Cybersecurity GRC 15 items
Phishing & Social Engineering Resilience Assessment
Evaluates technical email defenses and human resilience against phishing, business email compromise, and social engineering attacks.
CIS v8NIST 800-53NIST 800-50
Free PDF · enter your email to download.
Email Authentication & Filtering
- Are SPF, DKIM, and DMARC configured for all sending domains? *
- Is the DMARC policy set to quarantine or reject? *
- Is an email security gateway filtering spam, malware, and malicious URLs? *
- Are inbound attachments sandboxed or detonated before delivery?
- Are external email banners applied to messages from outside the organization? *
Simulation & Testing
- Are phishing simulation campaigns conducted at least quarterly? *
- Is the click-through rate tracked and trended over time? *
- What was the click rate on the most recent phishing simulation?
- Are targeted or spear-phishing scenarios included for high-risk roles?
Reporting & Response
- Is there a one-click report-phishing button in the email client? *
- Are reported phishing messages triaged and remediated across all mailboxes? *
- Is the median time to remediate a reported phishing email measured?
Business Email Compromise Controls
- Is out-of-band verification required for payment or banking change requests? *
- Are wire transfer and vendor-change approvals dual-controlled? *
- Are executives and finance staff given targeted BEC awareness training? *
Download the full Phishing & Social Engineering Resilience Assessment checklist
Get it as a clean, printable PDF — free.
