TL;DR: Exposed losses from business email compromise reached $44 billion over five years, the average data breach cost hit $9.44 million, and phishing attacks rose 35% last year, according to Abnormal AI. The underlying problem is not that prevention failed once, but that many security programmes still assume attackers are static while the threat landscape keeps changing.
Editorial analysis by NHI Mgmt Group, based on content published by Abnormal AI: “The Myth of Cybersecurity: Identifying and Mitigating Cyberattacks with Dr. Eric Cole”.
By the numbers:
- $44 billion in exposed losses to business email compromise over the past five years.
- The cost of a data breach is now $9.44 million.
- There was a 35% increase in phishing attacks last year.
Key questions
Q: What breaks when organisations assume phishing prevention makes them safe?
A: The main failure is complacency.
A: Phishing succeeds because attackers only need one person to act under pressure.
Practitioner guidance
- Test email trust paths continuously Run regular simulations and scenario reviews that stress mailbox access, sender trust, and approval workflows, then compare results against actual incident patterns rather than training completion alone.
- Add verification to payment and approval flows Require independent confirmation for high-risk requests that arrive by email, especially where bank details, invoice changes, or urgent exceptions are involved.
- Monitor for business email compromise indicators Track anomalous forwarding rules, suspicious sign-in behaviour, and unusual payment requests as a combined fraud and identity risk signal.
Bottom line: The article argues that cyber myths persist when organisations mistake preventive coverage for actual invulnerability.
Explore further
View Full Forum → | NHI Foundation Course → | Our Services → | Read the full analysis →
Cybersecurity myth, not control absence, is the deeper governance failure: the dangerous assumption is that stronger tools can make an organisation effectively impenetrable. That assumption was never defensible against adaptive adversaries, and it breaks down further when phishing and BEC remain profitable at scale. The implication is that resilience must be designed around repeated intrusion attempts, not one-time prevention success.
A few things that frame the scale:
- The IBM/Ponemon 2025 Cost of a Data Breach Report found that phishing-initiated breaches cost an average of $4.8M each.
A question worth separating out:
Q: How should security teams respond when phishing losses keep rising?
A: They should treat the issue as a programme-design problem, not a single-tool problem. That means tightening verification on high-risk requests, testing real trust paths, and reviewing whether current controls still match attacker behaviour. The goal is to reduce the chance that one deceptive message becomes a financial or identity incident.
👉 Read our full editorial: Cybersecurity myths are failing as breach and phishing losses rise