Three in four workers in the European Union have come across suspicious emails, messages or links at work, according to a Eurobarometer survey published by the European Commission on 30 September.

Greece’s Hellenic Data Protection Authority (HDPA) has seized on the figures, released as European Cybersecurity Month (ECSM) got under way, to remind public bodies and private companies that protecting personal data is central to tackling cyberthreats.

The survey suggests cyberthreats are now a fixture of working life, and that there is a clear gap between what employees know about digital risks and what they actually do.

Phishing leads the pack

Phishing remains the most common threat. Some 39% of employees say they have received fraudulent messages or been directed to fake websites designed to steal data or gain unauthorised access.

Next come attempts to steal personal data, reported by 18% of respondents, followed by malware attacks (17%) and attempts to obtain passwords (16%).

A further 15% say they have already encountered scams powered by artificial intelligence (AI). That last category is growing in importance, as AI hands attackers the tools to produce ever more convincing messages, images, voices and videos.

Knowing versus doing

Employees broadly understand the risks, but awareness does not always translate into safe habits.

Some 83% of employees say a cyberattack can have serious consequences, and 72% say they can spot a suspicious email.

Yet only 54% check who sent a message before clicking on a link.

AI-generated or doctored content is an even bigger blind spot. Fewer than half (48%) say they could recognise a deepfake video.

Beyond the technical fix

The HDPA is using European Cybersecurity Month to remind data controllers, the public and private organisations responsible for handling personal information, of their obligations when a breach occurs.

Under Article 33 of the General Data Protection Regulation (GDPR), they must notify the relevant supervisory authority. But fixing the technical problem and alerting the regulator is not always the end of the matter.

In some cases, organisations must also tell the people affected.

When citizens must know

Article 34 of the GDPR requires organisations to inform people without undue delay when a breach is likely to put their rights and freedoms at high risk.

That risk could include financial fraud, identity theft or the exposure of sensitive personal information.

Prompt notification has a practical purpose, giving people the chance to protect themselves before the damage spreads.

Depending on the case, that could mean changing passwords, cancelling or replacing bank cards, watching out for suspicious messages or taking other targeted steps.

Why transparency matters

Telling people about a breach is not only a legal obligation under the GDPR. It is also central to managing the fallout of a cyberattack.

Hiding an incident, or delaying notification without good reason, can leave those affected more exposed, because it robs them of the chance to protect themselves in time.

Transparency is also the foundation of trust between an organisation and the citizens, customers or employees whose data it holds.

A call to prepare

The HDPA is urging public bodies and private organisations to take stock of how ready they are for a cybersecurity incident.

That means updating incident response plans, training staff regularly and building data protection into every stage of handling an incident.

With three in four employees already exposed to suspicious messages or links, the HDPA argues, cybersecurity can no longer be treated as a purely technical matter. It is a daily responsibility for organisations and a key part of protecting the public.

Share.
Exit mobile version