• HOME
  • NEWS
  • 74% OF EMPLOYEES IN THE EU HAVE RECEIVED SUSPICIOUS CONTENT AT WORK.

74% of employees in the EU have received suspicious content at work

74% of employees in the EU have received suspicious content at work

New data from ENISA and Eurobarometer show why meeting NIS2 requirements calls for a unified approach to technology, processes, and staff preparedness


European Cybersecurity Month begins with new data regarding threats facing organizations and employee behavior. In September, ENISA published its report on the 2026 cybersecurity threat landscape, while the European Commission presented Flash Eurobarometer 576, which focuses on employee awareness and preparedness.

This topic is particularly relevant for Bulgarian organizations as well. Following the amendments to the Cybersecurity Act promulgated on February 13, 2026, NIS2 requirements have been incorporated into the national regulatory framework. These mandate higher standards for risk management, the protection of networks and information systems, incident response, business continuity, supply chain security, and employee training.


Suspicious content reaches three out of every four employees

 

According to Flash Eurobarometer 576, 74% of employees in the European Union report having received suspicious emails, messages, voice messages, or links at work over the past six months.

 

The most frequently cited threat is phishing and other deceptive content (39%). This is followed by:

  • attempts to steal personal data – 18%;
  • malware attacks – 17%;
  • attempts to steal passwords – 16%;
  • scams created using artificial intelligence – 15%.

 

The data reveals a gap between risk awareness and practical preparedness. Although 83% of employees believe that the consequences of a cyberattack would be serious for their organization, only 45% state that their employer regularly provides information and up-to-date guidance on cybersecurity. At the same time, 85% are interested in improving their skills.


no_title

73% of targeted organizations fall within the scope of NIS2

 

The *ENISA Threat Landscape 2026* analyzes over 8,000 cyber incidents and events observed in 2025. According to the report, 73% of the targeted organizations are classified as "essential" or "important" entities under NIS2.

 

The public administration sector was the most frequently targeted, accounting for 32% of cases.

 

Cybercrime accounted for 36% of the analyzed incidents. Among financially motivated events, ransomware remained the leading threat (40%), followed by data compromise (31%), and fraud and impersonation (19%).

 

These data points are directly linked to the key areas covered by NIS2 and the Cybersecurity Act: risk management, access protection, incident detection and reporting, backup and recovery, supply chain security, and cybersecurity training.


From regulatory requirement to an effective protection model

Compliance goes beyond a single product or document. It begins with an assessment of the current state and proceeds with the implementation of interconnected organizational and technical measures.

Paraflow supports corporate and public sector organizations throughout the entire process - from identifying non-compliance issues to the implementation, monitoring, and maintenance of the necessary solutions.


Current State Assessment and Planning

 

Paraflow supports organizations with:

  • initial consultation;
  • IT infrastructure audit and assessment;
  • vulnerability identification and prioritization;
  • gap analysis of current compliance;
  • strategy and implementation planning;
  • technology solution deployment;
  • development of policies, procedures, and documentation.

 

Protection of Networks, Systems, and Electronic Communication

 

Paraflow designs and implements multi-layered technological protection, which may include:

  • Next-Generation Firewalls (NGFW);
  • Intrusion Detection and Prevention Systems (IDS/IPS);
  • network segmentation and secure remote access;
  • email protection against phishing, malware, and data leakage;
  • DNS protection;
  • endpoint protection (including EDR);
  • vulnerability management solutions;
  • data protection via DLP;
  • cryptographic and PKI solutions.

no_title

Identity and Access Management

 

Compromised user accounts and unauthorized access remain among the primary entry points for attacks. IAM, MFA, and PAM solutions facilitate identity management, the implementation of multi-factor authentication, and the control of privileged accounts.

 

The goal is to ensure that access to systems and information is granted based on actual need and remains subject to monitoring and control.


Monitoring, Detection, and Response

 

SIEM solutions collect and analyze events from various infrastructure components to provide comprehensive visibility and enable the early detection of anomalies.

 

When combined with SOC services, they facilitate:

  • continuous monitoring of the environment;
  • threat detection and analysis;
  • incident prioritization;
  • timely response;
  • the collection of information required for regulatory reporting.

 

This is particularly important for significant incidents, for which the Cybersecurity Act mandates early warning within 24 hours and subsequent notification within 72 hours.


no_title

Backup, Recovery, and Business Continuity

 

Ransomware poses risks beyond just data encryption; attacks can involve data theft, operational disruption, and extortion.

 

To address this, Paraflow integrates backup and recovery solutions that support data protection and the restoration of critical systems following an incident. These solutions form part of a broader approach to business continuity and risk management.

 

Preparing Employees and Management Teams

 

Paraflow conducts specialized cybersecurity training for employees and management. These sessions help participants recognize threats, correctly report suspicious messages, and prepare to respond to cyber incidents.


An Integrated Approach to Cybersecurity

 

As a systems integrator, Paraflow connects individual security components into a unified architecture—covering network security, endpoints, email, identities, data, monitoring, and backup and recovery.

 

Solutions are implemented using technologies from leading vendors and developers, including Cisco, Palo Alto Networks, Check Point, Fortinet, Microsoft, Broadcom, Cynet, and Rapid7.

 

The approach is tailored to the specific organization’s IT infrastructure, risk profile, and regulatory obligations. The goal is not merely to tick boxes for specific requirements, but to build a manageable and resilient environment where people, processes, and technologies function as a single system.

 

European Cybersecurity Month is an ideal time for organizations to assess their current status and determine their next practical steps.

 

Contact the Paraflow team for an initial consultation, an IT infrastructure audit, or an assessment of readiness to meet the requirements of the NIS2 Directive and the Cybersecurity Act.

 

Sources:

ENISA Threat Landscape 2026, published on September 22, 2026;

Flash Eurobarometer 576: Cybersecurity at the workplace: awareness and preparedness among employees, published on September 30, 2026;

Act Amending and Supplementing the Cybersecurity Act, published in the State Gazette, Issue 17 of February 13, 2026.

Contact us for further information or consultation!

Get in touch

More news

Paraflow Achieves a Significant Jump in the Annual Digitalk 101 Ranking – The Largest IT Companies in Bulgaria

Paraflow Achieves a Significant Jump in the Annual Digitalk 101 Ranking – The Largest IT Companies in Bulgaria

Reinforced Leadership: Paraflow in the Top 5 System Integrators

Learn more
Successful upgrade of CRM functionalities in MS Dynamics 365 for PHOENIX PHARMA

Successful upgrade of CRM functionalities in MS Dynamics 365 for PHOENIX PHARMA

Optimization of sales processes and digitalization of customer management

Learn more
Paraflow Honored as Trellix Partner of the Year

Paraflow Honored as Trellix Partner of the Year

The prestigious award was presented during the international InfoSec SEE 2026 conference

Learn more