Vendor Social Engineering Risk Assessment Form
Assess your organization's exposure to social engineering threats and current risk management practices.
Which of the following social engineering attack types are vendors most frequently targeted with?
*
Phishing (email)
Vishing (phone calls)
Smishing (SMS/texts)
Impersonation (in-person/online)
Pretexting (fabricated scenarios)
Other
How frequently are vendor staff provided with social engineering awareness training?
*
Annually
Semi-annually
Quarterly
Never
Rate the effectiveness of current controls in place to prevent social engineering attacks.
*
1
2
3
4
5
Does your organization have a documented process for reporting suspected social engineering attempts?
*
Yes, well-documented and followed
Yes, but not consistently followed
No documented process
How often are simulated social engineering tests (e.g., phishing simulations) conducted for vendor staff?
*
Quarterly or more often
Annually
Less than annually
Never
Please rate the following aspects of your organization’s preparedness against social engineering threats.
*
Rows
Awareness of phishing emails
Response to suspicious phone calls
Physical security awareness
Very Poor
1
2
3
Poor
4
5
6
Average
7
8
9
Good
10
11
12
Excellent
13
14
15
Has your organization experienced any social engineering incidents in the past 12 months?
*
Yes
No
Not sure
Which of the following controls are currently in place to mitigate social engineering risk? (Select all that apply)
*
Employee training
Email filtering
Caller verification procedures
Physical access controls
Incident response plan
Other
How confident are you that your organization can detect and respond to social engineering attempts?
*
Not confident at all
1
2
3
4
Extremely confident
5
1 is Not confident at all, 5 is Extremely confident
Overall, how would you rate your organization’s current risk level for social engineering attacks?
*
Low
Moderate
High
Submit Assessment
Should be Empty: