SEC536: Adversarial AI - Penetration Testing AI Systems


The SANS Security Awareness and Culture Report is an annual benchmark for the security awareness field, published by SANS Institute. Now in its 11th year, it is built from survey data collected from security awareness practitioners worldwide. It covers program maturity, human risk trends, team resourcing, AI-related risks, and practitioner compensation. It is the only annual report that benchmarks the security awareness program itself — team size, maturity stage, resourcing, and challenges — from a practitioner-first perspective.
The 2026 report draws on responses from over 1,700 security awareness practitioners across the globe, making it the most expansive edition in the report's history.
The report is built entirely from survey data contributed by security awareness professionals worldwide. Each year, SANS collects responses from practitioners running security awareness programs across organizations of all sizes and industries, spanning North America, EMEA, APAC, and LATAM. The survey covers program maturity, team size, resourcing, top human risks, leadership support, and practitioner compensation. The report is analyzed and authored by SANS security awareness experts, including the report's technical director, and reviewed by an advisory board of active practitioners from across the field. No vendor data is used in the research.
The Security Awareness & Culture Maturity Model (SACMM) is a five-stage framework developed by SANS Institute to help organizations assess and advance their security awareness programs. The five stages progress from Non-Existent through Compliance-Focused, Promoting Awareness and Behavioral Change, Long-Term Sustainment and Culture Change, and Optimization and Resilience. The model is updated annually based on practitioner survey data and includes a detailed Indicators Matrix with stage-by-stage action items. Organizations use it to identify their current maturity level, set realistic goals, and communicate program progress to leadership.
The report is designed for anyone responsible for building, running, or funding a security awareness program. Security Awareness Officers and program managers use it to benchmark their programs and identify next steps on the maturity model. CISOs and security leaders use it to understand whether their program investment is appropriate and to communicate the value of human risk management to boards and executive leadership. Risk and compliance teams use it to move beyond checkbox training toward measurable behavior change. HR and learning and development professionals use it to understand their role in building a security culture. The report is also a practical resource for practitioners looking to grow their careers in the security awareness field.