Home » Staff Think They Can Spot Scams, the Data Says Otherwise: What the Egress (KnowBe4) Report Found

Staff Think They Can Spot Scams, the Data Says Otherwise: What the Egress (KnowBe4) Report Found

The Egress (KnowBe4) report shows employees overconfident spotting scams while falling for them. Here is what UK small businesses should do to close the gap.

Worried employee at laptop, illustrating how employees overconfident spotting scams can be caught out

The headline finding of the Egress (KnowBe4) Report is uncomfortable but useful: employees overconfident spotting scams are the rule, not the exception. Most staff believe they would catch a phishing email or a fake invoice, yet the same people keep clicking, keep paying and keep handing over passwords. The gap between how good we think we are and how good we actually are is exactly where attackers make their money.

For a UK small business the direct answer is this. You cannot fix scam risk by asking people to “be more careful”, because the people most likely to be caught are often the ones most sure they never would be. What works is a mix of realistic testing, short and regular training, and a few technical controls that stop a mistake turning into a loss. Below is what the research points to and how to respond without a corporate security budget.

What the Egress (KnowBe4) report actually says

Egress is a UK founded email security firm now owned by the security-awareness company KnowBe4. Its research programme, published on the Egress resources hub, tracks how phishing and business email compromise land in real inboxes. The recurring theme is the confidence gap: employees rate their own ability to detect scams highly, then fall for tests and real attacks at rates that flatly contradict that self-assessment.

Two patterns matter most for smaller firms. First, attacks have moved beyond the badly spelled “Nigerian prince” email. Modern phishing copies your suppliers, your bank and your own branding, and increasingly uses AI to write clean, on-tone messages in seconds. Second, the riskiest moments are ordinary ones: a payment run on a Friday afternoon, a new starter eager to please, a director travelling and answering email on a phone. Confidence is highest exactly when attention is lowest.

This lines up with the broader picture in the UK Cyber Security Breaches Survey 2026, where phishing remains the most common attack type reported by small businesses by a wide margin. It is not the most sophisticated threat, it is simply the one that keeps working.

Why “just train people harder” does not work

The instinct after a near miss is to send a stern all-staff email and move on. The evidence says that changes very little. People forget a one-off briefing within weeks, and a warning does nothing to build the muscle memory of actually spotting a fake in the flow of a busy day.

Overconfidence also has a nasty side effect: people who are sure they are safe are less likely to report a mistake. A worker who clicks a bad link and feels embarrassed may say nothing, and that silence is what gives attackers time to move money or escalate access. The goal is not to make staff feel clever, it is to make reporting a suspected scam feel normal, quick and blame-free.

There is a modern twist too. As staff quietly adopt their own AI tools, the risk of pasting sensitive data into the wrong place grows, a problem we covered in Shadow AI: the hidden risk when staff use AI tools you never approved. And attackers now use automation to probe smaller targets at scale, as the case in Proton: an autonomous AI hacked a small business showed. Human judgement alone was never going to be enough.

What a realistic response looks like for an SME

You do not need an enterprise security team. You need three layers working together.

  • Regular phishing simulations. Send your own people safe, fake phishing emails and measure who clicks. Do this monthly or quarterly, not once a year, and use the results to target training rather than to shame anyone.
  • Short, frequent training. Five-minute modules on invoice fraud, fake delivery texts and password reuse beat a single two-hour session no one remembers.
  • Controls that catch the mistake. Multi-factor authentication (MFA, a second login step such as a code on your phone), and a hard rule that any change to bank details is verified by phone using a number you already hold, not one from the email.

That last control is the cheapest and most effective defence against invoice redirection fraud, where a scammer poses as a genuine supplier and asks you to update their payment details. It costs nothing and it is directly relevant to anyone already fighting late payment and cash flow pressure, where a diverted payment could be catastrophic.

Tools that run simulations and training

Several providers offer combined phishing simulation and security awareness training aimed at smaller organisations. The big names are worth knowing, but so are the UK and European challengers a business owner might not have on their radar.

Provider Origin Best known for Fit for SMEs
KnowBe4 (owns Egress) US Large library of training and phishing templates Widely used, scales down to small teams
MetaCompliance Northern Ireland Compliance-led awareness training and policy management Good for regulated small firms wanting audit trails
Hoxhunt Finland Gamified, personalised phishing training Strong on engagement and behaviour change
Sophos UK (Oxford) Endpoint security plus Phish Threat simulations Handy if you already use Sophos protection
Proofpoint US Email security and awareness training Better suited to larger or higher-risk firms

On pricing, most of these vendors quote per user per year and expect you to request a quote rather than buy off a public page, so treat any figure you see online with caution. As a rough planning guide, security awareness and phishing simulation for a small team tends to land in the region of a few pounds per user per month, and MFA is built into tools you likely already pay for, including Microsoft 365 and Google Workspace, at no extra cost. Spend the effort on turning MFA on everywhere rather than on buying anything new.

A realistic small business example

Picture a 12-person design studio in Bristol. The office manager receives an email that looks like it is from a regular print supplier, thanking them for recent work and attaching an “updated remittance” with new bank details. The writing is clean, the logo is right, and the amount matches a real outstanding invoice.

Without controls, the payment goes out and is gone. With controls, three things happen. The email fails a quiet check because the sending domain is subtly wrong. The office manager, trained on invoice fraud last month, pauses at the words “new bank details”. And the studio’s rule kicks in: any change to payment details is confirmed by calling the supplier on the number already in the accounts system. The scam collapses at no cost. That is what layered defence looks like in practice, and none of it depends on anyone feeling clever.

Frequently asked questions

Are small businesses really a target for phishing?

Yes, and increasingly so. Attackers favour smaller firms precisely because they assume the defences are weaker and the staff less trained. Automation now lets criminals target thousands of small businesses at once, so being small is no longer being invisible.

How often should we run phishing simulations?

Little and often works best. A short simulation every month or quarter keeps awareness fresh and lets you see whether click rates fall over time. A single annual test tells you almost nothing and lulls people back into overconfidence.

Should we punish staff who fail a phishing test?

No. Punishment drives mistakes underground, and a hidden click is far more dangerous than a reported one. Treat failures as coaching moments and reward fast reporting instead. You want people to raise their hand the second something feels off.

What is the single most effective thing we can do?

Turn on multi-factor authentication everywhere, then add a strict verbal-verification rule for any change to bank or payment details. Those two steps block the two most damaging outcomes: account takeover and invoice redirection.

Do we need to report an attack to anyone?

If money or data is lost, report it to Action Fraud and consider whether personal data was exposed, which can trigger obligations under UK data protection rules. If your business insurance includes cyber cover, notify your insurer early, as delays can affect a claim.

What to do next

  • Turn MFA on this week across email, banking and any cloud tools that hold customer or financial data. It is usually free and it is the highest-impact single change you can make.
  • Write one payment rule and share it: no change to supplier bank details is actioned without a phone call to a known number. Put it in your finance process today.
  • Pick a training and simulation tool from a shortlist that includes KnowBe4, MetaCompliance, Hoxhunt and Sophos, and start with a baseline phishing test so you know where you really stand.
  • Make reporting easy and blame-free. Give staff one clear way to flag a suspicious message and thank them every time they use it.