Javvad Malik at KnowBe4 explains why the definition of a security-aware employee is overdue for an update

There is a quiet paradox running through the way organisations think about security awareness. Employees are most suspicious of the communications channel that security teams feel most confident defending. And most trusting of the channels that security teams feel least equipped to monitor.
That tension is where real risk is accumulating, and it is what the data collected from Infosecurity Europe 2026 makes hard to ignore.
Across 169 cyber-security professionals surveyed at the event, confidence in detecting threats via email sits at 83%. For Slack, confidence drops to 40%. And yet two-thirds of respondents believe their employees are more likely to trust a message arriving in a Teams channel or Slack workspace than one landing in their inbox. The study shows that attacker opportunity and security team visibility are moving in opposite directions, and the space in the middle is where people spend most of their working day.
Before unpacking the problem, it is worth noting that email security has improved significantly.
The 83% detection confidence figure for email did not happen by accident. It reflects years of compounding investment in secure email gateways, anti-phishing controls, cloud email security, and awareness training that has produced real, measurable results. Phishing simulations became routine. Security teams built deep expertise. A generation of employees learned to slow down before clicking a link in their inbox.
The survey reflects this. Traditional phishing emails remain the threat respondents feel most prepared for, and 54% still identify them as the biggest risk to their organisation. The infrastructure and instincts built around email defence are real, and the industry deserves credit for getting there.
But maturity in one channel diverts attackers elsewhere.
Sophisticated attackers are rational actors. As email hardened as a target, every other channel became comparatively more attractive. Teams, Slack, SMS and WhatsApp did not become more dangerous because the technology fundamentally changed. They became more dangerous because the defences everywhere else got stronger, and the path of least resistance shifted.
The survey suggests this is a valid concern, with 62% of respondents saying they have already observed attacks moving beyond email. KnowBe4’s own Phishing Threat Trends Report, Volume 7, adds weight to that concern. Between October 2025 and March 2026, Teams-based attacks rose by 41%. Multi-channel social engineering is mainstream now, not emerging. When more than half of respondents select a non-email channel as the most vulnerable in their organisation, it is clear that awareness of the shift exists. The question is whether readiness has kept pace.
What makes collaboration platforms such fertile ground is not just that defences there are less mature. It is that employees approach them with a fundamentally different posture than they bring to email.
Email arrived in the workplace trailing decades of accumulated scepticism. Spam folders, phishing warnings, and years of training have conditioned employees to treat unsolicited messages with at least a degree of suspicion. Collaboration tools carry none of that baggage. A Teams message does not feel like an attack. It feels like a colleague needing something, a project moving, a quick answer before lunch. That normality is exactly what makes it useful to attackers.
A full two-thirds (66%) of survey respondents believe employees are more likely to trust messages on internal collaboration platforms. The detection confidence data maps directly onto that dynamic. Email: 83%. Teams: 61%. Social media: 51%. SMS and WhatsApp: 50%. Slack: 40%. High employee trust and low security visibility are converging in exactly the same set of channels.
The modern workplace does not look like it did when most security training programmes were designed. Employees now move fluidly between Teams calls, Slack threads, text messages and email, often within minutes. The threat landscape has followed that fragmentation, flowing across whatever surface is least defended and most trusted at any given moment.
Addressing this requires organisations to think about two things together rather than in isolation from one another.
The first is training. People need the same kind of instinct on Slack or Teams that years of phishing simulations built up around email. That means extending training scope to reflect the channels employees actually use, not the channels where threats first became visible.
The second is tooling. A well-trained employee who spots something suspicious on Teams still needs somewhere for that flag to go. Detection and response capabilities need to extend into collaboration platforms with the same depth they have reached in email security. Training and technology are interdependent here, and the absence of either limits the value of the other.
You cannot train people to spot something in Teams if there is nowhere useful for them to report it when they do.
The survey data suggests this combination is still missing in many cases. Only 41% of organisations regularly train employees on threats beyond email. More than one in ten (13%) never train on Teams, Slack or SMS threats at all, despite the fact that 62% are already seeing attacks arrive through those channels. As the platforms people use at work have evolved, security awareness training programmes, and the tools that underpin them, need to evolve alongside.
The goal of security awareness was never to secure the inbox in isolation. It was always to secure the people inside the organisation, wherever they communicate.
For a long time, the inbox was the obvious place to start because it was the dominant attack surface. That is no longer straightforward or even true. The surface has expanded to include wherever work actually happens, and the definition of a security-aware employee needs to expand with it.
Someone who would spot a phishing email without hesitation but who would not think twice about an unsolicited request arriving in a Teams message is only partially covered. Closing that void is the work in front of us.
Javvad Malik is Lead CISO Advisor at KnowBe4
Main image courtesy of iStockPhoto.com and juststock
Winston House, 3rd Floor,
Units 306-309, 2-4 Dollis park,
London, N3 1HF
020 8349 4363
© 2026, Lyonsdown Limited. teiss® is a registered trademark of Lyonsdown Ltd. VAT registration number: 830519543