Talk With an Expert

SANS 2025 Security Awareness Report

Embedding a Strong Security Culture

Security Awareness Report 2025

Now in its 10th year, the SANS Security Awareness Report remains the definitive, practitioner-built resource for understanding and managing the human side of cybersecurity. Drawing insights from over 2,700 professionals across 70+ countries, this report reflects where security awareness programs stand today, and where they need to go next. 

This year’s edition delivers more than benchmarking data. It’s a roadmap for growth: whether you’re building your team, advocating for leadership support, preparing for AI-related threats, or mapping your next career step, the 2025 report gives you the tools to make informed, strategic decisions 

What You’ll Discover in this Year’s Report

3.9

Full-Time Employees (FTE’s) are needed to embed security into culture. Get proven strategies to gain executive buy-in and secure long-term investment

#1

Social engineering remains the #1 threat, amplified by deepfakes and AI voice cloning. Technology alone isn’t enough; training remains essential.

10 Years

It takes 3–5 years to influence behavior. 5–10 years to shape culture. Understand how team size, program longevity, and leadership support correlate with success.

Why This Report Matters

Security is no longer just a technical challenge: it’s a human one. As cyber attackers increasingly target people, not systems, organizations must adapt by building strong, sustained security cultures.

Whether you're running a one-person program or leading an enterprise-wide initiative, this report delivers the insights and evidence to drive meaningful change.

It's built by practitioners, for practitioners, because no one understands the human side of cyber risk better than you.

Navigate the SANS Security Awareness Report Archive

Transform Your Security Culture with SANS

Discover how SANS can help you create lasting, behavior-driven changes across your workforce.

Contact Us Today