June 27, 2022, 6:25 p.m. | /u/YetAnotherHuckster

cybersecurity www.reddit.com

Anyone have any thoughts on which metrics might be best for controls for social engineering?

Most seem to use something like adherence to security awareness training as a key performance indicator (KPI). This is fine as one barometer. But it's far from ideal since there are both difference qualities of training and different people's attention and adherence to following it afterwards.

I also dislike email phishing tests, such as those most everyone seems to use thru KnowBe4 (I like this …

controls cybersecurity engineering metrics social social engineering

SOC 2 Manager, Audit and Certification

@ Deloitte | US and CA Multiple Locations

Senior InfoSec Manager - Risk and Compliance

@ Federal Reserve System | Remote - Virginia

Security Analyst

@ Fortra | Mexico

Incident Responder

@ Babcock | Chester, GB, CH1 6ER

Vulnerability, Access & Inclusion Lead

@ Monzo | Cardiff, London or Remote (UK)

Information Security Analyst

@ Unissant | MD, USA