Surprisingly Useful AI Article Enhancements
A new study from KnowBe4 has found that while most Australians believe they can identify cyber threats, many continue to engage in risky online behaviours that leave them exposed.
The research, titled “Australia’s Cybersecurity Paradox: Strong Defences, Weak Habits,” is based on a national survey conducted by YouGov and reveals a significant gap between how confident Australians feel about cybersecurity and what they actually do in practice.
According to the findings, 53 per cent of employed Australians admit to putting more effort into securing their work accounts than their personal ones. The report suggests this imbalance is largely driven by workplace policies rather than ingrained personal habits.
Confidence does not equal caution
The survey found 76 per cent of Australians feel confident in their ability to spot cyber threats. Yet two-thirds of respondents said they reuse passwords across multiple online accounts, and more than one in five share login credentials for sensitive accounts such as email or banking.
Meanwhile, 24 per cent of those surveyed take no action after hearing about a major data breach unless they are directly notified that their own data has been compromised.
Younger workers most likely to deprioritise personal security
The tendency to focus security efforts on work accounts rather than personal ones is most pronounced among younger Australians. The report found 66 per cent of Gen Z and 65 per cent of Millennials prioritise work account security over personal accounts, compared with just 35 per cent of Gen X respondents.
Erich Kron, CISO Advisor at KnowBe4, explained that the pattern points to a deeper behavioural challenge for organisations.
“Many people are careful with their work accounts because policies require it, but those same habits don’t always carry over into personal life,” Kron offered. “Cybersecurity resilience improves when secure behaviour becomes second nature – not just something employees do to meet workplace requirements. That’s where human risk management plays a critical role in turning awareness into lasting behaviour.”
Technology alone is not enough
The findings underscore a reality that cybersecurity professionals have long warned about: technical defences cannot fully compensate for poor user behaviour. With cybercriminals increasingly leveraging AI to scale and personalise attacks, the human element remains one of the most significant vulnerabilities in any security posture.
KnowBe4 argues that organisations need to take a broader approach to human risk management, reinforcing secure behaviour not just within corporate systems but across employees’ digital lives more broadly.
The full report is available for download here.
Methodology
The survey was conducted independently by YouGov between 17-20 October 2025 among 524 Australians aged 18 and over. Data was weighted by age, gender and region to reflect Australian Bureau of Statistics population estimates and carried out in accordance with ISO 20252:2019 standards.
Last Updated on April 9, 2026 by Nick Ross



