The European Union is launching its annual Cybersecurity Month on 1 October amid a significant gap between employees' awareness of digital threats and their actual behaviour in everyday work: while 83% acknowledge that the consequences of cyberattacks are serious, only one in two follows basic digital protection rules. This is according to newly published data from a Eurobarometer survey.
According to the study, three-quarters of workers in EU countries have encountered suspicious emails, messages or links in the workplace at least once. The most common threat was phishing: 39% of respondents reported receiving fraudulent messages or encountering fake websites designed to steal data or gain unauthorised access. Another 18% noted attempts to steal personal data, 17% encountered malware, 16% faced attempts to steal passwords, and 15% came across fraudulent schemes created using artificial intelligence.
The overwhelming majority — 83% of surveyed workers — regard the potential consequences of cyberattacks as serious. A significant share also recognises the risks associated with basic cybersecurity violations: 76% consider it dangerous to click on a link without first checking the sender, and 74% say the same about using the same password for personal and work accounts.
In practice, however, this knowledge is applied far less often. Only 54% of workers said they check the sender before clicking on links, and just half consistently lock their computer when leaving their workplace. Although 72% claim they can recognise a suspicious email, only 48% are confident in their ability to distinguish a fake video generated by AI.
The European Commission notes that awareness levels and adherence to basic cyber hygiene rules vary markedly by age: young people aged 15 to 24 demonstrate lower levels of awareness, which the Commission believes points to the need for more targeted training.