Most employees already know that clicking on a suspicious link or using the same password for work and personal accounts is a bad idea. But when it comes to everyday practice, Europe’s cyber hygiene starts to slip.
Three in four employees have encountered a suspicious email, message or link at work, according to a new Eurobarometer survey. Phishing remains the most common threat, with fraudsters trying to trick people into handing over data or gaining unauthorised access through deceptive messages and websites. Employees also reported attempts to steal personal data or passwords, malware and scams created with the help of artificial intelligence.
Good cyber hygiene, such as using strong passwords, checking senders before opening links and reporting suspicious messages, must become part of everyday practice. — Henna Virkkunen, Commissioner for Tech Sovereignty, Security and Democracy
Published by the European Commission on the eve of European Cybersecurity Month, which takes place every October, the survey points to an awkward paradox: European employees generally understand the risks, but their behaviour does not always follow suit.
Knowing is not enough
There is little doubt that people do understand the basics of cyber risk. Most employees, for example, see clicking on a link without checking the sender as risky. They feel similarly about using the same password for work and personal accounts or sharing work-related information on social media. At the same time, 83 per cent of employees said a cyberattack could have serious consequences for their organisation.
But knowing the rules is not enough. While 72 per cent of employees are confident they can spot a suspicious email, only 54 per cent say they always check the sender before opening a link. And only half always lock their computer when they leave their desk.
That gap between what people know and what they actually do is one of the survey’s main findings. This does not necessarily mean employees are ignoring cybersecurity. Rather, some safety measures still do not seem as automatic as locking the door when leaving the office.
“Good cyber hygiene, such as using strong passwords, checking senders before opening links and reporting suspicious messages, must become part of everyday practice,” said Henna Virkkunen, European Commission Executive Vice-President for Tech Sovereignty, Security and Democracy.
AI adds a new layer to an old problem
An old problem now comes with a new complication: artificial intelligence. And this is where experience with traditional online fraud may no longer be enough. Only 48 per cent of respondents said they could recognise a video created using AI. And whether they could actually spot one in practice is another question.
That matters because the line between real and artificially generated content is becoming harder to see. An employee may no longer receive just a poorly written email with a suspicious link. A scam can now come wrapped in a convincing image, voice or video.
The survey also highlights a generational gap. Some 81 per cent of employees aged 15 to 24 reported encountering suspicious messages, emails or links, compared with 54 per cent of those aged over 50. At the same time, awareness of cyber risks rises significantly with age. The Commission therefore points to the need for targeted training, particularly for younger workers.
Employees want to learn, but there’s no time
For companies, that creates another challenge. Cybersecurity training is far from unusual: 60 per cent of employees said they had received some form of training in the past year. But access drops significantly in smaller organisations.
The appetite for more training is high. Some 85 per cent of employees would like to improve their cybersecurity skills, according to the survey. The biggest obstacle is not a lack of interest. One in four employees, or 26 per cent, cited lack of time as the main barrier.
The survey also suggests employees have a fairly positive view of how prepared their organisations are. Yet, according to their responses, only around half of them have key security measures in place, while others are still planning to introduce them.
The EU is tightening the rules
The EU is gradually building a broader cybersecurity rulebook. The NIS2 Directive sets obligations for critical and other important sectors, while the Cyber Resilience Act extends security requirements to connected products and software. The EU is also tackling the shortage of people with the right digital skills through its Cyber Skills Academy.
But rules alone cannot fix what happens at the desk. If an employee knows they should check the sender but clicks before doing so, the gap between awareness and safe behaviour remains.
As Ms Virkkunen put it: “As European Cybersecurity Month begins, this is a reminder to every citizen, every employer and every organisation that we must move from awareness to action.”