Close Menu
  • Home
  • Articles
    • Attacks
      • BEC
      • Data Breach
      • DDoS
      • Evasion Attacks
      • Injection
      • Malware
      • MITM
      • Phishing
      • Ransomware
      • RCE
      • Social Engineering
      • Spoofing
      • Spyware
    • Business and Policy
      • BCP and DRP
      • GRC
      • Regulations
    • Data Protection
      • DLP
      • DRM
      • Encryption
      • IAM
    • Future, Trends and Insight
      • AI
      • Events & Community
      • Emerging Tech
      • Expert Panel
      • Interviews With Experts
      • Insights
      • Study & Research
    • Resources
      • Guides
      • Tools
      • Training & Education
    • Security
      • API
      • Apps
      • Cloud
      • Critical Infrastructure
      • Endpoint
      • Hardware
      • IoT
      • Mobile
      • Network
      • OT
      • Port Security
      • Security Architecture
      • Software Development
      • Supply Chain
      • Zero Trust
    • Threats and Vulnerabilities
      • Emerging Threats
      • Insider Threats
      • Risk Management
      • Threat Intelligence
      • Zero Day
  • News and Exclusives
    • Latest News
    • ISB Exclusive
    • Positive News
  • Who We Are
    • About Us
    • Information Security Buzz Expert Panel​
    • Write for Us
    • Media Pack
  • Contact Us
  • Newsletter
Facebook X (Twitter) LinkedIn
Facebook X (Twitter) LinkedIn
Information Security BuzzInformation Security Buzz
  • Home
  • Articles
    • Attacks
      • BEC
      • Data Breach
      • DDoS
      • Evasion Attacks
      • Injection
      • Malware
      • MITM
      • Phishing
      • Ransomware
      • RCE
      • Social Engineering
      • Spoofing
      • Spyware
    • Business and Policy
      • BCP and DRP
      • GRC
      • Regulations
    • Data Protection
      • DLP
      • DRM
      • Encryption
      • IAM
    • Future, Trends and Insight
      • AI
      • Events & Community
      • Emerging Tech
      • Expert Panel
      • Interviews With Experts
      • Insights
      • Study & Research
    • Resources
      • Guides
      • Tools
      • Training & Education
    • Security
      • API
      • Apps
      • Cloud
      • Critical Infrastructure
      • Endpoint
      • Hardware
      • IoT
      • Mobile
      • Network
      • OT
      • Port Security
      • Security Architecture
      • Software Development
      • Supply Chain
      • Zero Trust
    • Threats and Vulnerabilities
      • Emerging Threats
      • Insider Threats
      • Risk Management
      • Threat Intelligence
      • Zero Day
  • News and Exclusives
    • Latest News
    • ISB Exclusive
    • Positive News
  • Who We Are
    • About Us
    • Information Security Buzz Expert Panel​
    • Write for Us
    • Media Pack
  • Contact Us
  • Newsletter
Subscribe
Information Security BuzzInformation Security Buzz
Home - Security - Confidence Gap in Cybersecurity Leaves Businesses at Risk
Security Attacks Business and Policy Latest News News & Analysis Phishing Social Engineering Study & Research

Confidence Gap in Cybersecurity Leaves Businesses at Risk

Kirsten DoyleBy Kirsten DoyleMarch 13, 2025Updated:March 13, 20254 Mins Read
Share LinkedIn Twitter Facebook Copy Link Email
Confidence
Share
Facebook Twitter LinkedIn Email Copy Link
Quick AI Summary
ChatGPTClaudeGeminiGrokPerplexityDeepSeekCopilot

New research has revealed that although 86% of employees believe they can confidently identify phishing emails, nearly half have fallen for scams.  

The study, conducted by KnowBe4, surveyed professionals in the UK, USA, Germany, France, Netherlands, and South Africa and revealed a growing chasm between confidence and competence in identifying cyber threats.  

Interestingly, South Africa leads with both the highest confidence levels and the highest scam victimization rate, suggesting that confidence is unwarranted and fuels a false sense of security, leaving workers more susceptible to advanced cyber threats.  

Fluctuating Confidence Levels 

Across all demographics, confidence levels depended largely on the type of scam. Employees said they were most prepared to detect traditional cyber threats but struggled with more sophisticated deception tactics. Some 86% believe they can confidently identify phishing emails, 83% claimed the same about vishing and social media phishing, followed by smishing 82%, social engineering attacks 67%, and deepfake scams 65%.  

However, 24% of those surveyed have fallen for phishing attacks, and 12% have been tricked by deepfake scams, and over two thirds (68%) of South African employees reported falling for scams—the highest victimization rate.   

A Complex Interplay of Factors 

“The significant variation in confidence levels across regions regarding cyber threat identification stems from a complex interplay of factors,” explains Javvad Malik, Lead Security Awareness Advocate at KnowBe4. “Cultural differences in risk perception and self-assessment play a crucial role, as do the quality and frequency of cybersecurity awareness training programmes.” 

He says exposure to cyber threats, regulatory environments, and media coverage of security issues are also a factor, and technological infrastructure, digital literacy, and language barriers in non-English speaking countries contribute to these disparities. “Corporate culture, historical context of cyber incidents, and socioeconomic factors affecting education and access to technology round out the influential elements,” Malik adds.  

He says these differences suggest a need for a tailored, culturally sensitive approach to cybersecurity training. “This disparity also underscores the importance of not relying solely on self-reported confidence levels when assessing cybersecurity preparedness. Instead, actual performance in simulated phishing tests may provide a more accurate picture of employees’ abilities to identify and respond to social engineering attempts.” 

Susceptibility Factors 

Anna Collard, SVP content strategy and evangelist, KnowBe4, adds that overconfidence fuels a “dangerous blind spot”—employees believe they are wise to scams, but, in reality cybercrooks can exploit more than 30 susceptibility factors.  

These include psychological and cognitive biases, situational awareness gaps, behavioural tendencies, and even demographic traits, Collard explains. “With phishing, AI-driven social engineering, and deepfake scams evolving rapidly, organizations must counteract misplaced confidence with hands-on, scenario-based training. True cyber resilience comes not from assumed knowledge but from continuous education, real-world testing, and an adaptive security mindset.”  

The survey findings emphasize the critical need for personalized, relevant, and adaptive training that caters to employees’ individual needs while considering regional influences and evolving cyber tactics. Organizations that prioritize this approach will not only reduce risk but also cultivate a genuine security-first culture. In the battle against digital deception, the most dangerous mistake employees can make is assuming they are immune.  

Fostering a Transparent Culture 

Over and above training, the report highlights the importance of fostering a transparent security culture. While 56% of employees feel “very comfortable” reporting security concerns, 1 in 10 still hesitate due to fear or uncertainty.  

The report factored in the security behaviours of over 12,000 employees around the world. The full survey findings, “Security Approaches Around the Globe: The Confidence Gap,” are available for download here. 

Kirsten Doyle
Kirsten Doyle
Information Security Buzz News Editor

Kirsten Doyle has been in the technology journalism and editing space for nearly 24 years, during which time she has developed a great love for all aspects of technology, as well as words themselves. Her experience spans B2B tech, with a lot of focus on cybersecurity, cloud, enterprise, digital transformation, and data centre. Her specialties are in news, thought leadership, features, white papers, and PR writing, and she is an experienced editor for both print and online publications.

  • Kirsten Doyle
    AI-Powered Attacks Become Top Concern for Security Professionals, New Filigran Survey Reveals
  • Kirsten Doyle
    ShinyHunters targets Oracle PeopleSoft customers through critical zero-day
  • Kirsten Doyle
    SIG report: AI-generated code is linked to twice the security risk and rising technical debt
  • Kirsten Doyle
    Miasma worm spreads from Red Hat packages to Microsoft repositories

The opinions expressed in this post belong to the individual contributors and do not necessarily reflect the views of Information Security Buzz.

Share. Facebook Twitter LinkedIn Email Copy Link

Related Posts

Building cyber resilience for mission-critical operations in 2026

May 27, 20267 Mins Read

Investigating the aftermath: understanding digital forensics after a cyber incident

May 7, 20265 Mins Read

Microsoft Edge Found Holding Saved Credentials in Plaintext Memory

May 6, 20263 Mins Read
ISB-Bora-Side-Bar

 
ISB-Bora-Side-Bar
Black ISB Logo

Information Security Buzz is an independent resource that provides the experts’ comments, analysis, and opinion on the latest Cybersecurity news and topics

X (Twitter) LinkedIn Facebook RSS

Working With Us

  • About Us
  • Advertise With Us
  • Contact Us

Write For Us

  • How To Contribute

The Pages

  • Privacy Policy
  • Cookie Policy
  • AI Policy
  • Terms & Conditions
  • Copyright Notice

Information Security Buzz and all its contents are copyright © 2014-2025. All rights reserved. All third-party trademarks are recognized.

Type above and press Enter to search. Press Esc to cancel.

Manage Consent
To provide the best experiences, we use technologies like cookies to store and/or access device information. Consenting to these technologies will allow us to process data such as browsing behavior or unique IDs on this site. Not consenting or withdrawing consent, may adversely affect certain features and functions.
Functional Always active
The technical storage or access is strictly necessary for the legitimate purpose of enabling the use of a specific service explicitly requested by the subscriber or user, or for the sole purpose of carrying out the transmission of a communication over an electronic communications network.
Preferences
The technical storage or access is necessary for the legitimate purpose of storing preferences that are not requested by the subscriber or user.
Statistics
The technical storage or access that is used exclusively for statistical purposes. The technical storage or access that is used exclusively for anonymous statistical purposes. Without a subpoena, voluntary compliance on the part of your Internet Service Provider, or additional records from a third party, information stored or retrieved for this purpose alone cannot usually be used to identify you.
Marketing
The technical storage or access is required to create user profiles to send advertising, or to track the user on a website or across several websites for similar marketing purposes.
  • Manage options
  • Manage services
  • Manage {vendor_count} vendors
  • Read more about these purposes
View preferences
  • {title}
  • {title}
  • {title}