“They’d never fall for that.”
It’s what many business leaders think about their teams when it comes to phishing scams. After all, your people are smart, switched on, and they’ve heard the warnings before. They know not to click on dodgy links or open unexpected attachments… right?
But here’s the catch. Confidence can be a risk in disguise.
When Confidence Becomes Complacency
At Nxt Gen IT, we’ve seen it time and time again. Employees who genuinely believe they can spot a scam, but still get caught out. According to recent research, a whopping 86% of employees say they’re confident in identifying phishing emails. But over half of them have already fallen victim to one.
That disconnect? It’s exactly what cyber criminals are banking on.
Today’s phishing attacks don’t look like spammy messages from a “foreign prince.” They look like:
- A payment reminder from a trusted supplier.
- An internal request from your finance team.
- A Microsoft login page that seems completely legit.
And when someone’s overconfident, they’re less likely to pause, question, or double-check. That’s when things go wrong.
The Dunning-Kruger Effect, in Action
This psychological concept explains how people with limited knowledge often overestimate their ability. In cyber security, that might look like someone clicking a link because they’re sure they know what a phishing email looks like… until they don’t.
Overconfidence leads to shortcuts. And shortcuts lead to breaches.
So, What Can You Do About It?
Start with mindset.
Awareness training isn’t about scaring your team. It’s about equipping them. Phishing awareness sessions, when done right, help employees recognise the more subtle, well-crafted threats that go unnoticed until it’s too late.
But training alone isn’t enough.
You also need a culture that encourages reporting. If employees feel embarrassed or fear being blamed, they’ll stay quiet. That silence gives cyber criminals the upper hand. Instead, create an environment where flagging something suspicious is second nature, not a cause for concern.
Because cyber security isn’t just a tech problem. It’s a people problem. And the solution lies in ongoing education, open communication, and a healthy dose of humility.
Nxt Steps
If you’re serious about dealing with your potential cyber security weakness, it’s time to go beyond firewalls and antivirus software. Let Nxt Gen IT help you build a team that’s not just informed, but truly empowered to stay vigilant.
Ask us about phishing simulation training, reporting tools, and how to create a culture of cyber awareness.
Ben helps growing businesses turn technology into a driver of performance instead of a barrier. At Nxt Gen IT he works with SME leaders, recruiters, and fast-scaling teams to design solutions that improve reliability, strengthen security, and unlock growth.
With a background in email deliverability and cloud systems, Ben specialises in making sure businesses communicate effectively, keep data safe, and get the most from Microsoft 365. His experience spans solution design, managed IT services, and virtual CIO support, always with a focus on practical outcomes that reduce headaches for business owners.
Ben has supported organisations across the UK, from recruitment agencies struggling with inbox placement to SaaS firms scaling fast, and SMEs needing a trusted partner for their IT. He believes tech is never the end goal: growth is. His role is to make sure technology never gets in the way of it.
