location: 1 survey, 1 phishing simulation campaign, 1 knowledge assessment and up to 10 interviews. Report with training needs, benchmarks and a program roadmap.

Limits: employees 100, locations 1, scenarios 1, participants 10

Includes:
- Security awareness survey for all staff in scope
- 1 phishing simulation campaign
- Knowledge assessment
- Up to 10 staff interviews
- Assessment report, training needs analysis and roadmap

Excludes:
- Repeat phishing campaigns
- Per-department breakdown
- Training content or delivery
- Ongoing phishing platform subscription

### Medium Organization Assessment: $25K

Awareness assessment for up to 500 employees and up to 3 locations: survey, 2 phishing simulation campaigns of different difficulty, knowledge assessment and up to 25 interviews. Results broken down by department.

Limits: employees 500, locations 3, scenarios 2, participants 25

Includes:
- Survey and knowledge assessment for all staff in scope
- 2 phishing simulation campaigns
- Up to 25 staff interviews
- Per-department results and benchmarks
- Culture evaluation
- Training needs analysis and roadmap

Excludes:
- Role-targeted campaigns (executives, finance, IT)
- Training content or delivery
- Ongoing phishing platform subscription

### Large Organization Assessment: $40K

For more than 500 employees; no fixed cap on headcount and locations - scoped at kickoff. Survey, 3 phishing campaigns including one targeted at high-risk roles, knowledge assessment and up to 50 interviews. Results by department, site and role.

Limits: scenarios 3, participants 50

Includes:
- Survey and knowledge assessment for all staff in scope
- 3 phishing campaigns, 1 targeted at executives, finance and IT
- Up to 50 staff interviews and focus groups
- Results by department, site and role
- Culture evaluation with benchmarks
- Multi-year awareness program roadmap

Excludes:
- Training content development
- Training delivery
- Ongoing phishing platform subscription
- Vishing or physical social engineering

## Terms

Starting price shown is the lowest published tier. A written proposal fixes scope, tier and price before anything is signed. Timeline is set in the SOW.

Scope this engagement: https://cisomarketplace.services/scope?service=employee-security-awareness-assessment
