Group Purchasing
Group Purchasing

What Comes After Behavior Change?

Authored byLance Spitzner
Lance Spitzner

One of my favorite parts of working on the human side of cybersecurity for so long is seeing just how much our field has matured.

It has been a long process and, at times, a frustratingly slow one. But the way we think about securing people today is fundamentally different from how we thought about it 15 years ago.

I started in cybersecurity on the technical side. In 1998, I set up my first honeypot on my wife’s dining room table because I wanted to better understand the threats I was expected to help organizations defend against. Over the years, I worked in network architecture, forensics, systems security, and other technical areas.

Around 2010, I began shifting my focus to the human side of cybersecurity. The more I studied attackers, the more I saw how often people were their target.

At the time, most organizations made very little investment in the human side of security. Security awareness often meant an annual, hour-long training video designed primarily to check a compliance box. Some of the content had little relevance to an employee’s actual job. Some of it had not been updated in years.

Something needed to change.

We Stopped Thinking Only About Training

Over the next decade, our community started making that change.

Programs moved beyond annual training toward more frequent, relevant engagement throughout the year. Then, around 2020, I began seeing another shift.

We were no longer just in the training business. We were in the human behavior and risk business.

Security awareness teams started applying behavioral science, identifying the specific human risks they needed to manage, and focusing on the behaviors that could reduce those risks.

Now, I think we are beginning to see the next step.

What if our goal is not always to teach someone another security behavior?

What if we can change the environment itself so that secure behavior becomes easier, more intuitive, or even the default?

That is where behavior change begins to become culture.

Behavior change asks: How do we get people to behave more securely?
Culture asks: How do we build an environment where secure behavior becomes easier and more natural?

For me, that distinction represents one of the most interesting ways our field is evolving.

Eleven Years of Data Shows How Far We’ve Come

I don’t base this observation on my experience alone.

The SANS Security Awareness & Culture Report is now in its 11th year, giving us more than a decade of data from the people building and managing these programs.

Some findings remain remarkably consistent. The 2026 report again found that two of the strongest drivers of program maturity are the size of the team dedicated to the human side of cybersecurity and how long the program has been operating. Mature programs take people, resources, and time.

But some of my favorite findings this year came from somewhere else entirely.

What More Than 4,500 Answers Told Us

For the second year, we asked practitioners a series of open-ended questions. We wanted to hear what actually worked, what failed, what surprised them, how AI is changing employee behavior, and what advice they would give someone entering the field.

We received more than 4,500 responses.

Multiple-choice questions are great at telling us what is happening. These responses helped us better understand why.

One theme kept resurfacing: The most effective practitioners are thinking beyond delivering training.

They are thinking about behavior. They are listening to employees. They are building relationships across the organization. They are making security simpler. They are treating people as partners instead of problems to be fixed.

One response captured the shift particularly well:

“Your job isn't to educate humans on security; it's to educate the security team on humans.”

I love that quote because it turns the traditional security awareness model around.

For years, we have asked: How do we make people understand security?

Increasingly, I think we also need to ask: How do we make security better understand people?

That is a very different way to approach the problem.

AI Makes This Shift Even More Important

AI was another major finding this year.

AI moved from fourth to second place among human risks organizations are most focused on, behind only social engineering. Employees are also moving beyond GenAI into technologies such as vibe coding and agentic AI, often faster than organizations can develop the policies and controls needed to manage them.

This creates a practical problem for security awareness teams.

The risks are changing faster than an annual training calendar can keep up.

A developer experimenting with vibe coding has different risks from someone putting sensitive information into a public chatbot. An employee using an AI agent that can take actions on their behalf introduces another set of considerations entirely.

We cannot solve all of those problems by continually adding more training.

We need to understand how people are using these technologies, work with the security team to reduce unnecessary friction, create policies people can understand and follow, and design environments that make secure choices easier.

Once again, we come back to culture.

Where Does Your Program Go Next?

Every organization is at a different point in this progression.

Some programs are still primarily compliance focused. Others are actively changing behavior. More mature programs have begun embedding security into how the organization operates, with the processes, resources, partnerships, and leadership support needed to sustain that change.

There is nothing wrong with being at an earlier stage. What matters is understanding where you are and what it will take to move forward.

That is why, this year, we have also included the SANS Security Awareness & Culture Maturity Assessment. It gives you a structured way to benchmark your program against the five stages of the SANS Security Awareness & Culture Maturity Model and identify practical next steps. The report also includes the Maturity Model Indicators Matrix, which helps you determine your current maturity level and what is needed to reach the next stage.

I have watched this field change tremendously over the past 15 years, and the 2026 data gives me a great deal to think about.

But what excites me most is the community behind that change. This report exists because security awareness practitioners around the world continue to share what they are trying, what is working, what is failing, and what they are learning along the way.

I hope you will apply those lessons to your own program.

Read the 2026 SANS Security Awareness & Culture Report and see where your program stands.

What Comes After Behavior Change? | SANS Institute