Fullscreen Menu - Background

Subscribe to SME News Search for an article Our amazing team

Ground Floor, Suites B-C, The Maltsters,
1-2 Wetmore Road, Burton upon Trent
Staffordshire, DE14 1LS

Background
Posted 21st January 2026

Rank Does Not Equal Immunity: Why Executives Are Falling for Phishing More Than Junior Staff

2025 was marked by the commercialisation of cyber crime and AI-enhanced attacks, resulting in a record number of phishing attacks globally.

Mouse Scroll AnimationScroll to keep reading
Fixed Badge - Right
rank does not equal immunity: why executives are falling for phishing more than junior staff.


Rank Does Not Equal Immunity: Why Executives Are Falling for Phishing More Than Junior Staff
Business woman working on laptop computer at home with warning window

2025 was marked by the commercialisation of cyber crime and AI-enhanced attacks, resulting in a record number of phishing attacks globally. While enterprise breaches dominated the headlines, data from Yubico’s 2025 Global State of Authentication Report suggests that the year ahead poses an even greater challenge to the backbone of the economy: small businesses.

According to the report, small businesses are facing a new wave of vulnerability, driven by a lack of resources and dangerous misconceptions about their appeal to attackers.

Key findings regarding the small business threat landscape include:

  • The training gap: A staggering 60 percent of entrepreneurs/sole traders and 57 percent of employees at small businesses (1–99 staff) received no cybersecurity training in 2025, leaving them defenceless against AI-driven social engineering
  • The MFA lag: Despite the rise in credential theft, 46 percent of entrepreneurs and 39 percent of small business employees report that their company does not use multi-factor authentication (MFA) across all applications
  • False security: The primary reason for this lack of protection is complacency; 36 percent of entrepreneurs believe their business simply “doesn’t require” robust authentication measures like MFA

Furthermore, the research highlights a dangerous disconnect in security habits and perceptions based on professional roles:

  • Out of touch workplace culture: There is a significant gap in perception; while 44 percent of C-Suite members believe their company has “very good” cybersecurity in place, only 25 percent of entry-level employees agree, suggesting a discrepancy in cyber awareness
  • The executive risk: C-Suite executives are frequently the weak link. Data reveals that 11.6 percent of C-Suite members admitted to interacting with a phishing message in the last week alone, compared to just 8.8 percent of entry-level employees

Niall McConachie, regional director (UK & Ireland) at Yubico, comments on the specific risks to small businesses and the necessary resolutions for 2026:

“Small businesses are currently operating under a dangerous misconception: believing they’re too small a target for attackers. In the age of AI-driven cyber crime, automated tools target all employees and businesses the same. Every unsecured entry point is a target, and our data confirms that entrepreneurs are leaving the front door wide open by neglecting basic training and not implementing multi-factor authentication (MFA).

“The disconnect between the C-Suite and the frontline is equally alarming. C-suite executives are privy to the most sensitive information in the business, yet the data shows they are interacting with phishing attempts at a higher rate than entry-level staff. This proves that rank does not equal immunity; in fact, it creates a critical risk where the individuals holding the most valuable data are the most susceptible. When those at the top believe security is ‘very good’ while simultaneously falling for attacks, it fosters a dangerous culture of complacency.

“For 2026, the resolution for small businesses must be the widespread adoption of enterprise-grade security. We need to abandon the idea that robust authentication is ‘too expensive’ or ‘too complex’ for smaller teams. Conversely, it’s too expensive not to protect systems and data. Implementing phishing-resistant MFA, such as device-bound passkeys like hardware security keys, is the only scalable way to level the playing field and immunise small businesses against the industrialised threat landscape they now face.”

Categories: Business News, News, People, Technology


You might also like...
How to Optimally Use Business Loans for Maximum Success?Finance21st July 2023How to Optimally Use Business Loans for Maximum Success?

In today's competitive business landscape, obtaining a business loan can provide the necessary funding to fuel business growth and expansion.

Bold, Bespoke, BrilliantBusiness News4th May 2022Bold, Bespoke, Brilliant

Excelling in bespoke website and graphic design, GEL Studios strikes the perfect balance between effortless style and seamless usability. We speak to Managing Director, Graeme, and find out more about how the company has gone from strength-to-strength as it wi

SME News Media Pack

Every quarter we offer a new issue of SME News which is published on our website, shared to our social media following and circulated to our opt-in subscribers from various sectors across the UK SME marketplace.

  • TickExpand your reach.
  • TickGrow your enterprise.
  • TickSecure new clients.
View Media Pack
Media Pack - Bottom Slant Gradient
we are sme.
Arrow