Skip to content
CISO Marketplace Services

Security Awareness Program Assessment

Comprehensive evaluation of your organization's security awareness and training initiatives, measuring effectiveness, cultural impact, and behavior change. Our assessment identifies gaps in your human security controls and provides a strategic roadmap for creating a security-conscious workforce that actively defends against social engineering and other human-targeted attacks.

In scope

  • Training content evaluation
  • Awareness program effectiveness
  • Phishing simulation results analysis
  • Security culture assessment
  • Behavior change measurement
  • Training delivery methods
  • Executive engagement review
  • Compliance training adequacy

You receive

  • Security awareness program report
  • Gap analysis and recommendations
  • Phishing simulation plan
  • Training content enhancement strategy
  • Security culture development roadmap
  • Metrics and measurement framework
  • Role-based training recommendations

Tiers

Choose the depth.

Essential Security Awareness Review

$28K

Assessment of the awareness program for up to 500 staff.

employees
500
  • Program and content review
  • Metrics baseline
  • Improvement plan
  • — Running simulations for you
Scope Essential Security Awareness Review

Comprehensive Awareness Program Development

$48K

Up to 2,000 staff, including a measured simulation and role-based gap analysis.

employees
2000
  • Measured simulation
  • Role-based gap analysis
  • — Ongoing program operation
Scope Comprehensive Awareness Program Development

Enterprise Security Culture Program

$75K

Up to 10,000 staff across regions; larger organizations are scoped at kickoff.

employees
10000
  • Multi-region program review
  • Executive and board reporting design
  • — Ongoing program operation — see Managed Security Awareness
Scope Enterprise Security Culture Program

Members: engagement coupons from the CISO Marketplace coupon book apply to services. There is no blanket discount.

What's inside this engagement

Phase by phase.

How a social engineering & physical engagement runs, what happens in each phase and what you see. Exact scope, tier and timeline are fixed in your proposal and SOW.

  1. 01Scoping & authorization

    Targets, pretexts, sites and legal authorization letters agreed before anything is sent or attempted.

    You see · Signed authorization and approved pretexts.

  2. 02OSINT & pretext design

    Public information on staff and sites is used to build believable pretexts.

    You see · Approval of the pretexts.

  3. 03Campaign / on-site execution

    Phishing, vishing or physical entry attempts, run to the agreed plan and stopped on request.

    You see · Real-time escalation if anything goes wrong.

  4. 04Reporting & awareness debrief

    What worked, who reported it, and the controls that failed, without naming and shaming individuals.

    You see · Metrics and a training plan.

Commercials

From first call to final report.

  1. 01

    Scoping call

    A practitioner, not a salesperson, walks through targets, constraints and what a good outcome looks like for you.

  2. 02

    Proposal & rules of engagement

    A fixed-scope proposal with tier, price and deliverables. Rules of engagement, contacts and out-of-bounds systems are agreed in writing.

  3. 03

    Sign, then start

    MSA and SOW are signed electronically and the deposit is paid. Only then does testing begin.

  4. 04

    Execution

    Testing runs to the agreed plan. Critical findings are escalated as they are found; you don't wait for the report.

  5. 05

    Report & debrief

    An executive summary plus technical findings with evidence, reproduction steps and fixes, walked through with your team.

  6. 06

    Retest

    Where the tier includes it, we verify your fixes and reissue the report, so auditors and customers see the issues closed.

Timelines are set per engagement in the SOW.

Related

Research

Latest from the blog

All posts on cisomarketplace.com →
Talk to an advisor
Advisor