You trust your team, right?
Theyโre smart, capable, and they know better than to click on suspicious links or open unexpected attachments.
They already know that phishing emails look trustworthy on purpose. To trick them into giving away sensitive data or downloading malicious software.
So, theyโre not the type to fall for it.
At least, thatโs what they thinkโฆ
Hereโs the problem: Just because someoneโs confident they could spot a phishing attack, it doesnโt mean they can. Itโs a false sense of security โ and itโs exactly what cyber criminals count on.
New research has found that a huge 86% of employees believe they can confidently identify phishing emailsโฆ yet over half of them have fallen for some form of scam in the past.
Think about that for a second.
These are people who knew about phishing, felt sure they wouldnโt be tricked, and yet still got caught out. Thatโs because cyber criminals arenโt just sending out the obvious โforeign princeโ emails anymore. Theyโre using sophisticated tactics like:
- Emails that look like theyโre from your bank or suppliers.
- Fake invoices that appear totally legitimate.
- Messages that seem to come from your own colleagues.
Because phishing scams have evolved, theyโre much harder to spot. And when someone thinks theyโre too smart to fall for one, thatโs when theyโre most at risk.
Overconfidence in cyber security is a classic case of the Dunning-Kruger effect โ a psychological phenomenon where people tend to think they know more than they do.
Whatโs the problem with being too confident?
Well, when people believe theyโre invincible to scams, they donโt take the necessary precautions. Instead of double-checking links or questioning unexpected emails, they just assume โIโd never fall for a scamโ and carry on clicking. This is how cyber criminals end up accessing business systems and data.
So, whatโs the good news?
You can lower the risk of getting hit by a phishing attack. But it starts with a shift in mindset. Instead of assuming your people know what theyโre doing, make sure theyโre properly informed. Regular phishing awareness training can make a massive difference, helping your staff to recognise newer and more subtle scams before itโs too late.
Training alone isnโt enough, though. Your employees also need to feel comfortable reporting anything suspicious, or they might stay quiet about a potential scam. And that gives cyber criminals the upper hand. Creating a workplace culture where security concerns are welcomed (not criticised) is just as important as education.
Cyber security isnโt about intelligence; itโs about vigilance. Even the most tech-savvy employee can be caught off guard by a well-crafted scam. The key is to assume a threat is real, remain cautious, and never rely on confidence alone.
The moment someone thinks โIโd never fall for thatโ is often the moment they do.