Office ergonomics and cybersecurity don’t immediately seem like natural bedfellows. But there is an important human factor connecting the two: digital fatigue.

Poor workstation setup, prolonged screen time, insufficient breaks and other ergonomic issues can contribute to physical and cognitive fatigue across your workforce. And when employees are tired, they’re less engaged, less vigilant, and exhibit diminished decision-making capacities.

Here, we explore four specific ways in which this increases the chance of human error in cybersecurity, which contributes to roughly 62% of data breaches1

1. Digital fatigue makes cybersecurity training easier to tune out

Cybersecurity training is only effective if employees are able and willing to absorb it.

That becomes more difficult when employees are already dealing with a constant stream of emails, instant messages, meetings, notifications and other digital demands. Add prolonged screen time and an uncomfortable or poorly configured workstation, and the cognitive burden can become even greater.

Research from CybSafe found that just 23% of employees said they were actively engaged with their cybersecurity training, while 41% said there was simply too much information to remember and apply in their day-to-day work2.

It’s not that employees don’t care about security. The problem this data highlights is that attention is a finite resource.

When employees are experiencing digital fatigue, another training module can feel like just another item on an already overflowing to-do list. Important guidance becomes easier to skim, forget or postpone.

That matters because cybersecurity awareness depends on employees remembering what to look for and what to do when something doesn’t look right.

2. Cognitive fatigue makes security alerts easier to ignore

Cybersecurity alert fatigue is a known issue across office workforces, and the digital strain of knowledge work can cumulate into cognitive fatigue that reinforces this state.

Modern office workers are surrounded by alerts, from email notifications to Teams or Slack messages, calendar reminders, MFA prompts, browser warnings, software updates and security notifications.

Most of them aren’t dangerous. But they all compete for the same limited pool of attention, and surveys suggest that around 54% of office workers turn a blind eye to cybersecurity alerts2.

Again, this doesn’t necessarily mean employees are deliberately ignoring security.

When you’re working through a packed inbox at the end of a long day, a security warning can start to look like another interruption that needs to be cleared rather than a signal that deserves investigation.

This is the danger of ergonomics-based cybersecurity fatigue. If employees encounter too many warnings, requests and security processes, they can become desensitized to them. The result is a gradual decline in cyber vigilance.

3. Digital fatigue increases the chances an employee falls for a veiled cyber attack

A suspicious email that might have received careful scrutiny in the morning may receive a much quicker response after hours of mentally demanding digital work. And that is exactly the kind of moment an attacker can exploit.

A 2023 survey found that 47% of office workers claimed information overload was affecting their ability to identify potential threats, including phishing emails2, and a more recent report backs this up.

Of the cyber breaches involving human error, roughly 45% are attributable to misdelivery of information, with many employees claiming to be distracted when clicking on phishing links3.

For more information about the human errors in cybersecurity, we recommend reading our guide: People as cybersecurity risk 

4. Fatigue makes cybersecurity shortcuts more tempting

Not every cybersecurity mistake involves clicking an obviously malicious link. Sometimes the problem is a shortcut.

An employee who is tired, overloaded or frustrated may be more inclined to take the quickest route through a security process:

  • Reusing a familiar password instead of creating a new one.
  • Putting off an important software update.
  • Approving an unexpected request without checking it properly.
  • Using an unsecured network because it’s more convenient.
  • Clicking a link without checking where it leads.
  • Finding a workaround when a security control makes a task more difficult.

These might seem like small decisions. But collectively, they can create significant cybersecurity human risk. Research found that 36% of respondents admitted occasionally cutting corners with cybersecurity protocols, while 7% said they frequently bypassed security measures2.

This is an important area of human factors in cyber security.

Security controls inevitably introduce some friction into the way people work. That’s often necessary. But when employees are already experiencing fatigue, even relatively small amounts of friction can make the shortcut more appealing.

In other words, fatigue can make the easiest option feel like the most reasonable option, making poor office ergonomics one of the root causes of cybersecurity mistakes employees make.

What can employers do to reduce the risk?

Cybersecurity is a complex risk involving technology, processes, organizational culture and human behavior. There is no single ergonomic intervention that will always prevent an advanced phishing attack.

But with recent evidence to suggest that cognitive load can significantly undermine protective cybersecurity intentions, an effective ergonomics program should be part of the risk management strategy.

Here are some general points to get started.

1. Assess employees’ workstations

A poorly adjusted chair, monitor, keyboard or desk can contribute to discomfort and fatigue over the course of a working day or gradually over longer periods.

Regular ergonomic assessments can identify issues before they become bigger problems. Cardinus makes it easy and cost effective to assess your teams, however large and wherever work happens. 

Our virtual ergonomics assessments can be rolled out to your entire workforce in an instant, customised to each individual’s workstation and unique requirements. See our ergonomics assessments page to learn more.

If you plan on carrying out assessments internally, our guide to the best ergonomics tools for office ergonomics might be useful.

2. Encourage regular recovery breaks

Employees spending hours continuously in front of a screen aren’t necessarily more productive.

Short, regular breaks give employees an opportunity to step away from the screen, move, reset their attention and return to work with a fresh perspective.

This matters for wellbeing as much as it does engagement – and prioritizing mental health at work brings its own set of benefits.

3. Reduce unnecessary digital overload

Organizations should consider whether employees are receiving too many unnecessary alerts, communications and interruptions, and whether important information can be consolidated or prioritized.

4. Make secure behavior easy

If a security process is unnecessarily complicated, employees may eventually look for a way around it.

Cybersecurity teams should aim to build security into everyday workflows wherever possible, reducing unnecessary friction while maintaining appropriate controls.

5. Treat ergonomics as part of a broader risk-management strategy

More than chairs, desks and avoiding aches and pains, ergonomics is about understanding how people interact with their working environment and designing that environment to support safe, effective performance.

That includes considering the physical and cognitive demands placed on people who spend much of their working day using digital technology.

How can Cardinus help?

Managing office ergonomics across a workforce can be challenging, particularly when organizations have multiple locations, hybrid workers and large numbers of employees. Cardinus can help.

Healthy Working is our award-winning office ergonomics software. It provides a practical way to manage your office ergonomics program, helping organizations assess all workstation types, identify risks and support employees in creating healthier ways of working.

For organizations that would rather outsource the process entirely, Cardinus also offers fully managed ergonomics services, providing expert support for your ergonomics program from assessment through ongoing implementation.

A healthier workstation isn’t just good for employee wellbeing; it can help create the conditions people need to do their best work, including making good decisions when cybersecurity matters.

Citations

    1. Human Error Cybersecurity Statistics 2026 – Total Assure
    2. Digital fatigue is increasing cyber risks in modern workplaces – Security Magazine
    3. Data Breach Statistics – Sentinel One
Recommended Posts

Start typing and press Enter to search

A pair of factory workers loading a mechanical lifting aid.