simpl.
Cybersecurity GRC 15 items

Phishing & Social Engineering Resilience Assessment

Evaluates technical email defenses and human resilience against phishing, business email compromise, and social engineering attacks.

CIS v8NIST 800-53NIST 800-50

Free PDF · enter your email to download.

Email Authentication & Filtering

  • Are SPF, DKIM, and DMARC configured for all sending domains? *
  • Is the DMARC policy set to quarantine or reject? *
  • Is an email security gateway filtering spam, malware, and malicious URLs? *
  • Are inbound attachments sandboxed or detonated before delivery?
  • Are external email banners applied to messages from outside the organization? *

Simulation & Testing

  • Are phishing simulation campaigns conducted at least quarterly? *
  • Is the click-through rate tracked and trended over time? *
  • What was the click rate on the most recent phishing simulation?
  • Are targeted or spear-phishing scenarios included for high-risk roles?

Reporting & Response

  • Is there a one-click report-phishing button in the email client? *
  • Are reported phishing messages triaged and remediated across all mailboxes? *
  • Is the median time to remediate a reported phishing email measured?

Business Email Compromise Controls

  • Is out-of-band verification required for payment or banking change requests? *
  • Are wire transfer and vendor-change approvals dual-controlled? *
  • Are executives and finance staff given targeted BEC awareness training? *

Download the full Phishing & Social Engineering Resilience Assessment checklist

Get it as a clean, printable PDF — free.