This informal CPD article ‘Why We Underestimate Our Own Cyber Risk’ was provided by SmartSec Academy, an independent cybersecurity awareness and professional development provider focused on improving human decision-making in digital environments.
Most people believe they would recognise a scam if they saw one. They picture something obvious. A clumsy email, a strange link, a request that does not add up. Because that picture feels easy to spot, many quietly assume they are unlikely to be the person who gets caught. That assumption is worth examining, because it is common, it feels reasonable, and it shapes how carefully people behave.
A Well-Documented Pattern of Thinking
Psychologists have long described a tendency known as optimism bias, sometimes called unrealistic optimism. It is the belief that negative events are less likely to happen to us than to other people [1]. It is not a flaw limited to a careless few. It is a normal feature of how most people judge personal risk, and it appears across many areas of life [1].
In a security setting, this pattern has a measurable effect. A study of employees found that those who were more optimistic about their own risk were more inclined to behave insecurely [1]. The belief that something is unlikely to affect you can quietly reduce the care you take to avoid it.
Why Cyber Risk Feels Distant
Optimism bias tends to be strongest for risks that feel familiar, common, or within our control [2]. Everyday cyber threats fit all three. Most people see phishing messages regularly, so the threat begins to feel routine and manageable rather than serious.
This is where a subtle problem appears. Seeing many phishing emails can lead people to feel less likely to fall for one, rather than more [2]. Familiarity becomes a quiet source of confidence. The reasoning feels sensible from the inside. I have seen these before, so I will recognise the next one. The difficulty is that this confidence is built on the obvious examples, while the convincing attempts are designed not to look like examples at all.
Confidence Does Not Always Match Ability
It is natural to assume that people with more technical knowledge are better protected, partly because they are more aware. The picture is more complicated. In a 2025 study of 300 workers, both IT and non-IT employees believed they were less at risk than others of similar age and experience. The IT employees showed a stronger version of this belief than their non-IT colleagues [2]. Greater familiarity with technology did not remove the bias. In some cases, it appeared to reinforce it.
This challenges a comforting idea, that knowing more automatically makes a person safer. Knowledge helps, but confidence and competence are not the same thing, and confidence can run ahead of ability.
What the Evidence Suggests About Detection
There is also a practical limit to how far anyone can rely on simply spotting threats. Phishing remains the most prevalent and disruptive type of attack reported by affected UK organisations, experienced by 85% of businesses that identified a breach or attack in a recent national survey [3]. A large share of incidents involve a person at some point, rather than a purely technical failure [4].
The UK National Cyber Security Centre is clear on this. It states that no training package can teach users to spot every phishing attempt, and that no one can reasonably be expected to identify them all [5]. If detection cannot be guaranteed even with good training, then personal certainty about always noticing an attack rests on uncertain ground.
How This Changes Behaviour
The reason this matters is behavioural. Underestimating personal risk does not stay in the mind. It changes what people do. Research has found that a stronger optimism bias is associated with lower engagement in protective security behaviour [2]. Someone who feels unlikely to be targeted has less reason to slow down, check an unexpected request, or report something that seems slightly off.
That is the quiet cost of feeling safe. The more certain a person is that it will not happen to them, the less motivated they may be to take ordinary precautions. The feeling is reassuring. The effect is not.
A More Useful Starting Point
The aim here is not worry and it is not suspicion of every message. Constant scrutiny is neither realistic nor productive, and examining every email in depth would leave little time for actual work [5]. A more useful starting point is quieter. It is accepting that anyone can be caught, including experienced, careful, and technically capable people.
That small shift tends to support better habits. People who accept they could be a target are more likely to pause on an unexpected request, verify before acting, and report quickly when something seems wrong. Awareness works better when it begins with the thought that this could happen to me, rather than the assumption that it happens only to other people.
Conclusion
Cybersecurity is usually discussed in terms of tools, threats, and attackers. One of the quieter risks is a belief. It is the sense that we, personally, are unlikely to be fooled. That belief is very common, it feels sensible, and it is precisely where caution tends to fade. Understanding that anyone can be a target, on an ordinary day, is not a pessimistic view. It is a more accurate one. And in this case, accuracy is what helps people make safer decisions.
We hope this article was helpful. For more information from SmartSec Academy, please visit their CPD Member Directory page. Alternatively, you can go to the CPD Industry Hubs for more articles, courses and events relevant to your Continuing Professional Development requirements.
References
[1] Owen, M., Flowerday, S.V. and van der Schyff, K. (2024) 'Optimism bias in susceptibility to phishing attacks: an empirical study', Information and Computer Security, 32(5), pp. 656-675. Available at: https://doi.org/10.1108/ICS-02-2023-0023
[2] Carbone, D., Marcatto, F., Mistichelli, F. and Ferrante, D. (2025) 'Perceiving Digital Threats and Artificial Intelligence: A Psychometric Approach to Cyber Risk', Journal of Cybersecurity and Privacy, 5(4), 93. Available at: https://doi.org/10.3390/jcp5040093
[3] Department for Science, Innovation and Technology (2025) Cyber Security Breaches Survey 2025. Available at: https://www.gov.uk/government/statistics/cyber-security-breaches-survey-2025/cyber-security-breaches-survey-2025
[4] Verizon (2025) Data Breach Investigations Report (DBIR). Available at: https://www.verizon.com/business/resources/reports/dbir/
[5] National Cyber Security Centre (2024) Phishing attacks: defending your organisation. Available at: https://www.ncsc.gov.uk/guidance/phishing