Group Purchasing
Group Purchasing

SANS 2026 Security Awareness & Culture Report

Embedding a Strong Security Culture

Asian Male Holding His Chin and Thinking

The Data Your Security Awareness Program Needs to Grow

The SANS Security Awareness & Culture Report® has tracked the human side of cybersecurity for eleven years. Each edition maps where programs stand, what risks are rising, and what the data tells us about how to respond.

The 2026 edition is the most expansive to date, drawing on responses from over 1,700 security awareness practitioners across the globe. For the first time in the report's history, the data demanded something new: a dedicated section on AI. It also introduces the new SANS Security Awareness & Culture Maturity Assessment, allowing practitioners to benchmark their program in real time against global peers.

Top Takeaways

#2

AI is now the #2 most-cited human risk among security awareness professionals, up from #4 in a single year. The 2026 report addresses it directly with dedicated guidance on GenAI misuse, Vibe Coding, and Agentic AI.

4.3+

Full-time employees required to embed security into an organization's culture. Get the benchmarking data to make the case for the team size their program needs.

11

Years of annual practitioner data making the SANS Security Awareness & Culture Report the field's longest-running benchmark for how security awareness programs are built, resourced, and measured.

Key Resources

Explore the Archive

FAQs

The SANS Security Awareness and Culture Report is an annual benchmark for the security awareness field, published by SANS Institute. Now in its 11th year, it is built from survey data collected from security awareness practitioners worldwide. It covers program maturity, human risk trends, team resourcing, AI-related risks, and practitioner compensation. It is the only annual report that benchmarks the security awareness program itself — team size, maturity stage, resourcing, and challenges — from a practitioner-first perspective.

The 2026 report draws on responses from over 1,700 security awareness practitioners across the globe, making it the most expansive edition in the report's history.

The report is built entirely from survey data contributed by security awareness professionals worldwide. Each year, SANS collects responses from practitioners running security awareness programs across organizations of all sizes and industries, spanning North America, EMEA, APAC, and LATAM. The survey covers program maturity, team size, resourcing, top human risks, leadership support, and practitioner compensation. The report is analyzed and authored by SANS security awareness experts, including the report's technical director, and reviewed by an advisory board of active practitioners from across the field. No vendor data is used in the research.

The Security Awareness & Culture Maturity Model (SACMM) is a five-stage framework developed by SANS Institute to help organizations assess and advance their security awareness programs. The five stages progress from Non-Existent through Compliance-Focused, Promoting Awareness and Behavioral Change, Long-Term Sustainment and Culture Change, and Optimization and Resilience. The model is updated annually based on practitioner survey data and includes a detailed Indicators Matrix with stage-by-stage action items. Organizations use it to identify their current maturity level, set realistic goals, and communicate program progress to leadership.

The report is designed for anyone responsible for building, running, or funding a security awareness program. Security Awareness Officers and program managers use it to benchmark their programs and identify next steps on the maturity model. CISOs and security leaders use it to understand whether their program investment is appropriate and to communicate the value of human risk management to boards and executive leadership. Risk and compliance teams use it to move beyond checkbox training toward measurable behavior change. HR and learning and development professionals use it to understand their role in building a security culture. The report is also a practical resource for practitioners looking to grow their careers in the security awareness field.