< Back to all clusters
[TECHNOLOGY] · Australia, United Kingdom · 11 sources

Cybersecurity Awareness Gap Persists as Organizations Seek Better Practices

Recent research by the National Cybersecurity Alliance shows that while employee awareness of phishing, multi‑factor authentication and password security has risen, secure behaviors have dropped. MFA awareness grew from 52 % to 77 % of workers, yet consistent MFA use fell, and the proportion of employees who promptly install updates or watch for phishing cues also declined. At the same time, cybercrime victimization increased from 34 % to 44 %.

Industry experts attribute the gap to “cybersecurity fatigue” and the overload of security messages. They argue that awareness alone no longer protects organizations; instead, companies must redesign processes, apply risk‑tiered controls and automate routine tasks. Thought leaders suggest moving away from blanket awareness training toward faster, low‑friction security mechanisms and integrated platforms that reduce tool fragmentation.

Managed security service providers (MSSPs) are positioning themselves to help midsize firms cut complexity, improve visibility and demonstrate measurable risk reduction. The shift includes offering outcome‑focused services—such as consolidated dashboards, automation of detection and response, and clear security‑ROI metrics (e.g., breach cost avoidance, mean‑time‑to‑detect and response). A parallel push for broader security education targets non‑technical staff through regular training cycles, phishing simulations and visual reminders, ensuring the entire workforce can act as a security asset.