Security Awareness Training RFI/RFP questionnaire — 0-Doubt
Security Awareness Training evaluation questionnaire
Start from a neutral baseline and add what matters to you. Criteria are labeled by source — the platform baseline is architecture-neutral; buyer-contributed criteria are shown separately.
Build your evaluation
no account needed
Match on your requirements
no account needed
This evaluation is stored in your browser only. We cannot see it, and it is not tied to any account. Save it to a link or create an account to keep it across devices — you can export it at any time either way.
1. Weight what matters
32 criteria
baselineWhat phishing simulation capabilities are included — template variety, difficulty tiering, and how frequently are new templates added to reflect current real-world lures?
baselineDescribe how the platform measures behavior change over time (click rates, report rates) versus just training completion, and provide a customer reference showing a measured reduction in click-through rate.
baselineDoes the platform support a 'report phish' button integrated into the email client, and what is the automated triage workflow when an employee reports a suspicious email (auto-analysis, SOC escalation, deduplication of mass-reported campaigns)?
baselineHow is training content localized and culturally adapted for a global workforce (language, region-specific compliance content, region-specific phishing lures)?
baselineDetail adaptive/risk-based training — can high-risk users (repeat clickers, privileged-access holders) be automatically assigned more frequent or advanced training, and how is the per-user risk score calculated?
baselineWhat integrations exist with the email security stack (SEG, EDR) to correlate simulated-phishing failures with real-world incident data for the same user?
baselineExplain manager/executive reporting — can results be segmented by department/business unit, and is there a board-level summary suitable for compliance audits (e.g., SOC 2 security-awareness control evidence)?
baselineHow does the platform handle new-hire onboarding training assignment automatically (HRIS integration) versus manual enrollment?
baselineDoes the platform simulate vishing (voice phishing) and smishing (SMS phishing) in addition to email phishing, given that attackers increasingly use these channels, and how mature is that capability compared to the core email-phishing simulation?
baselineDescribe microlearning/just-in-time training delivery — can a short, targeted training module be automatically triggered immediately after a user fails a simulated phish, versus only being assigned during a scheduled annual/quarterly cycle?
baselineWhat is the pricing model — per employee per year, tiered by content library access, or a flat platform fee — and does the price change based on company size in a way that's transparent and predictable for budget planning?
baselineDetail training content coverage for emerging threats specifically — AI-generated deepfake voice/video scams, QR-code phishing (quishing), and business email compromise — and how quickly new content is authored after a new attack pattern becomes prevalent.
baselineIs the training content and delivery platform accessible (WCAG/ADA compliant) for employees using screen readers or other assistive technology, and has this been independently audited?
baselineWhat gamification and engagement mechanics are built in (leaderboards, badges, team competitions), and does the vendor have measured data showing gamification actually improves completion rates or behavior change versus non-gamified delivery?
baselineExplain executive/board-specific training — is there content tailored to high-value targets (whaling-specific scenarios, executive-assistant training for BEC protection), or is the same generic content assigned to every employee regardless of risk profile?
baselineHow does the platform handle contractors, temporary staff, and third-party vendors who need security awareness training but aren't full employees in the HRIS — is there a lightweight enrollment path, or does it require the same provisioning as a full employee?
baselinePerform authorized social engineering testing of municipal personnel, including email phishing campaigns against an agreed-upon population, sophisticated enough to simulate an adversary-in-the-middle (AiTM) attack.
baselineConduct simulated phishing and approved pretexting scenarios to assess user awareness and process controls (Social Engineering, optional/scoped).
baselineOffer optional Social Engineering Testing (phishing, vishing, smishing, and AI emulation/simulation) supporting three corporate-level campaigns annually, and publish an annual Social Engineering Assessment Report with recommendations, outcomes, and key risks.
baselineCoordinate with the organization to document opportunities, threats, techniques, approaches, and audiences for three annual social engineering tests (Social Engineering Annual Strategy) within 45 calendar days of contract award and annually thereafter.
baselineProvide annual information security and privacy awareness training to all Contract Staff prior to accessing the organization's data or IT systems.
baselineProvide Security Awareness Program Development or Review.
baselineVendor must itemize one-time setup/onboarding/deployment/configuration/integration costs separately from ongoing annual recurring service costs, and may include an optional Security Awareness Training offering priced separately (not counted toward the $150,000 annual budget cap).
baselineAll required Services must be delivered under a hybrid approach requiring Contractor Staff to be in the organization's office at least 2 days per week; Contractor must sign the organization's IT Security Rules of Behavior Form and complete mandatory IT Security and Privacy Awareness Online Training (Role-Based Privacy Act Training if accessing the organization's systems).
baselineBidder must provide training to identified Bank personnel (10x2) on solution/service architecture pre-implementation, and hands-on training on SIEM policy configuration/alert monitoring post-implementation (train-the-trainer not permitted); provide periodical security-awareness sessions on latest threats/vulnerabilities for Bank staff including executives/Board members.
baselineThe vendor shall provide customized materials and recommendations for enterprise-wide training for admin, core team users, business/general, leadership users as well as for external contractors and new hires using the tool, and develop a communications and training plan based on GRC best practices.
baselineConduct awareness training sessions (classroom and on-the-job) on IT Risk assessment and ISO27001 standard for DC and DR staff on a yearly basis, to enable Bank personnel to carry out such assignments independently in future.
baselineThe bidder shall provide periodic security awareness training at least 4 times per calendar year to the financial institution's staff before and after production deployment; provide at least 10 end-user training sessions in the first year plus handholding to designated staff; and arrange admin training for at least 3 of the financial institution's admins from the OEM.
baselineSocial Engineering: Assess vulnerabilities to various types of Phishing attacks. Determine adequacy of physical access security and protocols.
baselineSocial Engineering: phishing simulation campaigns, pretexting and vishing scenarios, and physical engineering.
baselineDo you perform background checks on all relevant personnel?
baselineVendor will conduct background checks and will not utilize any individual convicted of a crime involving dishonesty, fraud, theft, or an offense with a minimum one-year incarceration penalty, to fulfill obligations under the Agreement.
Signing up adds sharing with your team, sending this as an RFP to vendors, and private document sharing. Nothing above is taken away, and nothing here is sent anywhere until you choose to.
Platform baseline
neutral · staff-reviewed
RFIWhat phishing simulation capabilities are included — template variety, difficulty tiering, and how frequently are new templates added to reflect current real-world lures?Answer key — what a strong answer shows
Look for a stated template refresh cadence and difficulty tiering, not just one generic phishing template repeated indefinitely.
RFPDescribe how the platform measures behavior change over time (click rates, report rates) versus just training completion, and provide a customer reference showing a measured reduction in click-through rate.Answer key — what a strong answer shows
Strong answers cite a real before/after click-rate reduction from a named customer, not just completion percentages.
RFIDoes the platform support a 'report phish' button integrated into the email client, and what is the automated triage workflow when an employee reports a suspicious email (auto-analysis, SOC escalation, deduplication of mass-reported campaigns)?Answer key — what a strong answer shows
Look for integrated automated triage, not a mailbox a human has to manually check and sort.
RFIHow is training content localized and culturally adapted for a global workforce (language, region-specific compliance content, region-specific phishing lures)?Answer key — what a strong answer shows
Strong answers name specific languages/regions supported natively versus requiring custom content builds.
RFPDetail adaptive/risk-based training — can high-risk users (repeat clickers, privileged-access holders) be automatically assigned more frequent or advanced training, and how is the per-user risk score calculated?Answer key — what a strong answer shows
Look for an explicit risk-scoring methodology driving automated assignment, not a flat one-size-fits-all curriculum.
What integrations exist with the email security stack (SEG, EDR) to correlate simulated-phishing failures with real-world incident data for the same user?
From other buyers
crowdsourced · anonymized
💬
No buyer-contributed criteria yet
Verified buyers can suggest criteria (anonymized before pooling).
RFI
Answer key — what a strong answer shows
Genuine integration sharing a user risk signal is stronger than a standalone silo with no correlation to real incidents.
RFPExplain manager/executive reporting — can results be segmented by department/business unit, and is there a board-level summary suitable for compliance audits (e.g., SOC 2 security-awareness control evidence)?Answer key — what a strong answer shows
Look for exportable, audit-ready reporting mapped to specific compliance controls, not just a raw completion CSV.
RFIHow does the platform handle new-hire onboarding training assignment automatically (HRIS integration) versus manual enrollment?Answer key — what a strong answer shows
Native HRIS integration (auto-enroll on hire date) is stronger than manual CSV upload processes prone to gaps.
RFIDoes the platform simulate vishing (voice phishing) and smishing (SMS phishing) in addition to email phishing, given that attackers increasingly use these channels, and how mature is that capability compared to the core email-phishing simulation?Answer key — what a strong answer shows
Look for genuine multi-channel simulation capability, not just email; a vendor offering only email phishing simulation is addressing a shrinking share of the real attack surface.
RFPDescribe microlearning/just-in-time training delivery — can a short, targeted training module be automatically triggered immediately after a user fails a simulated phish, versus only being assigned during a scheduled annual/quarterly cycle?Answer key — what a strong answer shows
Immediate, contextual just-in-time training after a failure is materially more effective for behavior change than delayed, disconnected annual training assignment.
RFIWhat is the pricing model — per employee per year, tiered by content library access, or a flat platform fee — and does the price change based on company size in a way that's transparent and predictable for budget planning?Answer key — what a strong answer shows
Strong answers give clear per-employee economics; watch for vendors who quote a low headline price but gate the more effective adaptive/behavioral features behind a much higher tier.
RFPDetail training content coverage for emerging threats specifically — AI-generated deepfake voice/video scams, QR-code phishing (quishing), and business email compromise — and how quickly new content is authored after a new attack pattern becomes prevalent.Answer key — what a strong answer shows
Strong answers cite a concrete content-refresh cadence and name specific emerging-threat content already shipped, not a generic promise to 'stay current.'
RFIIs the training content and delivery platform accessible (WCAG/ADA compliant) for employees using screen readers or other assistive technology, and has this been independently audited?Answer key — what a strong answer shows
Look for a specific accessibility standard cited and ideally an independent audit, not just a verbal assurance — this is a real compliance requirement for many organizations, not a nice-to-have.
RFIWhat gamification and engagement mechanics are built in (leaderboards, badges, team competitions), and does the vendor have measured data showing gamification actually improves completion rates or behavior change versus non-gamified delivery?Answer key — what a strong answer shows
A vendor with real before/after engagement data is more credible than one asserting gamification helps without evidence — some workforces respond poorly to leaderboard-style competition.
RFPExplain executive/board-specific training — is there content tailored to high-value targets (whaling-specific scenarios, executive-assistant training for BEC protection), or is the same generic content assigned to every employee regardless of risk profile?Answer key — what a strong answer shows
Role-tailored content for high-value targets (executives, finance staff who approve wire transfers) is materially more relevant than one-size-fits-all training.
RFIHow does the platform handle contractors, temporary staff, and third-party vendors who need security awareness training but aren't full employees in the HRIS — is there a lightweight enrollment path, or does it require the same provisioning as a full employee?Answer key — what a strong answer shows
A dedicated lightweight path for non-employee populations indicates real-world deployment maturity; requiring full HRIS-integrated provisioning for a short-term contractor is an unnecessary friction point.
RFPPerform authorized social engineering testing of municipal personnel, including email phishing campaigns against an agreed-upon population, sophisticated enough to simulate an adversary-in-the-middle (AiTM) attack.
RFPConduct simulated phishing and approved pretexting scenarios to assess user awareness and process controls (Social Engineering, optional/scoped).
RFPOffer optional Social Engineering Testing (phishing, vishing, smishing, and AI emulation/simulation) supporting three corporate-level campaigns annually, and publish an annual Social Engineering Assessment Report with recommendations, outcomes, and key risks.
RFPCoordinate with the organization to document opportunities, threats, techniques, approaches, and audiences for three annual social engineering tests (Social Engineering Annual Strategy) within 45 calendar days of contract award and annually thereafter.
RFPProvide annual information security and privacy awareness training to all Contract Staff prior to accessing the organization's data or IT systems.
RFPProvide Security Awareness Program Development or Review.
RFPVendor must itemize one-time setup/onboarding/deployment/configuration/integration costs separately from ongoing annual recurring service costs, and may include an optional Security Awareness Training offering priced separately (not counted toward the $150,000 annual budget cap).
RFPAll required Services must be delivered under a hybrid approach requiring Contractor Staff to be in the organization's office at least 2 days per week; Contractor must sign the organization's IT Security Rules of Behavior Form and complete mandatory IT Security and Privacy Awareness Online Training (Role-Based Privacy Act Training if accessing the organization's systems).
RFPBidder must provide training to identified Bank personnel (10x2) on solution/service architecture pre-implementation, and hands-on training on SIEM policy configuration/alert monitoring post-implementation (train-the-trainer not permitted); provide periodical security-awareness sessions on latest threats/vulnerabilities for Bank staff including executives/Board members.
RFPThe vendor shall provide customized materials and recommendations for enterprise-wide training for admin, core team users, business/general, leadership users as well as for external contractors and new hires using the tool, and develop a communications and training plan based on GRC best practices.
RFPConduct awareness training sessions (classroom and on-the-job) on IT Risk assessment and ISO27001 standard for DC and DR staff on a yearly basis, to enable Bank personnel to carry out such assignments independently in future.
RFPThe bidder shall provide periodic security awareness training at least 4 times per calendar year to the financial institution's staff before and after production deployment; provide at least 10 end-user training sessions in the first year plus handholding to designated staff; and arrange admin training for at least 3 of the financial institution's admins from the OEM.
RFPSocial Engineering: Assess vulnerabilities to various types of Phishing attacks. Determine adequacy of physical access security and protocols.
RFPSocial Engineering: phishing simulation campaigns, pretexting and vishing scenarios, and physical engineering.
RFPDo you perform background checks on all relevant personnel?
RFPVendor will conduct background checks and will not utilize any individual convicted of a crime involving dishonesty, fraud, theft, or an offense with a minimum one-year incarceration penalty, to fulfill obligations under the Agreement.