Part 3 of 12 — The New IT Reality
A series for CEOs and business leaders examining how IT challenges don't replace each other — they accumulate.

Every employee in your company uses technology eight or more hours a day. They install apps without reading terms of service. They manage cloud storage across multiple platforms. They video call across continents. They navigate complex software interfaces as naturally as breathing.

They're digital natives. They're technically literate. They're also, statistically, your biggest security vulnerability.

The Digital Literacy Paradox

Here's the paradox that keeps cybersecurity professionals up at night: the more comfortable people are with technology, the more dangerous they become.

High usage does not equal high understanding. Your marketing manager who runs three social media platforms simultaneously doesn't understand network security. Your finance director who processes complex Excel models doesn't know what a phishing email looks like when it's well-crafted. Your CEO who manages the company from an iPad during flights doesn't grasp the implications of connecting to airport WiFi.

People who bank on their phones, trade stocks on apps, and manage smart homes still click phishing links. Not because they're unintelligent. Because the threats are designed to exploit exactly the kind of confidence that comes with habitual technology use.

"I Know About Computers" — The Most Dangerous Phrase in Cybersecurity

There is a concept in psychology called the Dunning-Kruger effect: people with limited knowledge in a domain tend to dramatically overestimate their competence. In cybersecurity, this isn't an academic curiosity. It's an operational crisis.

The employee who declares "I know about computers" is statistically more likely to fall for a sophisticated phishing attack than the employee who admits "I'm not sure about this." Why? Because the confident employee trusts their own judgment. They don't pause. They don't verify. They click, they respond, they transfer — because they're confident they can tell the difference between a real request and a fake one.

They can't. Not anymore. Not when AI can generate a perfectly formatted email from your CEO, complete with their writing style, sent from a domain that's one character different from yours, referencing a real project discussed in a meeting last Tuesday.

The Numbers Tell a Brutal Story

Verizon's 2024 Data Breach Investigations Report found that 68% of breaches involved a human element — social engineering, errors, or misuse. Not zero-day exploits. Not sophisticated nation-state hacking. Human beings making human mistakes.

Proofpoint's 2024 State of the Phish report found that 71% of employees admitted to engaging in risky behaviour — using work devices for personal activities, reusing passwords, clicking links from unknown senders. Not because they didn't know better. Because they thought the rules applied to other people.

And here's the counterpoint that matters: KnowBe4 research shows that phishing susceptibility drops by up to 75% with proper, sustained training. The problem isn't unsolvable. It's just being solved the wrong way.

Why Security Awareness Training Fails

Most organisations approach security awareness as a checkbox exercise. Once a year, employees sit through a PowerPoint presentation about phishing. They learn to "look for suspicious links" and "verify the sender." They pass a quiz. The compliance box gets ticked. Everyone goes back to work.

And then they click the next well-crafted phishing email, because the training addressed symptoms rather than causes.

The real reasons people fall for social engineering are psychological, not technical:

  • Authority bias: An email that appears to come from the CEO gets acted on without question. The more hierarchical the organisation, the more vulnerable it is.
  • Time pressure: "Urgent: process this payment before end of day." Urgency bypasses critical thinking. Every time.
  • Overconfidence: "I've been using email for twenty years. I can spot a scam." This confidence is exactly what attackers count on.
  • Social proof: "Everyone in the team already clicked this link." If others have done it, it must be safe.
  • Reciprocity: "The IT department sent this security update." People comply with requests from those who appear to be helping them.

Traditional training addresses none of these. It teaches people what phishing looks like. It doesn't teach them why they're vulnerable to it.

The CEO Wire Transfer: A Case Study in Confidence

Consider this scenario — one that plays out hundreds of times daily worldwide. Your CFO receives an email from the CEO: "I need you to process an urgent wire transfer. It's for the acquisition we discussed last week. The details are attached. Keep this confidential — we'll announce it on Monday."

The email references a real conversation. The tone matches the CEO's writing style. The sender address looks correct at a glance. The request is unusual but not impossible.

Google and Stanford research found that new employees are 5x more likely to click phishing links. But in this scenario, it's not the new employee who's most at risk. It's the experienced CFO — the one who has a relationship with the CEO, who has processed similar requests before, who trusts their own ability to distinguish real from fake.

The confident employee doesn't double-check. They execute. And by the time anyone realises what happened, the money is gone.

The Greek Context: Hierarchy, Language, and "My Nephew Set Up the Network"

Greek business culture carries specific vulnerabilities that deserve direct acknowledgment.

Hierarchy: Greek organisations tend toward hierarchical structures where questioning authority is culturally discouraged. When an email appears to come from the διευθύνων σύμβουλος requesting immediate action, the instinct is to comply, not to verify. This makes Greek businesses particularly susceptible to authority-based social engineering.

Language barrier — no longer: Historically, the Greek language provided a degree of natural protection against phishing. Poor Greek in an email was an immediate red flag. That protection has evaporated. AI language models now produce flawless, natural Greek — complete with the formality registers and business vocabulary that make an email convincing. The language barrier is gone.

Informal IT knowledge: Many Greek businesses still rely on informal technical expertise. "My nephew set up the network." "My friend's son handles the website." This creates environments where no one has a comprehensive understanding of the organisation's IT landscape, where no formal security policies exist, and where no one is specifically responsible for security awareness. It's not that people don't care. It's that no one has been given the mandate or the tools to address it properly.

Building a Culture, Not a Checklist

The solution isn't more PowerPoints about phishing. It's building an organisational culture where security awareness is embedded in daily operations.

This means creating an environment where "I'm not sure about this — can someone check?" is the smartest thing anyone can say, not a sign of incompetence. Where questioning an unusual request — even from the CEO — is encouraged and rewarded. Where security isn't something the IT department does to you, but something the entire organisation does together.

The organisations that get this right don't just reduce their phishing click rates. They build resilience against every form of social engineering, from business email compromise to physical social engineering to AI-powered voice cloning. Because they've addressed the root cause: not what people click, but how they think.

Key Takeaway

Your employees aren't the problem. Their confidence without context is. Digital literacy doesn't equal security awareness, and overconfidence is the attacker's greatest ally. The solution isn't more training slides — it's building a culture where "I'm not sure about this" is the smartest thing anyone can say.

Previously: Remote, Hybrid, Back-to-Office: Your IT Infrastructure Never Went Back to Normal


Next in the series: AI in Business: Between Salvation and Panic

Wondering how your organisation would fare against a real-world social engineering test? Let's talk about building security awareness that actually works — because the next attack won't come with a PowerPoint warning first.