SEC536: Adversarial AI - Penetration Testing AI Systems


Experience SANS training through course previews.
Learn MoreLet us help.
Contact usBecome a member for instant access to our free resources.
Sign UpWe're here to help.
Contact Us
Security awareness programs have made progress over the past decade. Check-the-box training is giving way to programs that focus on managing behavioral change. But the 2026 SANS Security Awareness & Culture Report finds that changing behavior is not the same as building a security culture.
Surveying more than 1,700 security awareness professionals, the report shows that 45% of programs are in Stage 3 of the SANS Security Awareness & Culture Maturity Model: Promoting Awareness and Behavior Change. It is the largest group in the model.
The finding reflects how far the industry has come. In 2016, nearly a third of the programs were Non-existent or Compliance-focused, while only 2.2% had reached the highest stage, Optimization and Resilience. A decade later, just 3% are Non-existent, 19% are Compliance-focused, and 12% have reached Optimization and Resilience.
Programs at Stage 3 use data to identify and prioritize their top human risks. They communicate with employees throughout the year, encourage incident reporting, and help people apply what they learn, However, these programs have not necessarily changed the workforce’s shared attitudes and beliefs about security.
The distinction is simple: Behavior is what people do; culture is how people think and feel. Employees may know how to report a suspected incident, but a strong security culture ensures they feel safe doing so, even when they believe they caused it.
Moving from behavior change to culture change requires time and resources. Programs that successfully changed workforce behavior had at least three dedicated full-time employees (FTEs) and typically needed three to five years for that change to take hold across the organization. Programs that saw culture change needed at least 4.3 FTEs and five to 10 years to mature. The most mature programs had more than six dedicated FTEs and had operated for more than a decade.
Leadership support is also essential. Senior leadership appears in the report as both major blockers and important supporters, highlighting the need for security awareness teams to connect their work to business priorities. The most successful programs build partnerships across leadership, operations, audit, compliance, and governance, risk, and compliance teams. They also provide regular updates, support security-related communications beyond training, and use industry data to make the case for additional resources.
AI is adding to the challenge. It is now the second-highest human risk identified by security awareness professionals, as employees increasingly use public AI tools in ways that may expose sensitive data. At the same time, more than 70% of security awareness teams are using AI themselves, most often to create content and extend limited capacity.
The work is no longer just delivering and monitoring training outcomes. It is about managing those changing behaviors and building the relationships that allow secure practices to become part of the organization’s culture.
Read Behavior Change Is Not the Finish Line for a deeper look at why so many security awareness programs plateau at Stage 3 and what it takes to turn sustained behavior change into a strong security culture.


Launched in 1989 as a cooperative for information security thought leadership, it is SANS’ ongoing mission to empower cybersecurity professionals with the practical skills and knowledge they need to make our world a safer place.
Read more about SANS Institute