© All rights reserved. Powered by Techronicler
By Travis Springer, President, Sagiss

Ask any office worker whether they know phishing is a threat, and they’ll say yes. Ask whether they know not to click unfamiliar links or reply to unverified requests, and they’ll say yes to that too. Security awareness training has been a workplace staple for more than a decade. It’s safe to say that workers know the rules. But they still click anyway.
The 2026 Sagiss Managed Security Report, which surveyed 500 U.S. desk-based workers, found that 63% of employees clicked a work-related link in the past year and later felt they should have double-checked it first. Fifty-seven percent confirmed the legitimacy of a request only after taking action. Forty-five percent replied to a work message and later questioned whether it was genuine.
The temptation in security circles is to frame this as a training problem. If workers are still clicking, the thinking goes, they simply need more education. That framing misses what the data actually shows.
Employees have the knowledge. The problem is the environment in which they are asked to apply it.
When the Sagiss survey asked workers which situations most likely lead to mistakes, 55% pointed to rushing between tasks or meetings. Another 48% cited multitasking. High message volume, constant context switching, and the pressure to stay responsive across multiple channels have created conditions where careful verification is difficult to practice, even for people who know exactly what they should be doing.
With AI, attackers have introduced a weapon into that environment that is purpose-built to exploit overworked, distracted employees.
Seventy-two percent of workers in the Sagiss survey said phishing attempts are more convincing than a year ago because of AI-written language. Nearly 65% said an AI-generated message could likely impersonate someone they work with. More than half (57%) said AI makes phishing harder to spot because it feels more professional. This is the reality many workers face in their inboxes.
The change in attack quality has been rapid. Large language models can generate polished, contextually accurate messages at scale. They can draw on publicly available information, such as LinkedIn profiles, company websites, and prior data leaks, to produce content that mirrors a colleague’s tone or references a real project. Thirty-three percent of survey respondents said they’ve noticed better grammar and writing in suspicious messages over the past year. Twenty-seven percent pointed to greater personalization. Twenty-six percent said the tone now feels more natural and human.
People spent years learning to spot awkward phrasing, generic greetings, and mismatched urgency. Now, those red flags are precisely the things AI removes first.
The challenge extends beyond the workday. Sixty-eight percent of workers in the Sagiss survey said they check work email or chat outside normal business hours at least sometimes. Fifty-six percent feel pressure to respond after hours. About 34% said they have responded to a work message after hours and later felt they should’ve verified it more carefully.
A message that arrives at 8 p.m., appears to be from a manager, references an actual deadline, and is written in fluent professional prose isn’t going to trigger the same scrutiny as a clunky bulk phishing email. Attackers understand that this is a time when employees are less focused and trying to rush through work tasks so they can get back to dinner with their families or catching up on their favorite shows.
Forty-one percent of respondents said they’ve ignored an initial suspicion about a message because it seemed urgent. Workers who had a gut feeling overrode that instinct because the message communicated urgency convincingly enough. When attackers can manufacture urgency with the same ease they manufacture professional tone, even a security-conscious employee becomes a viable target.
Awareness training is still valuable. The Sagiss data doesn’t suggest workers are uninformed. What it suggests is that training alone can’t carry the weight of an organization’s phishing defense when the attacks have become more credible and the work environment more demanding.
Procedural interventions are the most durable. Requiring out-of-band verification for high-risk requests, such as wire transfers and access modifications, creates a checkpoint that does not depend on an employee correctly reading a message under pressure. Phishing-resistant multi-factor authentication removes the relay vulnerability that AI-powered kits have learned to exploit. Clear escalation paths give employees somewhere to go when something feels wrong, without the hurdles that often lead people to act first and question later.
None of these controls assume that workers will perform perfectly under pressure. They are designed for the reality that workers will occasionally slip up, regardless of how well they understand the threat.
The 2026 Sagiss data is a useful corrective for any organization still treating phishing primarily as an education problem. Workers already know how to dodge phishing attempts. What they need are systems built to account for the moments when knowing is not enough.

Travis Springer is the President at Sagiss, a premier managed IT & cybersecurity service provider serving businesses across the Dallas-Fort Worth area. With a background in finance and nearly a decade of experience in IT leadership, Travis specializes in helping business owners leverage technology to drive growth, improve security, and streamline operations.
At Sagiss, he works closely with clients to align IT strategy with business goals, making complex tech decisions simple and actionable. Travis brings a practical, business-first perspective to conversations about cybersecurity, cloud solutions, and digital transformation—making him a trusted voice for entrepreneurs navigating today’s fast-changing tech landscape.
If you wish to showcase your experience and expertise, participate in industry-leading discussions, and add visibility and impact to your personal brand and business, get in touch with the Techronicler team to feature in our fast-growing publication.
Individual Contributors:
Answer our latest queries and submit your unique insights:
https://bit.ly/SubmitBrandWorxInsight
Submit your article:
https://bit.ly/SubmitBrandWorxArticle
PR Representatives:
Answer the latest queries and submit insights for your client:
https://bit.ly/BrandWorxInsightSubmissions
Submit an article for your client:
https://bit.ly/BrandWorxArticleSubmissions
Please direct any additional questions to: connect@brandworx.digital