Education
August 21, 2026
Cyber education as a competitive advantage in the digital economy
Companies that invest only in technology remain vulnerable to risks

The economy has become digital. This statement, which a few years ago might have sounded like a trend diagnosis, today describes a consolidated reality. Companies, consumers, financial institutions, governments, and professionals have come to depend on connected platforms to conduct transactions, share information, hire services, consume content, study, work, and relate. Digitalization has expanded access to products, services, and opportunities, but it has also significantly increased the exposure of individuals and organizations to cyber risks. In this context, digital and cyber education becomes fundamental to promoting the conscious, safe, and responsible use of technologies.
In Brazil, this movement is particularly evident in the financial sector. According to the Febraban Survey of Banking Technology 2025, 82% of Brazilians’ banking transactions in 2024 were carried out through digital channels, out of a total of 208.2 billion operations; mobile phones accounted for 75% of these transactions. Mobile banking alone amounted to 155 billion transactions in the period, 20 billion more than in 2023, while Pix reached almost 25 billion operations made via smartphones. This data shows that the digital economy is no longer a complementary layer of economic life but has become its daily infrastructure.
This expansion, however, brings an important paradox: the greater the digitalization, the greater also the potential attack surface. More connected users, more devices used, more data traffic, more integrations between systems, and more transactions carried out online also mean new points of exposure. The advancement of digital markets, therefore, simultaneously expands opportunities for innovation and the challenges related to data protection, trust, and the security of economic relations.
The user’s role
The risk is not only in the technological infrastructure. It is also in the way people understand, use, and behave in these environments. Systems can be protected, networks can be monitored, identities can be authenticated, and data can be encrypted. Nevertheless, an inadequate decision by a user, such as clicking on a malicious link, reusing weak passwords, ignoring alerts, sharing sensitive information, or approving an undue request, can compromise individual and organizational resources. This finding reinforces a central point: the main vulnerability of digital transformation is not necessarily in the technology, but in the preparation of people.
This perception was also observed in a study conducted by the author, in 2024, within the scope of the MBA in Digital Business at USP/ESALQ, which investigated the relationship between digital education, human behavior, and security in digital markets.
The research identified a relevant difference between users’ knowledge perception and their effective practices of digital security. Many participants considered themselves prepared to act in the digital environment, but still presented significant gaps related to understanding risks and adopting basic protection measures. The result reinforces a recurring finding in the specialized literature: the security challenges faced by organizations are not limited to technology, decisively involving the human factor and the difficulty of transforming knowledge into safe behavior.
This false sense of preparedness is one of the most critical points of contemporary security. In a highly digitized economy, frequent access to technology can create the impression of mastery. Using applications, making online purchases, operating mobile banking, or interacting on social networks does not necessarily mean understanding the risks involved in these actions. The daily use of digital tools can generate familiarity, but familiarity does not equate to cybersecurity competence.
The TIC Domicílios 2024, from Cetic.br, also helps to scale this scenario. The research had national coverage, with data collection between March and August 2024, covering 23,856 households and 21,170 respondent individuals, with the objective of measuring possession, use, access, and habits of the Brazilian population in relation to information and communication technologies.
In 2024, 84% of the population appeared as internet users in the standard indicator, while 29 million people remained non-users. The data reveals a dual dimension to the challenge: while the country expands its connectivity, it still needs to deal with inequalities in access, quality of use, and digital skills development.
The problem, however, is not restricted to those outside the digital environment. It also affects those who are already connected. Research on digital literacy and information security indicates that even among individuals with higher education, professional experience, and broad access to technology, important gaps in knowledge and adoption of good digital security practices may persist. This point is particularly relevant because it shifts the discussion beyond digital inclusion in the strict sense. It is not enough to be connected. It is necessary to be prepared to act in a critical, safe, and responsible manner.
Corporate environment
In the corporate environment, this issue becomes strategic. Companies frequently invest in platforms, systems, automation, artificial intelligence, cloud computing, and advanced security solutions. These investments are indispensable, but insufficient when not accompanied by an organizational culture oriented towards security. Technology reduces risks, but does not eliminate unsafe behaviors. Therefore, cyber education must be understood as a permanent organizational competence, not as a one-time training action.
Recent international reports reinforce this interpretation. The Verizon 2025 Data Breach Investigations Report analyzed 22,052 security incidents and 12,195 confirmed data breaches, involving organizations of different sizes, sectors, and countries.
The report itself highlights recurring themes such as the role of third parties, exploitation of vulnerabilities, stolen credentials, web applications, ransomware, and other attack patterns. Although the technical mechanisms vary, many of these risks remain related to how people, partners, suppliers, and organizations manage access, information, and decisions in digital environments.
The financial impact is also significant. Cybersecurity Ventures estimates that cybercrime will cost the world US$10.5 trillion in 2025 and could reach US$12.2 trillion annually by 2031. The same source points out that these costs include data destruction, stolen money, loss of productivity, intellectual property theft, leakage of personal and financial information, fraud, operational disruption, forensic investigation, system restoration, reputational damage, legal costs, and potential regulatory fines. Given this magnitude, digital security is no longer just a technical issue but becomes a matter of continuity, competitiveness, and trust.
In this context, cyber education can be objectively defined as the set of knowledge, skills, and behaviors that allow people to use digital technologies consciously, safely, and responsibly. The literature on digital literacy and information security suggests that this competence involves not only technical mastery but also the ability to recognize risks, protect personal data, adopt good practices, and exercise citizenship in connected environments. For companies, it represents a reduction in operational risks, strengthening of data protection, and increased customer and employee trust; for consumers, it represents autonomy and safer participation in the digital economy.
The central issue, therefore, is not to replace technology with education, but to integrate both. Robust digital security requires architecture, governance, monitoring, incident response, identity management, and data protection. But it also requires critical thinking, continuous learning, digital responsibility, ethics in information use, and awareness of the impact of individual actions in connected environments. In an environment marked by rapid technological transformations, professionals prepared for the 21st century combine basic digital security knowledge with human competencies such as critical thinking, intellectual curiosity, continuous learning ability, and responsibility.
Competitive advantage
It is at this point that cyber education transforms into a competitive advantage. Organizations that continuously educate their professionals and clients tend to build more resilient environments, reduce exposure to incidents, strengthen trust in digital relationships, and respond better to technological changes. In contrast, companies that treat security solely as the acquisition of tools remain vulnerable, even if they have sophisticated technologies.
Organizational culture plays a decisive role in this process. Isolated training, annual campaigns, and occasional communications are important, but not sufficient. Cyber education needs to be continuous, contextualized, and integrated into work routines. It must be present in leadership, processes, internal communication, supplier relations, digital product design, and customer experience. Security cannot be perceived as the exclusive responsibility of technical areas; it must be understood as a cross-cutting competence of the organization.
Digital transformation will continue to advance. New technologies, such as generative artificial intelligence, advanced automation, the internet of things, cloud computing, and data-driven systems, will continue to expand possibilities for innovation and efficiency. At the same time, they will also create new risk vectors.
IBM’s 2025 report on the cost of data breaches highlights that the adoption of artificial intelligence is outpacing the implementation of adequate security and governance practices, increasing the exposure of ungoverned systems. This scenario reinforces that the discussion on security must keep pace with the speed of innovation.
The future of the digital economy will increasingly depend on the ability of organizations to balance technology, governance, and education. Digital maturity will not be defined solely by the tools adopted, but by the way people and institutions use them. Trust, an essential element for any market, will be built by the combination of secure infrastructure, adequate legislation, well-defined processes, and prepared users.
The security of the digital economy, therefore, does not start only in the systems. It starts in the choices people make every day when interacting with digital environments. It starts with the decision to verify information, protect a credential, question an unusual request, understand a privacy policy, or recognize that convenience and risk often go hand in hand. In an increasingly connected society, educating people to act with digital awareness is not just a preventive measure. It is a condition for business sustainability, for consumer protection, and for the development of a safer, more reliable, and inclusive digital economy.
| To access the references of this text click here |
Who wrote this column
Marcelo Uchôa








