KnowBe4: Employee Distraction, Not Sophistication, is Top Cybersecurity Risk

This title was summarized by AI from the post below.
View profile for Jonathan S. Weissman

Rochester Institute of…38K followers

KnowBe4 Finds Top Cybersecurity Risk is Employee Distraction, Not Threat Sophistication LEEDS, England, Aug. 26, 2025 /PRNewswire/ -- KnowBe4, the world-renowned cybersecurity platform that comprehensively addresses human risk management, today released a new report entitled Navigating Cyber Threats: Infosecurity Europe 2025 Findings. The findings show that cybersecurity professionals are sounding the alarm; not about increasingly sophisticated cyber threats, but about something far more human – distraction. The new research from KnowBe4, surveyed more than 100 security professionals during the Infosecurity Europe 2025 conference to gauge the current state of cybersecurity concerns. The main findings of the report include: Distraction is a Top Cybersecurity Weakness: Distraction (43%) and lack of security awareness training (41%) are identified as primary reasons employees fall victim to cyberattacks, rather than attack sophistication. Phishing Remains Dominant: Phishing is the leading threat (74%), with impersonation of executives or trusted colleagues being the most common tactic. AI-generated threats are not yet dominant but fears about their rise are growing. Cybersecurity Spending Increase with Alignment Gaps: 65% of organisations plan to increase cybersecurity budgets, with top investment areas including email security and security awareness training. However, there is a disconnect between perceived effectiveness of AI-based tools (32% believe greatest impact) and their prioritisation for funding (26%). Anticipation of the AI Tipping Point: 60% of organisations fear the rise of AI-generated threats, suggesting preparation for future threats while still dealing with current human risks. The Confidence Paradox: Nearly 90% of respondents express confidence in their ability to respond to cyberattacks, which appears inconsistent with breach frequency and known vulnerabilities. This overconfidence is considered a risk in itself. https://lnkd.in/g7urgucV

To view or add a comment, sign in

Explore content categories