Skip to content

The Three Reasons Why Employees Get Hacked

Nearly half of all successful cyberattacks start with a negligent employee. Search engines will tell you it comes down to phishing, weak passwords and careless data handling. Look closer and all three say the same thing: this is about people.

A man in an open-plan office types through his inbox one-handed while holding a coffee, jacket still over the chair, a meeting starting behind him
In this article

Ask a search engine why employees get hacked and it answers with three items: falling for phishing and social engineering scams, poor password management and credential hygiene, negligent data handling and unsecured devices. All three are important reasons. But the answer becomes far more useful once you take a step back and notice what they have in common — nearly every one of those statements is about people.

The numbers point the same way. It is proven that at least 47% of successful cyber-attacks start with a careless employee, according to IBM's Cost of a Data Breach Report 2025 — and mostly with a phishing email. So why does it happen? Why do employees get caught up in it? Our experience shows three main reasons why they fall for malicious emails.

1Technical deficienciesUnsecured devices, and misconfigurations of the PC, the server and the network environment.
2Lack of knowledgeWeak IT security skills — today an employee must have knowledge in around 20 IT security domains.
3Behavioral patternsGullibility, ignorance, an unreflective sense of duty, overconfidence, carelessness.

Technical deficiencies are the simplest to correct

If you want to counter this, correcting technical deficiencies or misconfigurations of the PC, the server and the network environment is a relatively simple measure. Most company computers today have a firewall activated, the latest updates installed and backups running. At least the basis for secure work is laid.

Does that make misconfigurations irrelevant? Of course not. Something like this can be exploited by cybercriminals the moment they gain access to the company network. The point is not that the technical layer stops mattering — it is that this is the layer you can close with configuration work.

Around 20 IT security domains per employee

Weak IT security skills among employees are the second reason why they get hacked. The demands on employees' security know-how have increased considerably in recent years, because today an employee must have knowledge in around 20 IT security domains. The list starts with the basics:

  • recognizing phishing emails,
  • using secure passwords,
  • being able to correctly interpret internet addresses,
  • knowing what business — or even private — consequences a successful cyber-attack can have, for example after activating a malicious Excel macro in a downloaded spreadsheet.

Twenty domains is not a briefing. The challenge of training the entire workforce in IT security has become significant in its own right.

Behavior is the most dangerous reason

And then we come to the most dangerous reason why employees are hacked: human behavior patterns. From the perspective of cybercrime prevention, personal behavior — and attitude — is the greatest risk that can lead to a successful cyber-attack. Gullibility. Ignorance. An unreflective sense of duty. Overconfidence. Carelessness.

It is not without reason that 47% of successful hacks start directly with a careless colleague. Technical gaps can be closed and knowledge can be taught. Behavior is what decides what an employee actually does when the malicious email arrives.

What a good awareness program does

In view of all three reasons, it is clear what is being done about them: we train and improve the risk behavior — read: the awareness — of the staff. A good cybersecurity awareness program is comprehensive and mostly online, and it pursues the sensitisation of employees with at least these three measures.

  1. 01Regular and realiztic phishing campaignsThey consolidate and test the knowledge among the staff. Incorporating personal data is not forbidden — it serves the educational purpose.
  2. 02Focussed, short and repetitive trainingOn IT security, cyber risks and the company's security policies. Training has to be adapted to the company's or the user's context, otherwise it builds no usable knowledge.
  3. 03A phishing reporting button with automated analysisIt ensures that employees report suspicious emails and that those messages are subject to a downstream analysis and feedback process.

Cyberdise was built to run exactly this program: it raises awareness by up to 60% compared to conventional anti-phishing solutions, as measured in the AISP paper.

60%better risk behavior - scientifically proven

Source: AISP study - full whitepaper available

Conclusion

Companies and management are struggling with technical weaknesses, with a lack of IT security knowledge and, above all, with insufficient and outdated behavior patterns among their employees. Two of those three yield to configuration and to a curriculum. The third one needs a program, time, and a tool that drives the behavioral change.

That is what Cyberdise Awareness is for. It greatly simplifies the implementation of an awareness program: customized training campaigns, phishing and smishing simulations, a phishing button with a designed and configured incident reporting process, AI-supported analysis of suspicious messages that offloads work from the security engineer, and a reporting system that management can understand.

Why are technical misconfigurations still a risk?
Most company computers already have a firewall activated, the latest updates installed and backups running, so the basis for secure work is laid. A misconfiguration of the PC, the server or the network environment still matters, because cybercriminals can exploit it once they gain access to the company network.
How many IT security domains must an employee master?
Around 20. It starts with recognizing phishing emails, using secure passwords, being able to correctly interpret internet addresses, and knowing what business or private consequences a successful cyber-attack can have.
What belongs in a good awareness program?
At least three measures: regular and realiztic phishing campaigns, focussed and repetitive training adapted to the company's or the user's context, and a phishing reporting button with automated message analysis plus a downstream feedback process.

Two of the three reasons yield to configuration and training.

The third one is behavior — see what changing it looks like in practice.

Book a DemoDownload

Sources

  1. The Three Reasons Why Your Employees Are Hacked in 2026Cyberdise AG
  2. Cost of a Data Breach Report 2025IBM
  3. AI-Enabled Spearphishing (AISP)Cyberdise AG / HSLU

Written by

Palo Stacho

Founder and Managing Director

Founder and Managing Director of Cyberdise AG in Zug, Switzerland. He writes about the state of the awareness industry and why behavior, not knowledge, decides whether an attack succeeds.