Cybersecurity Awareness High, But Compliance Lags: EU Survey Reveals Gaps in Daily Practices

September 30, 2026
Cybersecurity Awareness High, But Compliance Lags: EU Survey Reveals Gaps in Daily Practices
  • A Europe-wide survey finds that 74% of employees encountered suspicious emails, messages, or links in six months, yet only 45% say their organisations regularly provide cybersecurity awareness updates.

  • Risks extend beyond phishing to attempts at stealing personal data (18%), passwords (16%), malware (17%), and AI-generated scams (15%).

  • Awareness and risk recognition rise with age, underscoring the need for targeted training for younger workers aged 15 to 24.

  • The piece calls for turning awareness into practical capability through ongoing training and supportive infrastructure to counter evolving threats, including AI-enabled risks.

  • AI is reshaping threats and work practices, demanding broader preparedness beyond cybersecurity teams as AI enables more convincing social engineering.

  • The findings come during European Cybersecurity Month amid EU policy efforts like NIS2, Cyber Resilience Act, and AI Act, plus the Cybersecurity Skills Academy to strengthen security and resilience.

  • While rules tighten under NIS2 and the Cyber Resilience Act and skills are promoted via the Cyber Skills Academy, rules alone won’t close the behavior gap; awareness must translate into action.

  • Event note: Cloud & Cyber Security Expo Paris runs November 18–19, 2026, focusing on identity security, threat detection, incident response, and compliance.

  • Exposure to cyber threats varies by country, with Spain, Luxembourg, and France most exposed, while Ireland reports higher AI-generated scam and fraud instances.

  • Regulatory measures can strengthen requirements but real-time decision-making by workers handling inboxes and devices remains essential.

  • Phishing, AI-driven scams, and other threats risk undermining trust in the digital economy and threaten both businesses and public services.

  • ENISA data show social engineering persists, AI-enabled manipulation rising 259% year over year; 2025 incidents include cybercrime 36%, ransomware 40%, data breaches 31%, and fraud/impersonation 19%.

Summary based on 11 sources


Get a daily email with more EU News stories

More Stories