Three quarters of EU employees have encountered suspicious emails or messages at work

Three quarters of EU employees have encountered suspicious emails or messages at work

The extent of the cyber threat to European businesses has been laid bare by a new report from Eurobarometer, which has revealed that three quarters of employees in the EU have encountered suspicious emails, messages or links at work.

As the report found, phishing was the most commonly reported workplace cyber threat, with two fifths (39%) of employees saying they had encountered fraudulent messages or websites designed to steal data or gain unauthorised access.

Other reported threats included attempts to steal personal data, which were reported by 18% of employees, along with attempted password hacks (16%), malware attacks (17%), and artificial intelligence (AI)-generated scams (15%).

‘While most employees believe, according to the survey, that their organisation is effective in protecting against cyberattacks, only around half of organisations have key cybersecurity measures in place, and a further quarter plan to introduce them,’ Eurobarometer noted.

Security gap

The findings also show a gap between employees’ awareness of cybersecurity risks and their everyday behaviour. While 83% said the potential consequences of cyberattacks were serious, fewer than half (48%) said they could recognise an AI-generated fake video.

Less than a fifth (18%) said their organisation had experienced no cyber incident at all, as far as they were aware.

On the positive side, the survey found that employees generally recognised several forms of risky behaviour – among those using digital systems and tools at work, 76% considered clicking on a link without checking the sender, while 74% identified using the same password for private and work accounts as a risk.

A further 69% said sharing work-related information on social media could pose a cybersecurity risk.

However, this awareness did not consistently translate into practice. Although 72% said they could identify suspicious emails, only 54% said they checked the sender before opening links.

The survey found that awareness of cybersecurity risks increased significantly with age, with the Commission highlighting the need for targeted training among younger employees aged 15 to 24.

Elsewhere, 60% of employees said they had received cybersecurity training during the previous year, although participation was significantly lower in smaller organisations. At the same time, 85% said they were interested in improving their cybersecurity skills, with lack of time identified as the main barrier by 26%.

‘Awareness to action’

“Phishing, AI-generated scams and other cyber threats can seriously harm businesses, public services and trust in the digital economy,” commented Henna Virkkunen, Executive Vice-President for Tech Sovereignty, Security and Democracy.

“As European Cybersecurity Month begins, this is a reminder to every citizen, every employer and every organisation that we must move from awareness to action. The Commission is working to strengthen skills, improve preparedness and support stronger cybersecurity measures across Europe. Good cyber hygiene, such as using strong passwords, checking senders before opening links and reporting suspicious messages, must become part of everyday practice.” Read more here.

Discover more from Europe-Data.com

Subscribe now to keep reading and get access to the full archive.

Continue reading