EU Cybersecurity Survey Reveals High Threat Levels and Practice Gaps
A fresh European Commission Eurobarometer survey shows three in four EU employees face workplace cyber threats, underscoring critical gaps in daily security hygiene.

BRUSSELS — Three out of four employees across the European Union have encountered suspicious emails, messages, or links in their professional environments, according to a newly published Eurobarometer survey by the European Commission. Released to coincide with the launch of European Cybersecurity Month across all 27 Member States, the findings highlight an ongoing disconnect between high employee threat awareness and consistent daily cyber hygiene.
Prevalence of Workplace Cyber Threats
Phishing emerged as the predominant workplace cyber threat, with 39% of European employees encountering fraudulent messages or websites aimed at stealing data or unauthorized system access. Additional reported incidents include attempts to steal personal data (18%) and passwords (16%), alongside malware infections (17%) and artificial intelligence (AI)-generated scams (15%). Overall, just 18% of workers stated that their organization had experienced no cybersecurity incidents as far as they were aware.
The Awareness-to-Practice Gap
While 83% of survey respondents understand that the potential consequences of cyberattacks are serious, foundational security habits remain inconsistent:
Although 76% recognize that clicking unverified links is dangerous and 72% believe they can spot suspicious emails, only 54% actually check senders before opening links.
Only half of surveyed employees (50%) consistently lock their computer screens when stepping away from their workstations.
Basic cyber hygiene and risk awareness tend to increase significantly with age, pointing to an urgent need for targeted training programs directed at younger personnel aged 15 to 24.
Training Deficits and Enterprise Preparedness
While approximately six in ten employees (60%) reported receiving cybersecurity training within the past year, participation rates drop steeply within smaller organizations. Despite 85% expressing an eagerness to enhance their digital security skills, 26% cited a lack of time as the primary barrier.
The survey findings align with the broader implementation of EU-wide legislative measures, including the NIS2 Directive, the Cyber Resilience Act, and the AI Act, designed to reinforce supply chains, secure connected products, and address digital skills shortages.
Related Topics
Zhansaya Nurlanovna
Contributing writer at EUReflect.
Follow EUReflect
See more of our reporting on Google
Mark EUReflect as a preferred source and our stories are ranked higher for you in Top Stories, Discover and Google News — and carry a “preferred” badge when they are cited in AI results.
Add EUReflect as a preferred source



