For years, organisations have treated digital fluency as a proxy for cyber awareness. The assumption is understandable: People who grew up in a digital world should be more able to recognise digital threats than those who did not. Yet familiarity with technology does not necessarily translate into security-minded habits.
Today’s digital natives, especially younger generations, are accustomed to environments designed around speed, convenience, and constant engagement. They move between digital platforms and make countless trust decisions each day, often without a second thought. While these habits make them effective users of technology, they can also create blind spots that cybercriminals increasingly exploit.
As younger generations make up a growing share of the workforce, organisations must confront an uncomfortable reality: Digital fluency does not automatically translate into cyber resilience.
The digital fluency gap
Findings from Yubico’s Global State of Authentication Report highlight this challenge: despite being among the fastest adopters of security tools such as multi-factor authentication, Gen Z respondents were significantly more likely to interact with phishing messages than older generations, at 62% and 23%, respectively.
The findings reveal an important distinction: Digital fluency is not the same as cyber resilience. Part of the reason lies in how younger generations have learned to interact with technology.
Gen Z grew up in a digital world designed around immediacy. Whether through social media, messaging platforms, e-commerce apps, or digital banking services, speed and convenience have become the hallmark of a generation that is “always on.”
Over time, this creates an instinct to trust familiar digital interactions and click through prompts with minimal friction. While this behaviour improves convenience and efficiency, it can also increase exposure to phishing attempts that exploit urgency, curiosity, and perceived opportunities.
When familiarity becomes a vulnerability
Digital fluency can create a false sense of self-confidence when it comes to spotting cyberthreats. The more familiar users become with digital interactions, the less likely they may be to pause and question what appears to be a routine request. In fact, Singaporean workers have been found to be among the most cyber-aware across the markets we surveyed, yet close to half of them still interacted with phishing messages.
The challenge is becoming more pronounced as AI lowers the barrier for cybercriminals to create realistic and convincing phishing messages. What was once easily detected through poor grammar, suspicious links, or obvious signs of fraud can now be disguised as authentic-looking communications that resemble everyday digital interactions.
For younger users, this creates a gap between perception and reality. The familiarity that allows them to navigate digital platforms with ease can also make them less likely to scrutinise what appears to be a legitimate request.
At the same time, attackers are no longer confined to email, with phishing attempts increasingly appearing through QR codes, social media messages, messaging applications, and other digital platforms used daily. Distinguishing between legitimate and fraudulent interactions is increasingly challenging, regardless of how tech-savvy an individual may be.
What this could spell for organizations
The consequences of these interactions extend beyond personal accounts. An employee unknowingly disclosing sensitive information in the workplace through phishing attacks leaves organisations vulnerable to identity theft, account compromise, and social engineering campaigns.
For organisations, the concern is not simply that younger employees encounter more phishing attempts. It is that the habits developed in consumer digital environments often carry over into the workplace.
With speed and convenience as a default mode of interaction, individuals must constantly keep an eye out for potential threats, while attackers only need to get it right once. A phishing attempt that begins on an individual’s device can quickly escalate into a business risk once work credentials, corporate systems, or sensitive data become compromised.
As phishing attacks become increasingly difficult to distinguish from legitimate interactions, user vigilance alone cannot remain the primary line of defence.
Organisations should instead adopt security measures that limit the impact of user mistakes and reduce opportunities for attackers to gain access.
Turning a vulnerability into a strength
Importantly, the effectiveness of these measures ultimately depends on user adoption, an area where younger generations may have an advantage.
Younger generations’ familiarity with technology also means they may be quick to adopt new tools and adjust to changing digital environments. Through cybersecurity education and appropriate security measures, they can develop secure habits just as quickly as they adopt new technologies.
Ultimately, no generation is immune to social engineering and phishing attacks. But by acknowledging that being tech-savvy does not equate to being cybersecure, organisations can better prepare their workforce for the realities of today’s threat landscape.
















