I lived for 25+ years in another country as the internet began its trek into WWW land. (think 300 baud). I remember the first innocuous viruses and some early phishing scams. I lived close enough to a couple of countries and had acquaintances/co-workers in several countries where cyber security was an absolute necessity. Even with VPN, life was dangerous with email. And my coworkers were well aware of this. Back in the late '90s, two workers in a specialty field (health related) were murdered shortly after leaving one country and then sending a short email to the home office about contact information.
I can go on and on about security in some countries and even back here (USA) for people who have "friends" who are overseas.
I am paranoid for a reason when it comes to email and web sites, not so much for me as to friends who I still have overseas. Even with knowing what can happen and what has happened, I know former co-workers personally (some in leadership) who disregarded safety protocols and put lives at risk.
For Company privacy and information security, it is a risk in emails.
Some people just don't think;
Some people think "they" are immune;
Some people think that their "trusting instincts" are better than others;
some people just like to flirt with danger and see how much they can get away with;
A few think they can out con the con-phishers.
There are a hundred ways to describe these folks. IN the end, it is dangerous to the integrity of the company they work for.
IF your company is working with a company in another country Or in the USA, your company's weakness is shown by those who open such email. Cyber theft of company information comes from one person in your company opening a phishing email planted by a competing company.