TALLINN - According to a Eurobarometer survey published by the European Commission, three-quarters of European Union employees have encountered suspicious emails, messages, or links at work.
The most common cyber threat in the workplace is phishing. 39 percent of EU and 31 percent of Estonian employees reported fraudulent messages or websites aimed at stealing data or gaining unauthorized access. Also mentioned were attempts to steal personal data and passwords, malware attacks, and AI-generated fraud.
"Today's Eurobarometer survey shows that people are very aware of cybersecurity. But understanding the risk is not the same as being prepared for it. Phishing, AI-generated scams, and other cyber threats can cause serious harm to businesses and public services, and reduce trust in the digital economy. Now, as European Cybersecurity Month begins, this survey reminds all citizens, employers, and organizations that we must also take action. The Commission is working hard to ensure that more effective cybersecurity measures are adopted across Europe, that skills are developed, and that preparedness is increased. Good cyber hygiene should be part of daily activities. This includes using strong passwords, checking senders before opening links, and reporting suspicious messages," commented Henna Virkkunen, Executive Vice-President responsible for technological sovereignty, security and democracy.
Employees admit to often behaving riskily, especially in situations related to phishing and password management. Although 85 percent of respondents considered the potential consequences of cyberattacks to be serious, only about half thought they could recognize an AI-generated fake video. Just under a fifth of respondents confirmed that, to their knowledge, their organization had not experienced any cyber incidents at all.
Of those who use digital systems and tools at work, 76 percent of EU and 87 percent of Estonian residents said that clicking a link without checking the sender is risky. A similar proportion thought that using the same password for personal and work accounts is also dangerous. 69 percent of employees felt that sharing work-related information on social media poses a threat. Most employees are also aware that they should report suspicious emails and install software updates.
Unfortunately, this awareness is often not reflected in daily practice. Although nearly three-quarters of those surveyed said they could identify suspicious emails, only slightly more than half confirmed that they always check the sender before opening links, and only half of the respondents claimed to always lock their computer when leaving their workstation.
Basic cyber hygiene habits, such as checking senders before opening links and using strong passwords, are common but are used inconsistently by employees. Awareness of cyber risks also increases significantly with age. However, younger employees aged 15-24 require targeted training.
Although the survey indicates that most employees believe their organization effectively protects itself against cyberattacks, only about half of organizations have implemented key cybersecurity measures, and a quarter of organizations plan to introduce them.
Six out of ten employees said they had undergone cybersecurity training in the past year. Participation is noticeably lower in smaller organizations. At the same time, 85 percent of respondents said they are interested in improving their cybersecurity skills, but for about a quarter of employees, the main obstacle is a lack of time.
To address these findings, the European Union must apply cybersecurity standards in vital sectors, connected products, and digital services.
The Flash Eurobarometer survey "Cybersecurity in the workplace: employee awareness and preparedness" was conducted online from April 27 to May 8, surveying 25,747 EU citizens from all 27 member states. The results were published as European Cybersecurity Month began - an annual cybersecurity campaign that raises awareness of online security risks.
2026 © The Baltic Times /Cookies Policy Privacy Policy