Free Phishing Test
SECURITY AWARENESS

Security Teams Under Pressure: How Phishing Attacks, Staff Shortages and Legal Regulations Are Changing Security Awareness

12-may-2026 11 minutes read

Today, security teams operate under pressure that would have been hard to imagine just a few years ago. All the more so because this pressure is growing from several sides at the same time: staff shortages, regulatory changes, GenAI, the growing number of security incidents and increasingly complex digital threats have meant that cybersecurity has long ceased to be exclusively a technical area.

Today is a test of the resilience of the entire organization. This is also confirmed by legal regulations that require companies not only to implement appropriate protection measures against cyber threats, but also to demonstrate due diligence in information security, risk management and security awareness training.

But how to cover all these areas if internal security teams lack people, time and operational space for subsequent tasks?

Why are security teams under so much pressure today?

Security teams are under pressure today because the number of responsibilities is growing faster than available resources, budgets and competencies. CISO must also be responsible for detecting threats, managing security incidents, regulatory compliance, building and developing the information security system, and preparing the organization for increasingly sophisticated cyberattacks.

Gartner indicates that the current cybersecurity landscape is influenced by, among others: chronic talent shortages, regulatory changes, GenAI and constantly changing digital threats. Each of these factors separately increases the level of difficulty. Together they create an environment in which the activities of the security team increasingly require not only technical knowledge, but also operational resilience, efficient prioritization and reporting of effects to the management.

Cybersecurity data clearly shows the scale of the burden on security teams:

  • 68% of European cyber specialists declare that their work is more stressful today than five years ago.
  • 54% indicate unrealistic expectations or excessive workload.
  • 58% of organizations remain understaffed.

Source: ISACA, State of Cybersecurity 2025 – Europe, 2025.

Security teams have less space for preventive activities, analyzing trends, updating procedures and systematically strengthening information security.

For CISO the consequence is concrete: the growing number of incidents and cyber threats does not allow us to postpone actions “for later”, but an overloaded team does not always have the resources to conduct every project internally. This also applies to educational programs, phishing tests and Security Awareness which require regularity, updating of scenarios and measuring employee reactions.

The pressure is therefore double. On the one hand, organizations must improve security, meet regulatory requirements and document due diligence. On the other hand, teams responsible for cybersecurity in Poland and Europe operate in conditions of staff shortages, growing expectations and an increasingly complex attack landscape.

This is why CISOs increasingly need to ask: “what should we implement?” as well as: “who will maintain, measure and report on it throughout the year?”

Staff shortages in cybersecurity – what do the statistics say?

Staff shortages in cybersecurity are no longer a recruitment problem that can be solved with another recruitment. This is a factor that directly affects the organization’s digital security, the pace of response to cyber threats and the ability to maintain continuous preventive activities.

According to ISACA data:

  • 58% of European organizations remain understaffed in cybersecurity.
  • 65% of organizations have unfilled cybersecurity positions.

At the same time, IBM indicates that 48% of organizations face a high level of security competence deficiency.

In practice, this means that the security team’s activities increasingly have to be carried out in conditions of limited bandwidth. Often the same team is responsible for:

  • threat detection,
  • alert analysis,
  • security incident management,
  • security of ICT systems,
  • regulatory compliance,
  • security audits,
  • communication with the management board,
  • handling security incidents,
  • continuity of systems operation,
  • conducting year-round educational campaigns for both employees and management staff.
It is no wonder that with such a workload, security teams treat some elements of the cybersecurity strategy as an obligation to be ticked off, rather than a real priority.
Piotr Kaźmierzak, CEO of SECAWA

The problem is also exacerbated by the recruitment time. ISACA indicates that in many organizations, employment for entry-level positions lasts from 3 to 6 months, and a similar time also applies to more advanced roles. This means that even if the CISO has an approved cybersecurity investment program, new competencies will not appear in the organization immediately. And remember that cybercrime, new attack techniques and the growing number of incidents do not wait until the recruitment process is completed.

Therefore, the information security system should be designed so that not every activity requires constant manual operation by an internal team. Especially where periodicity, measurability and reporting are important – as in Security Awareness programs, phishing tests or employee education in information security.

Staff shortages do not release the organization from responsibility for the level of safety. However, they mean that some processes need to be conducted differently: with less workload on the team, but maintaining data, reports and evidence of due diligence.
Piotr Kaźmierczak, CEO of SECAWA

Phishing and social engineering – current cybersecurity statistics

Phishing remains one of the most important risks because it hits people: rush, routine, trust in the sender and the pressure to react quickly. Even the latest security tools do not fully eliminate the risk that an employee will click on a link, open an attachment or provide data on a fake website.

Cybersecurity data that shows the scale of the problem is

These numbers are important because they show that phishing is not a side topic in information security. It is a permanent element of the threat landscape that affects cybersecurity in Poland.

Read the summary of phishing statistics from the CERT Polska 2025 report

Cybercriminals are increasingly using scenarios that look like a regular part of the working day: a message from a courier, an alert from the system, a request from the finance department, a message from a public institution or a link to a document. That’s why phishing requires not only email filters and security tools, but also regular monitoring of how employees react to realistic manipulation attempts.

In such a model, specific data becomes crucial:

  • click-through rate,
  • report suspicious messages
  • response time,
  • vulnerability by departments and roles,
  • trend of changes over time.

Without this information, it is difficult to assess whether the organization actually reduces the risk of information security incidents or only formally implements educational activities.

An effective Security Awareness program is no longer just a regulatory requirement, but an urgent necessity

An effective Security Awareness program is no longer just a regulatory requirement, but an urgent necessity for every organization that wants to actually reduce the risk of a security incident and build a multi-layer defense against phishing, smishing, vishing and other manipulation techniques.

Technology alone is not enough. Email filters, EDR, MFA and response procedures are necessary, but they cannot replace an employee who can recognize a suspicious message, stop before clicking and report an attack attempt with one simple action.

The problem is that ensuring such a program requires constant work by the security team. It’s not just about purchasing a platform or conducting one pre-audit training. The full program means:

  • learning to use the new tool and integration with the existing infrastructure,
  • designing attack scenarios tailored to the industry, roles and processes of the organization,
  • implementation of the campaign throughout the year, not only before the inspection,
  • analysis of results and preparation of reports for the management board, auditors and supervisory authorities,
  • ensuring compliance with GDPR and control over the location of employee data,
  • constantly updating content as cybercriminals’ techniques change.

With staff shortages and an increasing number of incidents, it’s easy to understand why Security Awareness is sometimes treated as a chore to check off. Meanwhile, a poorly run program does not provide CISOs with hard data on employee behavior, does not strengthen the reporting of suspicious messages and does not help demonstrate due diligence in information security.

Not every organization has the people, time and resources to maintain a Security Awareness program on its own. However, the audit will not wait. Also the regulator. Attacker? The more.
Piotr Kaźmierczak, CEO of SECAWA

Practical SECAWA Anti-Phishing Training – a measurable program without adding work to the security team

Practical SECAWA Anti-phishing Training is a long-term Security Awareness program based on realistic simulations of cyberattacks, condensing education at the moment of a mishap and measuring employees’ reactions. It is not another platform for self-service, but a service in which SECAWA team takes over responsibility for the implementation of training – from scenarios, through campaigns, to analysis of results and reports.

Polish capital that understands the local threat landscape

SECAWA has been developing its own methodology for over 7 years, cooperating with the state administration and the enterprise sector. As a result, the training stays grounded in the realities of the market – it takes into account cybersecurity in Poland, local phishing scenarios, regulatory requirements and the way Polish organizations operate.

This is important because effective Security Awareness cannot be based solely on universal templates. Employees have to deal with cyberattacks that resemble real fraud attempts: communication from public institutions, suppliers, courier companies, payment systems and internal company processes.

Training that does not require your organization’s resources

SECAWA takes full responsibility for conducting the training:

  • scenario design,
  • implementation of the campaign,
  • preparation of nano-trainings,
  • analysis of results,
  • reporting effects,
  • updating content as attack techniques change.

The client’s side has a maximum of 3 hours per month to accept ready-made materials and schedules. This is especially important where the security team’s activities are already burdened with alerting, compliance, audits and security incident management.

PTA allows you to maintain a continuous educational program without shifting further tasks to the internal team. The CISO retains control over the course of action and effects, but does not have to build the entire training from scratch.
Piotr Kaźmierczak, CEO of SECAWA

Measurable effects and ready reports

Practical Anti-Phishing Training is based on data, not declarations. The platform measures real employee reactions to simulated attacks and shows whether the organization is actually strengthening its resistance to phishing.

The dashboard includes:

  • click-through rate,
  • response time,
  • suspicious message reporting indicators,
  • click to report ratio
  • vulnerability by departments, roles and groups,
  • trend of changes over time.

This is cybersecurity data that can be used not only to plan subsequent campaigns, but also for conversations with the management board, auditors and supervisory authorities. Ready-made reports help demonstrate that the organization not only conducts educational activities, but actually monitors their effectiveness.

In the PTA model, the goal is not just to “train employees”, administer a single knowledge test, and provide certificates of completion. The goal is a real change in behavior: fewer clicks, more reports and faster response to suspicious messages.

Employee data under control and GDPR compliance

The Security Awareness program must strengthen information security, not create new risks related to data processing. Therefore, in PTA it is important to control where employee data goes, how it is processed and who has access to it.

Our proprietary SECAWA training platform operates on infrastructure located in the European Union, which supports compliance with GDPR and personal data protection requirements. SECAWA has full control over product development and data processing, without transferring this responsibility to intermediaries outside the EU.

For organizations subject to regulations, security audits and information security management requirements, this is an important element of the entire program. Security Awareness cannot be achieved at the expense of data control.

SaaS or on-premise – two implementation models and full functionality in both

Practical Anti-Phishing Training can work in the SaaS or on-premise model. The organization chooses a variant that is consistent with its own infrastructure, security policy and regulatory requirements.

The SaaS model allows you to quickly launch training without interfering with the client’s environment. The on-premise model works well where the priority is full control over the environment, data and integration with internal procedures.

In both variants, the organization benefits from the full functionality of the solution and ongoing updates. This is important because cybercrime is constantly changing its operating techniques, and training scenarios must keep up with the development of digital threats.

Free Phishing Test – check your team’s resistance without costs or obligations

Free Phishing Test allows you to check how employees react to a realistic attack attempt before the organization decides on a full Security Awareness program. It’s a low barrier to entry: no cost, no obligation, and no burden on your security team.

As part of the test, SECAWA conducts a simulation of a cyber attack on a selected group of employees. This allows the organization to see specific behaviors:

  • who clicked on the link
  • who reported the suspicious message
  • what was the reaction time like
  • which groups require additional support,
  • what recommendations are worth implementing after the test.

What does a CISO gain after a phishing test?

After the phishing test, the CISO receives data that helps assess the real level of employee security against phishing. This is a practical starting point for deciding whether the organization needs a full training program, how intense the training should be and what scenarios it is worth building resistance to first.

Free Phishing Test also gives access to the SECAWA’s proprietary training platform. It allows you to check whether the method of conducting simulations, reporting and education after an incident fits the culture of the organization, the requirements of the security team and the expectations of the management board.

If cybersecurity in Poland today is faced with a growing number of incidents, and phishing remains one of the most frequently handled cybersecurity incidents, it is worth starting by checking your own resilience.

Schedule a Free Phishing Test and see how your team reacts to a realistic attack attempt – without adding work to the security department.

Schedule a Free Phishing Test and see how your team reacts to a realistic attack attempt – without adding work to the security department.

Gain specialised knowledge about cybersecurity

Build a resilient cybersecurity culture with our support

Let's discuss your organization's cyber needs

Fill in the form

Would you like to test the resilience of your systems?

Fill in the form to schedule a free, no-obligation consultation. We will discuss the scope of the penetration tests and prepare a proposed approach tailored to your organization and infrastructure.
Would you prefer to speak to us directly?
+48 732 123 579