The SANS Security Awareness and Culture Maturity Model eBook, published by SANS Institute in January 2026, lays out a five-stage framework for benchmarking and advancing an organization's security awareness program. Developed by SANS Workforce Security and Risk Training with input from hundreds of organizations over more than a decade, the model helps security leaders identify their program's current maturity level, understand what effective progress looks like, and communicate a roadmap to leadership.
Key findings:
- For the fifth consecutive year, Verizon's Data Breach Investigations Report finds that more than 60% of breaches involve a human element, underscoring why security culture is treated as a core risk control rather than a training checkbox
- The model defines five maturity stages: Non-Existent, Compliance Focused, Promoting Awareness and Behavior Change, Long Term Culture Change, and Optimization and Resilience
- Stage 2 (Compliance Focused) programs are typically completed within about one month, since the focus is on meeting minimum training requirements rather than shaping behavior
- Stage 3 (Promoting Awareness and Behavior Change) organizations typically see measurable behavior change within 6 to 12 months when they focus on a small set of high-impact behaviors
- Reaching Stage 4 (Long Term Culture Change) organization-wide can take 3 to 10 years, depending on organizational size, complexity, and existing culture
- Stage 5 (Optimization and Resilience) is sustained through continuous improvement rather than reached as a final milestone, requiring ongoing measurement and adaptation
- Programs with dedicated staff and longer program age show a strong correlation with higher maturity and greater influence over workforce behavior
- Cross-department partnerships, particularly with Human Resources, Communications, and Operations, are identified as a key factor that helps programs scale their reach and impact
- Metrics evolve by stage, moving from completion-based measures like training completion rates at Stage 2 to organization-level indicators like time to detect and recover from incidents, and benchmark comparisons against industry peers, at Stage 5
The model frames security awareness as a discipline that matures in a predictable sequence: from no program, to a compliance obligation, to targeted behavior change, to embedded culture, and finally to a strategic function tied to measurable business outcomes. The throughline across all five stages is that technology alone cannot close the human risk gap; progress depends on sustained investment in dedicated people, cross-functional partnerships, and communication that treats the workforce as capable of behavior change rather than as a compliance liability.
The framework draws on more than a decade of input from organizations using the model, supplemented by external data from Verizon's Data Breach Investigations Report and SANS' own 2025 Security Awareness Report on the strategic elements that most influence program maturity.