Phishing Risk Assessment

Free phishing risk self-assessment. Score your security awareness training, email controls, MFA and BEC defences, and get a prioritised action list.

Advertisement

Phishing Risk Assessment

What this assessment measures

Twenty-one questions across five domains, weighted so that the controls with the largest real-world effect carry the most score. It produces an overall readiness score, a breakdown per domain, and a prioritised list of actions ordered by how much each gap is costing you.

Everything runs in your browser. No answers are uploaded or stored, and the shareable link encodes your responses in the URL so a colleague can open the same result without an account.

This tool assesses defences only. It does not generate phishing emails, lures, pretexts or simulation templates.

The five domains

Technical email controls — gateway filtering, DMARC enforcement, external-sender tagging, time-of-click URL rewriting, and lookalike-domain monitoring. These are the controls that stop a message before a human is involved.

Identity and access — MFA coverage, phishing-resistant factors for privileged accounts, conditional access, and detection of the post-compromise steps attackers take (mailbox forwarding rules, OAuth consent grants). This domain determines how much damage a successfully phished credential can actually do.

Awareness and training — frequency, role-specific content for finance and IT, phishing simulations, and coverage of voice and SMS pretexting rather than email alone.

Reporting and response — whether staff can report in one click, how fast a report is triaged, whether you can purge a message from every mailbox, and whether a credential-compromise playbook exists and has been exercised.

Governance and financial controls — out-of-band verification for payment changes, the metrics you report to leadership, supplier email posture, and whether reporting a mistake is genuinely blame-free.

Why the technical and identity domains are weighted highest

Security awareness training is necessary but it is not a control you can rely on alone. Well-run programmes reduce click rates substantially but never to zero, and a single click is all an attacker needs. The controls that do not depend on user vigilance — a tuned gateway, DMARC at enforcement, phishing-resistant MFA, and fast search-and-purge — are what determine whether a click becomes an incident.

That is also why the assessment rewards reporting rate over click rate. A workforce that reports quickly gives you the chance to purge the campaign from every other inbox before it is opened. A workforce that clicks less but reports nothing leaves you blind.

Phishing-resistant MFA

Modern phishing kits run as an adversary-in-the-middle proxy. They present a convincing copy of your login page, relay the credential and the one-time code to the real service in real time, and steal the resulting session cookie. This defeats SMS codes, TOTP apps and standard push notifications, because all of them produce a value the proxy can simply forward.

FIDO2 security keys and passkeys are bound to the origin, so the key refuses to authenticate to a lookalike domain. This is why the assessment scores origin-bound factors well above app-based push, and why it treats privileged accounts as the priority for rollout.

Business email compromise

Most fraudulent losses from email do not involve malware at all. They involve a plausible message asking finance to update bank details or approve an urgent payment. No email filter reliably distinguishes that from legitimate business correspondence, which is why the assessment treats out-of-band verification — a callback to a number you already held, never one supplied in the request — as a top-weighted control.

Using the results

The priority list is ordered by weighted gap, so the first item is the change that moves your score most. Re-run the assessment after any significant change to your mail platform, identity provider or finance process, and use the shareable link to compare before and after.

Pair this with the Email Authentication Validator to confirm your DMARC policy is actually at enforcement, and the Email Security Gateway Checker to verify your mail transport posture.

This tool is provided for informational and educational purposes only. All processing happens in your browser — no data is sent to or stored on our servers. While we strive for accuracy, we make no warranties about the completeness or reliability of results.