Information security awareness
Knows the most common threats such as phishing, ransomware and deception, recognises their signals and knows which action is then expected.
How hrmforce measures this
- Assessment method
- Knowledge test · rho 0.40 (SD 0.13)
- hrmforce instrument
- Knowledge test (client-specific)
- Competency (50-framework)
- Environmental Awareness
- Trainability
- high
- Demand outlook 2026 to 2030
- rising
Test of declarative job knowledge, usually assembled per client.
Behavioural anchors
| Level | Behaviour at this level |
|---|---|
| N1 Guided | Recognises an obvious phishing message, does not click and reports the message through the designated channel. works under supervision and follows instruction · routine, one variable at a time · own task |
| N3 Proficient | Explains to colleagues how threats work, judges doubtful cases independently and adapts own behaviour to new threats. sets own approach and seeks input proactively · several variables, some ambiguity · own team or process |
| N5 Leading | Designs the organisation's awareness programme, measures its effect and adjusts the approach based on measured results. sets the standard and the policy · strategic, under high uncertainty · organisation, value chain or profession |
N2 and N4 are deliberately not anchored. Raters place them between the anchors, following the O*NET convention.
Underlying skills
These skills inherit the assessment route and the behavioural anchors of this construct.
| T | Skill | Definition | Demand outlook 2026 to 2030 |
|---|---|---|---|
| K | Recognising phishing Phishing | Recognises suspicious senders, links and requests in messages and does not click before authenticity is checked. | rising |
| K | Recognising ransomware Ransomware | Recognises ransomware signals such as encrypted files and ransom notes and disconnects from the network immediately. | rising |
| K | Recognising social engineering Social engineering | Recognises attempts to obtain access or data through trust, time pressure or authority and verifies first. | rising |
| K | Recognising CEO and invoice fraud CEO fraud · Invoice fraud | Recognises fake requests for urgent payments or changed bank details and verifies through a known second channel. | rising |
| K | Recognising account takeover Account takeover | Recognises signals of a compromised account such as unknown logins and changed rules and reports it immediately. | rising |
| V | Reporting a suspicious message Reporting suspicious email | Reports a suspicious message through the agreed route without forwarding it and deletes it only after reporting. | rising |
| V | Running a security awareness campaign Security awareness | Sets up a campaign with learning goals, recurring moments and measurable change in employee behaviour. | rising |
| V | Running a phishing simulation Phishing simulation | Runs a controlled test mail, measures click behaviour and feeds results back without penalising people. | rising |
| K | Safe use of usb and peripherals Removable media | Does not connect unknown media or cables, uses approved equipment and encrypts business media. | stable |
| K | Knowing workplace security rules Security policy | Knows the organisation rules on access, visitors, data classification and reporting and acts accordingly. | stable |