Company leadership believes employees are experiencing an increased number of cyber attacks; however, the metrics do not show this. Currently, the company uses “Number of successful phishing attacks” as a KRI, but it does not show an increase.
Which of the following additional information should be the Chief Information Security Officer (CISO) include in the report?
- The ratio of phishing emails to non-phishing emails
- The number of phishing attacks per employee
- The number of unsuccessful phishing attacks
- The percent of successful phishing attacks
Reveal Solution Next Question