Use them together because each measures a different layer of behaviour. Knowledge checks show what people know, phishing simulations show what they do, and culture surveys show what they believe. That combination helps security teams decide whether to adjust messaging, training assignments, or reporting support for different groups instead of treating all users the same.
Why the three signals work better together
Culture surveys, phishing tests, and knowledge checks answer different questions, so using only one can give a false sense of confidence. A team may know the policy, still click a convincing lure, or understand the risk but not trust the reporting path. Combined, the three signals let you separate awareness, behaviour, and organisational norms.
That distinction matters because the same failure can mean very different things. A weak knowledge score may call for targeted education, while repeated phish clicks may point to message design, reporting friction, or a control gap that needs operational change rather than another generic training module.
The best way to read the data is as a three-part view of the same population: what people know, what they do under pressure, and how the workplace environment shapes those choices. Used that way, the survey becomes a context layer for interpreting the tests instead of a soft metric that sits beside them without influencing decisions.
How to interpret differences between the three measures
These measures rarely move in lockstep. A group with strong knowledge but poor phishing resilience may not need more theory, but may need better reporting cues, more realistic simulations, or clearer expectations from managers. A group with positive survey responses but weak test results may be signalling optimism bias, low confidence, or confusion about what a suspicious message looks like in practice.
When the survey shows low trust in the security function, that is often an explanatory signal rather than a separate problem to ignore. People may know the right action but still avoid reporting if they believe they will be blamed, delayed, or overwhelmed by process. In that case, the operational fix is often to simplify the reporting path and make feedback visible.
Phishing-test outcomes should also be read carefully. A click is not always a knowledge failure, and a no-click result is not always proof of resilience. If users are learning the test pattern, or if a narrow scenario is overused, the simulation may be measuring familiarity with the exercise rather than real-world susceptibility.
Turning combined results into action
The practical value of combining the three instruments is segmentation. Security teams can group users or functions by where the mismatch appears, then tailor action to the cause instead of applying one company-wide message. For example, one group may need clearer examples, another may need manager reinforcement, and another may need a better reporting workflow.
If you want the results to drive change, keep the survey questions tightly tied to behaviours you can influence. Questions about confidence, trust, and perceived friction are more useful than broad sentiment prompts because they point to a decision: whether to improve wording, change training assignment, or fix the reporting journey.
That approach also helps leaders avoid blaming users for problems that are partly systemic. If people know the policy but still fail the simulation, the issue may be how messages are written, how alerts are presented, or whether the organisation rewards fast reporting over silent avoidance.
Risk and Threat Considerations
Phishing tests and culture surveys can be misread if they are treated as proof of protection rather than indicators of control quality. The risk is not just lower training effectiveness, but also blind spots in reporting behaviour, manager reinforcement, and employee willingness to escalate suspicious activity.
Failure mechanism: A team can score well on knowledge checks while still being vulnerable to convincing lures, especially when attackers exploit urgency, authority, or routine workflow patterns. Survey results can also mask weak reporting culture if people answer positively about security in the abstract but hesitate to act when a real message arrives.
Impact: Organisations may overestimate resilience, miss groups that need targeted intervention, and leave exposed a path for credential theft, fraud, or malware delivery. When the three measures diverge, the gap itself is the signal that should drive remediation.
Standards & Framework Alignment
This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.
CIS Controls v8, NIST SP 800-53 Rev 5 and NIST CSF 2.0 set the governance and control requirements practitioners need to meet.
| Framework | Control / Reference | Relevance |
|---|---|---|
| CIS Controls v8 | CIS-14 — Security Awareness and Skills Training | Culture surveys and knowledge checks measure awareness and skill gaps that shape user behavior. |
| CIS-17 — Incident Response Management | Phishing tests and reporting behavior reveal whether users will escalate suspicious messages. | |
| Recommendation — Use results to target awareness and skills training at the groups showing the weakest understanding or highest failure rates. Align phishing reporting feedback with incident response workflows so users can escalate suspected phishing quickly. | ||
| NIST SP 800-53 Rev 5 | AT-2 — Awareness Training | Knowledge checks and surveys help validate whether awareness training is changing understanding. |
| AU-6 — Audit Record Review, Analysis, and Reporting | Combined survey, test, and knowledge data need review and analysis to spot control gaps. | |
| Recommendation — Tailor awareness training content to the user groups whose knowledge checks show persistent misunderstandings. Analyze phishing, survey, and assessment results together to identify where behavior and understanding diverge. | ||
| NIST CSF 2.0 | PR.AT-01 — Awareness and Training are provided to users and personnel in accordance with risk management strategy | The three signals support a risk-based awareness and training program. |
| Recommendation — Use the combined results to adjust awareness and training by role, risk, and observed behavior. | ||
Practitioner Guidance
What to prioritise: Treat the three results as a triage tool, not a scorecard. Prioritise groups where knowledge is high but behaviour is poor, because that usually points to a control or usability problem rather than a content problem.
What to verify: Check whether the phishing scenarios, survey wording, and knowledge questions are all aimed at the same user population and the same risk theme. If they are misaligned, the comparison will be noisy and can lead to the wrong training decision.
Decision rule: If users understand the risk but do not report suspicious activity, improve reporting support and feedback first; if they misunderstand the risk, adjust training and messaging; if they distrust the process, fix the culture signal before expecting better behaviour.
Practitioner takeaway: The value is not in measuring more, but in using the mismatch between belief, knowledge, and behaviour to identify which part of the security programme actually needs to change.