The SANS 2023 Security Awareness Report: Managing Human Risk, published by SANS Institute in July 2023, examines how organizations build, mature, and staff their security awareness programs, and how security awareness professionals are compensated. The survey drew on responses from almost 2,000 security awareness practitioners across more than 80 countries, covering program maturity, leadership support, team size, top human risks, budgets, and career development.
Key findings:
- Only 6.1% of respondents (114 of 1,864 who gave a job title) held a title that reflects a human-risk focus, even though people are widely cited as the primary attack vector
- Professionals with human-risk-focused job titles earned $7,000 more annually on average ($104,157) than peers with unrelated titles ($97,350), the first year this gap favored awareness-focused roles
- 75% of organizations have a security awareness budget, but only 25% of respondents know what that budget actually is
- Programs need at least three full-time equivalent staff to change behavior, and the most mature programs average at least six FTEs
- The pay gap between technical and non-technical security awareness professionals narrowed to about $2,000 annually, down sharply from prior years
- 72% of security awareness programs report into Cybersecurity, IT, Operations, or Risk Management, while only 7% report into HR, Legal, Audit, or Training
- Nearly 70% of security awareness practitioners spend half their time or less on the role, a rate unchanged from the prior year
- Phishing, vishing, and smishing, the "three *ishings," ranked as the top human risk, ahead of passwords and authentication, detection and reporting, and IT admin misconfiguration
- Lack of relevant metrics and lack of ROI data ranked near the bottom of program challenges, well behind lack of budget, staffing, and time
- The average global salary for security awareness professionals in 2023 was $97,998, ranging from $35,040 in Africa to $116,403 in North America
- Consumer goods was the highest-paying industry for security awareness professionals at $121,875, while agriculture was the lowest at $56,810
Across the findings, a consistent gap shows up between how much organizations rely on people to manage cyber risk and how much they invest in the roles built to do that. Programs with stronger leadership support and larger dedicated teams mature faster, while budget size and metrics maturity trail far behind as differentiators. The data also suggests the field is still early in professionalizing: most practitioners work the role part time, and titles that explicitly reflect a human-risk focus remain rare, even as they now command a pay premium.
Respondents were primarily practitioners with security or technical backgrounds, based in organizations across North America, Europe, Asia, Africa, Australia, and South America, with the majority reporting into cybersecurity, IT, operations, or risk management functions rather than HR, legal, audit, or training.