Workplace cybersecurity exposure is widespread across the EU, with the vast majority of employees reporting contact with malicious content. However, organisational support for building defences remains patchy, according to findings from a European Commission Eurobarometer survey on cybersecurity awareness and preparedness. The European Union Agency for Cybersecurity (ENISA) highlighted the results during European Cybersecurity Month.
In the six-month period covered by the survey, 74% of workers said they had received suspicious emails, text or voice messages, or links. By contrast, only 45% reported that their organisation regularly provides cybersecurity information or awareness updates. This disparity is significant given that the tactics used to compromise employees are becoming more sophisticated.
ENISA's latest threat landscape assessment, drawn from examination of more than 8,000 incidents, documents the continued prevalence of social engineering alongside an escalating deployment of AI by threat actors.
Phishing Remains the Most Common Threat
Phishing and fraudulent emails dominated the list of suspicious activities reported by workers in the Eurobarometer study, affecting 39% of employees. Personal data theft attempts were cited by 18%, while other threats included malware, password theft, ransomware and AI-generated scams.
Employees demonstrated awareness of the risks involved. Some 83% believed a cyberattack would inflict serious damage on their organisation, and 82% expressed confidence in their organisation's digital systems and tools as defences against such attacks.
Yet technical safeguards alone cannot eliminate the human element when malicious messages arrive in employee inboxes. ENISA's threat landscape report identified social engineering as a persistent component of attacker strategies, including phishing and ClickFix techniques that trick users into executing hidden malicious code on their machines.
Cybercrime represented 36% of the incidents examined by ENISA during its reporting period. Within financially motivated attacks recorded in 2025, ransomware deployment accounted for 40% of analysed events, data breaches for 31% and fraud and impersonation for 19%.
AI Is Changing the Threats Employees Encounter
Malicious cyber threat groups are increasingly turning to AI to amplify or support their operations, according to ENISA's assessment.
Information manipulation campaigns powered by AI provide a striking illustration of this shift. ENISA identified a 259% increase in AI-enabled foreign information manipulation and interference campaigns, rising from 41 to 147 over a 12-month period.
For organisations, the implications extend beyond specialist security teams. AI-generated scams and refined social engineering tactics place ordinary employees directly in the firing line, confronted with content that can be difficult to distinguish from legitimate material.
This reality underscores the importance of workforce readiness as part of any comprehensive security response.
The Eurobarometer survey found that 85% of employees expressed interest in upgrading their cybersecurity capabilities. However, workers identified multiple obstacles to pursuing such development. Time constraints at work emerged as the leading barrier, cited by 26%, while 16% pointed to cost. Additional challenges included inadequate information about available training and insufficient organisational backing.
Workplace Skills Are Struggling to Keep Pace With Change
The cybersecurity findings align with broader evidence of a mismatch between technological advancement and employee capability development.
Research by PwC on AI and workforce skills revealed that 64% of workers had used AI in their roles over the previous 12 months, a 10 percentage point increase year-on-year. Simultaneously, the share of employees reporting access to adequate learning and development resources fell from 59% to 51%.
While the PwC study does not specifically measure cybersecurity training and the two surveys address different workplace dimensions, together they illustrate a pattern: employees are navigating rapid technological shifts while institutional support for their development remains inconsistent.
This tension becomes especially acute when AI is reshaping both sides of the equation simultaneously. Workers are expected to integrate AI into their daily tasks, while simultaneously encountering threats that leverage the same technology to become more convincing and effective.
The task for employers therefore extends beyond promoting tool adoption. Staff also require the competencies to operate securely as the digital landscape surrounding those tools transforms.
Cybersecurity Awareness Needs to Become Preparedness
ENISA is leveraging European Cybersecurity Month to advance awareness and skills development across both organisations and the public.
The agency's toolkit includes Awareness Raising-in-a-Box, a resource designed to assist organisations in building cybersecurity awareness programmes, and the European Cybersecurity Skills Framework, which establishes a shared standard for cybersecurity roles and competencies across EU member states.
The Eurobarometer results suggest demand for such development is already present. The majority of workers surveyed expressed a desire to strengthen their cybersecurity knowledge, and most acknowledged the potential severity of an attack.
The harder question is whether organisations are establishing sufficient pathways for that awareness to translate into actionable capability.
With suspicious content reaching nearly three-quarters of surveyed employees, organisations cannot rely on workers to independently recognise and respond correctly to threats as they encounter them. As AI expands the toolkit available to attackers and increases the sophistication of malicious content, regular skills development becomes essential to how organisations manage cyber risk.



