Ask a search engine why employees get hacked and it answers with three items: falling for phishing and social engineering scams, poor password management and credential hygiene, negligent data handling and unsecured devices. All three are important reasons. But the answer becomes far more useful once you take a step back and notice what they have in common — nearly every one of those statements is about people.
The numbers point the same way. It is proven that at least 47% of successful cyber-attacks start with a careless employee, according to IBM's Cost of a Data Breach Report 2025 — and mostly with a phishing email. So why does it happen? Why do employees get caught up in it? Our experience shows three main reasons why they fall for malicious emails.
Technical deficiencies are the simplest to correct
If you want to counter this, correcting technical deficiencies or misconfigurations of the PC, the server and the network environment is a relatively simple measure. Most company computers today have a firewall activated, the latest updates installed and backups running. At least the basis for secure work is laid.
Does that make misconfigurations irrelevant? Of course not. Something like this can be exploited by cybercriminals the moment they gain access to the company network. The point is not that the technical layer stops mattering — it is that this is the layer you can close with configuration work.
Around 20 IT security domains per employee
Weak IT security skills among employees are the second reason why they get hacked. The demands on employees' security know-how have increased considerably in recent years, because today an employee must have knowledge in around 20 IT security domains. The list starts with the basics:
- recognizing phishing emails,
- using secure passwords,
- being able to correctly interpret internet addresses,
- knowing what business — or even private — consequences a successful cyber-attack can have, for example after activating a malicious Excel macro in a downloaded spreadsheet.
Twenty domains is not a briefing. The challenge of training the entire workforce in IT security has become significant in its own right.
Behavior is the most dangerous reason
And then we come to the most dangerous reason why employees are hacked: human behavior patterns. From the perspective of cybercrime prevention, personal behavior — and attitude — is the greatest risk that can lead to a successful cyber-attack. Gullibility. Ignorance. An unreflective sense of duty. Overconfidence. Carelessness.
It is not without reason that 47% of successful hacks start directly with a careless colleague. Technical gaps can be closed and knowledge can be taught. Behavior is what decides what an employee actually does when the malicious email arrives.
What a good awareness program does
In view of all three reasons, it is clear what is being done about them: we train and improve the risk behavior — read: the awareness — of the staff. A good cybersecurity awareness program is comprehensive and mostly online, and it pursues the sensitisation of employees with at least these three measures.
- 01Regular and realiztic phishing campaignsThey consolidate and test the knowledge among the staff. Incorporating personal data is not forbidden — it serves the educational purpose.
- 02Focussed, short and repetitive trainingOn IT security, cyber risks and the company's security policies. Training has to be adapted to the company's or the user's context, otherwise it builds no usable knowledge.
- 03A phishing reporting button with automated analysisIt ensures that employees report suspicious emails and that those messages are subject to a downstream analysis and feedback process.
Cyberdise was built to run exactly this program: it raises awareness by up to 60% compared to conventional anti-phishing solutions, as measured in the AISP paper.
Source: AISP study - full whitepaper available
Conclusion
Companies and management are struggling with technical weaknesses, with a lack of IT security knowledge and, above all, with insufficient and outdated behavior patterns among their employees. Two of those three yield to configuration and to a curriculum. The third one needs a program, time, and a tool that drives the behavioral change.
That is what Cyberdise Awareness is for. It greatly simplifies the implementation of an awareness program: customized training campaigns, phishing and smishing simulations, a phishing button with a designed and configured incident reporting process, AI-supported analysis of suspicious messages that offloads work from the security engineer, and a reporting system that management can understand.

