Applied Judgment Assessment
Applied skill assessment · every member of staff, in any role, once a year · browse the full catalogue

Workplace Cybersecurity Awareness Assessment for Annual Recertification of All StaffNext year you will sit this again. This year's report tells you what next year's would have to show.

Thirty-nine short exercises on the ordinary attack surface of a working week: a message asking for something, a request for a code, a file leaving where it should be, a voice on the phone claiming to be somebody, and the decision to report or not. Scored against published guidance and chance-corrected against how people typically answer, weighted by a printed blueprint of how much of the week each domain governs, and decided three ways against a declared cut: recertified, on the boundary, or recertify now. Every scale carries a pair of marks that a sitting next year would have to pass to count as real change. One payment covers the sitting and the report together.

30 minutes39 scored exercisesEvidence-keyed scoringGlobal · INR & USD

An annual recertification that measures current practice, prints its own threshold, and never calls a person a fail on noise

The Workplace Cybersecurity Awareness Assessment for Annual Recertification is a thirty-minute knowledge-and-action-choice instrument for every member of staff. It measures what a person knows current practice requires across five domains of an ordinary working week, decides recertification three ways against a declared cut, and prints the movement a sitting next year would need to count as real change.

Security-awareness products sell teaching by the seat, by the month, for every employee, with a completion certificate at the end. What almost none of them publish is a measurement: how much of the current practice a particular person actually holds this year, with the error stated, against a cut that is written down. That is what an annual recertification is supposed to be, and it is the only thing this instrument does. It teaches nothing; each exercise's rationale points to the public guidance it was keyed from, and the report says where the ground was lost.

Fourteen situations offer the same four routes every time, act on it, stop and check one named thing, refuse and report, or leave it, and only the situation changes: a supplier's new bank account from the usual address, a gift-card request from an account that joined this morning, a restart notice from IT with nothing to click. Six select-every-line exercises ask what may and may not be done with a password, a laptop, an access badge, an outside attachment, a spreadsheet of personal details and the codes in an authenticator app. Six true-or-false claims separate current guidance from what teams still believe about rotation, the padlock, codes by text, files that are only inside, public chargers and personal cloud copies. Five matching exercises put each request against the one check that settles it, four ordering exercises walk the first four steps after a wrong recipient, a lost phone, an encrypted screen and a found memory stick, and two pretext calls are spoken on your own device with the written version available at any time.

The five domains are anchored on Area 4, Safety, of the European Commission Joint Research Centre's Digital Competence Framework for Citizens, DigComp 2.2, reused under its Creative Commons Attribution licence with attribution; the Commission and its Joint Research Centre do not endorse this instrument and no affiliation is claimed. Keying comes from published public guidance on passwords, multi-factor authentication, phishing, business email compromise, voice phishing and incident reporting, from national cyber-security centres and consumer-protection bodies, and no vendor or product is named anywhere in it.

Each domain is scored as chance-corrected accuracy against a declared answer prior on every option, line, pair and position, so that zero is a respondent answering the way people typically answer and a habit such as refusing everything or checking everything scores well below them. The five domains carry a printed blueprint of how much of the week each one governs, with the reason for each share, beside equal weights, and the page says which set the arithmetic used and why. Reliability decides only whether a domain may carry a number of its own: two domains are short by construction and carry a placement word and no figure, with the refusal printed where the scale would have gone, and both still count toward the composite at their share.

The report is a change-threshold card. One scale per domain and one for the composite, each with today's score inside its 68 and 95 per cent bands and a pair of marks either side that a sitting next year would have to pass, with the span between them shaded and captioned on the drawing itself: a sitting next year anywhere in here would not be distinguishable from today. Domains are ranked by that threshold, narrowest first, because the narrowest is the one most able to show a real change next year. The decision is read off the whole 95 per cent band against the cut: recertified only when the whole band clears it, recertify now only when the whole band is under it, and on the boundary in words otherwise, which is a third outcome and never a fail.

One three-way decision, five domains on a change-threshold card, and a printed threshold for next year:
Messages and requestsCredentials, codes and accessDevices, files and where data goesPeople, doors and phonesNoticing and reporting

What you walk away with

A three-way recertification decision, read off the whole band

Recertified when the whole 95 per cent band of the composite clears the declared cut, recertify now only when the whole band is under it, and on the boundary in words whenever the cut lies inside the band. The reasons are printed beside the decision, and the page says which decision carries the reliability.

The change-threshold card, narrowest measurement threshold first

One scale per domain with today's score inside its 68 and 95 per cent bands and a pair of marks either side, the span between them shaded and captioned on the drawing: a sitting next year anywhere in here would not be distinguishable from today. Under every scale, what would move that domain and what would not.

The blueprint weights, with their reasons, beside equal weights

How much of an ordinary week each domain governs, declared and printed with its reason next to the equal-weight figure, and a printed statement of which set the arithmetic used: differential weights only when the reliability spread justifies them, unit weights otherwise, and the page says so.

The voice on the line, reported apart from every figure

Two pretext calls, a service desk wanting a code and an assistant wanting a payment released, spoken on your own device with the written version available at any time. A call delivered in writing is refused as a listening claim and printed as delivered in writing, never scored as a failure and never hidden.

Every refusal printed where the figure would have gone

An empty sitting scores exactly zero and describes nothing. A domain too short to carry a number carries a placement word and its printed refusal, full size, in the place the scale would have taken, and still counts toward the composite. The reliability table says, part by part, what each figure is permitted to claim.

One if-then, and next year's threshold in numbers

A single boxed sentence naming a specific situation and a specific behaviour, drawn from the domain furthest behind, followed by the score a sitting next year would have to reach or fall to for the change to count as real, and the sentence separating that measurement threshold from the smaller number whoever pays for the training would actually care about.

Inside your report

Illustrative sample — your report is generated from your own responses.

The change threshold card: one scale per domain, narrowest measurement threshold first, then the composite the decision reads
This year's recertification decision, read off the whole 95% band
On the boundary

Composite 33, 95% band 20 to 46; the cut of 50 lies inside the band, so this measurement cannot tell recertified from recertify now at this length. A third outcome, never a fail.

● today · filled block 68% · outlined box 95% · ▲ ▲ a pair of marks either side, never a target · shaded span = not distinguishable from today · dashed line = typical · solid line = the cut
1. Messages and requests · 30% of the blueprint
Above the typical respondent · threshold 42 points either side
a sitting next year anywhere in here would not be distinguishable from today0 = typicallower mark 20upper mark 100 (ceiling)-100 = every answer wrong100 = every answer right
What would move it. Deciding every request by what it asks for and by which channel, not by how familiar the sender looks.
What would not. Treating every message as an attack: two of the fourteen are ordinary instructions.
2. Credentials, codes and access · 20% of the blueprint
Above the typical respondent · threshold 45 points either side
a sitting next year anywhere in here would not be distinguishable from today0 = typicallower mark -4upper mark 86-100 = every answer wrong100 = every answer right
What would move it. Asking which container a file belongs in before it moves, and reporting a lost device inside the hour.
What would not. A stronger password on a personal account: the copy is still outside the organisation's control.
3. Devices, files and where data goes · 20% of the blueprint
About typical · threshold 46 points either side
a sitting next year anywhere in here would not be distinguishable from today0 = typicallower mark -38upper mark 54-100 = every answer wrong100 = every answer right
What would move it. Treating a code and a login as things never handed over, whoever asks and however good the reason.
What would not. Rotating passwords more often. The exercises count who holds the credential, not how strong it is.
4. People, doors and phones · 15% of the blueprint
Placement only: below the typical respondent
No figure, no band and no threshold pair, printed where the scale would have gone

5 of 5 exercises answered, under the 8 a figure needs. This domain carries a placement word and no figure, by construction, and still counts toward the composite at 15 per cent.

5. Noticing and reporting · 15% of the blueprint
Placement only: about typical
No figure, no band and no threshold pair, printed where the scale would have gone

5 of 5 exercises answered, under the 8 a figure needs. This domain carries a placement word and no figure, by construction, and still counts toward the composite at 15 per cent.

The composite, the scale the decision reads · threshold 19 points either side
a sitting next year anywhere in here would not be distinguishable from today0 = typicalcut 50lower mark 14upper mark 52-100 = every answer wrong100 = every answer right
Tabular fallback for the card, in ladder order, the composite last.
PartScore95%Lower / upperPlacement
Messages and requests6233 to 9120 / 100▲ above the typical respondent
Credentials, codes and access419 to 73-4 / 86▲ above the typical respondent
Devices, files and where data goes8-25 to 41-38 / 54▬ about typical
People, doors and phones——withheld■ placement only: below the typical respondent
Noticing and reporting——withheld■ placement only: about typical
Composite3320 to 4614 / 52◆ on the boundary against the cut of 50

How to read it: the two marks are a pair, either side of today, never a target. A sitting next year that lands between them is within measurement error and is drawn flat, not as an arrow. The ladder is ordered by the measurement threshold itself, not by the drawn span. This is a measurement threshold; the smaller number that would matter to whoever pays for the training is a different thing and the report says so.

The blueprint weights, with their reasons, beside equal weights, and which set the arithmetic used
Blueprint-weighted 35, equal-weighted 33: unit weights were used, and this is why

The reliability spread across the five domains is 0.13, under the .15 at which differential weighting earns its keep. Hand-tuned weights below that point fit noise. The blueprint is still printed, because it is the value judgement the reader should see, and the decision read the equal-weighted figure.

Messages and requests■ blueprint 30%□ equal 20%, usedCredentials, codes and access■ blueprint 20%□ equal 20%, usedDevices, files and where data…■ blueprint 20%□ equal 20%, usedPeople, doors and phones■ blueprint 15%□ equal 20%, usedNoticing and reporting■ blueprint 15%□ equal 20%, used0%35%
Tabular fallback: each domain, its blueprint share and its reason, its equal share, and its score.
DomainBlueprintEqualScoreWhy this share
Messages and requests30%20%62The largest share, because most of the attack surface of a week arrives as a message asking for something, and it arrives every day.
Credentials, codes and access20%20%41A fifth, because a laptop, a memory stick, a shared link and a copied spreadsheet are where data leaves quietly, without any attacker at all.
Devices, files and where data goes20%20%8A fifth, because a password, a code or a sign-in prompt is what nearly every successful attack is ultimately after.
People, doors and phones15%20%-12 (placement only)A smaller share, because a person at a door or a voice on the phone is rarer than a message, though each one is rehearsed for a particular person.
Noticing and reporting15%20%4 (placement only)A smaller share by frequency, though it is the domain that limits the cost of every other: whether a thing noticed is reported, and how fast.

How to read it: the blueprint is a value judgement about how much of an ordinary week each domain governs, not a measurement, and it would be different for another setting, which is why each share carries its reason. Reliability decides only whether a domain may carry a number of its own, never how much it counts: a domain can hold fifteen per cent of the composite and still be refused a figure, and the card says both things.

Built for

  • Every member of staff in any role who sits an annual cybersecurity awareness check, and wants the result to be a measurement with its error stated rather than a certificate of attendance
  • Security and compliance leads who need whole-workforce recertification evidence per person, with a declared cut, a printed threshold for next year and a three-way outcome that never fails somebody on noise
  • Human resources and learning teams replacing a generic annual quiz with something that says which of five domains to spend the next year's training on, and what movement would count
  • Small and mid-sized organisations that need everybody recertified every year at a price under the cheapest per-seat training subscription, without buying a teaching platform to get the measurement

Sit this year's recertification, and see what next year's would have to show

39 exercises across seven formats · about 30 minutes · one payment covers the sitting and the report together: ₹399 in India inclusive of GST, or US$3.99 elsewhere. The report is a change-threshold card with a three-way decision, five domain scales with a pair of marks each, the blueprint printed with its reasons, and one action for the next occasion. Sit it again in twelve months.

₹399 (incl. GST) · assessment and full report, nothing further to pay

Buy this assessment

No account needed to buy. Your name and email identify the purchase and your receipt is sent to that address.

Secure Razorpay payment · ₹399 includes 18% GST

Bought this already and lost the tab? Sign in and enter your purchase code under Claim a purchase on your dashboard.

Secure checkout · INR & USDFull report immediately after submission

Frequently asked questions

Is this the same as the security awareness training my organisation already buys?

No. Awareness training is teaching, sold per seat per month, and it ends with a completion certificate. This is a measurement, sat once a year: thirty-five keyed exercises on what current published practice requires across five domains of an ordinary working week, chance-corrected against how people typically answer, weighted by a printed blueprint, and decided three ways against a declared cut. It teaches nothing, though every exercise's rationale points to the public guidance it was keyed from, so the report says exactly where the next year's training should go. It is priced as a one-off annual measurement, under the cheapest annual per-seat training subscription, because everybody has to sit it every year.

How is it different from the other security assessments in this catalogue?

There are two. The information-security-awareness product is a short generic legacy quiz. The social-engineering-defence product is a situational-judgement test of phishing and pretexting judgment, asking what you would do and reported as a lure board. This instrument is neither: it is a blueprint-weighted, chance-corrected measurement of current practice across five declared domains with a published recertification threshold, and it contains no situational-judgement item at all. Every scored exercise asks what current published guidance requires, never what you would do. The digital-competence check in this catalogue uses a whole public competence framework as its spine; this one uses a single area of that framework as one of its five domain anchors.

What do recertified, on the boundary and recertify now actually mean?

The composite is scored on a scale from minus one hundred to one hundred where zero is a respondent answering the way people typically answer, with a declared cut of fifty, which is about seventy-three per cent raw on the complete form. Recertified means the whole 95 per cent band of your composite is at or above the cut. Recertify now means the whole band is under it. On the boundary means the cut lies inside the band, so this measurement cannot tell the two apart at this length; it is a third outcome, it is never a fail, and the honest next step is a sitting within the quarter. The decision on the card is the one carrying the reliability band, and the page says so.

What is the change threshold, and why is it printed before I have sat it twice?

It is the movement a sitting next year would have to exceed to count as real change rather than measurement error, computed from the Reliable Change Index: 1.96 times the declared standard deviation times the square root of twice one minus the assumed reliability. It is printed on the first sitting as a pair of marks either side of today's score, with the span between them shaded and captioned that a sitting next year anywhere inside it would not be distinguishable from today. Domains are ranked by that threshold, narrowest first. It is a measurement threshold, and the report distinguishes it in words from a minimally important difference, the smaller, value-laden number whoever pays for the training would set by asking how much change would matter.

How much does it cost, how long does it take, and what happens with the spoken calls?

One payment covers the sitting and the report together: ₹399 in India inclusive of GST, or US$3.99 elsewhere, one time, and it is sat again in twelve months. Thirty-nine exercises across seven formats take about thirty minutes. Two of them are pretext calls spoken on your own device from written text, at most twice each, with the written version available at any time; they are reported on their own and never inside the composite. If your device cannot speak, or you ask for the written version, the answer records that the call was delivered in writing, and the report refuses it as a listening claim rather than scoring it as a failure. No percentile appears anywhere, and nothing on the report ranks you against anybody.

One of the AssessAll applied-judgment assessments

Each one takes a single capability, puts you inside the situations where it is actually tested, and scores your choices against published evidence — with a report designed for that capability alone, not a template. They span hiring, compliance, education, operations and personal skill.

Browse the catalogue →

Methodology: Thirty-nine original exercises across seven formats: fourteen single-choice situations that offer the same four routes every time, act on it, stop and check one named thing, refuse and report, or leave it, with only the situation changing; six select-every-line exercises on what may and may not be done with a named class of data, device or credential, keyed at two, three and four lines; six true-or-false claims separating current practice from what teams still believe about password rotation, the padlock, codes by text, files that are only inside the organisation, public chargers and personal cloud copies; five matching exercises with more entries on the right than the left, each request against the one check that settles it; four ordering exercises on the first four steps after a wrong recipient, a lost phone, an encrypted screen and a found memory stick; two pretext calls synthesised on the respondent's own device from the written text, with the written version available at any time and the delivery route recorded in the answer; and two counts about the respondent's own week that sit outside every scored scale. DECLARED RESPONSE INSTRUCTION: one instruction for the whole instrument and it is a KNOWLEDGE instruction. Every scored exercise asks what current published practice requires in a described situation; none asks what the respondent would personally do, and no scored exercise is a situational-judgement item. CONSTRUCT STATEMENT: this measures what a member of staff in any role does with the ordinary attack surface of a working week, across five domains: messages and requests; credentials, codes and access; devices, files and where data goes; people, doors and phones; and noticing and reporting. It does not measure technical security skill, any named product, the respondent's judgement under pressure, their honesty, their personality, or whether they would actually behave as they answered; it does not audit any organisation's security; and it is not a professional certification. HOW IT DIFFERS FROM THE LIVE NEIGHBOURS: the legacy information-security-awareness product is a short generic quiz; the social-engineering-defence product is a situational-judgement test of phishing and pretexting judgment reported as a lure board. This instrument is a blueprint-weighted, chance-corrected measurement of current practice across five declared domains with a published recertification threshold, and it contains no situational-judgement item at all. The digital-competence-check product uses the whole European Digital Competence Framework for Citizens as its spine; this instrument uses one of that framework's five areas as one of five domain anchors. FRAMEWORK ANCHOR: the five domains are anchored on Area 4, Safety, of DigComp 2.2, The Digital Competence Framework for Citizens (Vuorikari, Kluzer and Punie, 2022, Publications Office of the European Union, EUR 31006 EN), published by the European Commission's Joint Research Centre under a Creative Commons Attribution 4.0 licence and reused here with attribution; its competences on protecting devices and on protecting personal data and privacy carry the credentials, devices and data domains, and the messages, people and reporting domains are drawn from the public guidance below. ENISA's European Cybersecurity Skills Framework (2022) is cited as a secondary public reference for the awareness role profile. The European Commission, its Joint Research Centre, ENISA and the authors of those frameworks do not endorse this instrument and no affiliation is claimed. SCORING DESIGN, C20: a blueprint-weighted content composite. Each domain is chance-corrected accuracy over its answered exercises against the DECLARED per-option marginals authored on every option, line, pair and position, never a uniform draw, so that zero means answering the way people typically answer. Five domains carry a declared share of the composite, printed with the reason for each share, beside the equal-weight composite; which set the arithmetic uses is decided by the reliability spread across the domains, differential only above .15 and unit weights otherwise, stated on the page. Reliability per domain is McDonald's omega estimated from the answered count and an assumed inter-item correlation of .25 until live data exist; a domain under eight answered exercises or under omega .70 carries a placement word and no figure, and the two domains of five keyed exercises each do so by construction on a complete sitting while still counting toward the composite at their declared weight. Every figure carries its standard error band from a declared modelled standard deviation. The recertification decision reads the whole 95 per cent band of the composite against a declared cut of 50 on the corrected scale, whose raw equivalent is printed: recertified, on the boundary, or recertify now, never a bare pass or fail. The reliable-change threshold for a sitting next year, 1.96 times the declared standard deviation times the square root of twice one minus omega, is printed today as a pair of marks either side of every figure, and the domains are ranked by that measurement quantity, narrowest first. The two spoken calls are reported as their own strand outside the composite, and a call delivered in writing is refused as a listening claim and printed as delivered in writing, never scored as a failure. No percentile appears anywhere because no norm group exists yet. KEYING SOURCES, all public guidance and none a vendor product: the United Kingdom National Cyber Security Centre's guidance on password administration for system owners, on three random words, on multi-factor authentication for online services, on phishing attacks and defending an organisation, on what to do about a suspicious email, and on lost or stolen devices; the United States National Institute of Standards and Technology Special Publication 800-63B, Digital Identity Guidelines, on the withdrawal of forced rotation and the restriction of codes sent by text; the Cybersecurity and Infrastructure Security Agency's guidance on avoiding social engineering and phishing attacks and on business email compromise; the Federal Bureau of Investigation Internet Crime Complaint Center's public service announcements on business email compromise and its annual Internet Crime Report; the Federal Trade Commission's consumer guidance on gift-card scams and on recognising and avoiding phishing; the Federal Communications Commission's advisory on public charging stations; the Australian Cyber Security Centre's guidance on multi-factor authentication and on lost or stolen devices; the Indian Computer Emergency Response Team's directions of April 2022 on incident reporting and its public advisories on voice phishing; the United Kingdom Information Commissioner's Office guidance on personal data breaches, and the incident-notification provisions of the General Data Protection Regulation and of India's Digital Personal Data Protection Act 2023, both named factually; ENISA's Threat Landscape report for the prevalence of social engineering; and, for the psychometrics, Jacobson and Truax (1991) for the Reliable Change Index, McDonald (1999) for omega, Wainer (1976) on unit weights, Haladyna, Downing and Rodriguez (2002) for item writing and cue control, and Harvill (1991) for the standard error of measurement. Every exercise is an original work written for this instrument. No commercial instrument's items or name is reproduced, no security vendor or product is named anywhere, and no certification body's mark appears.