Published Date:
I read the new SANS Security Awareness & Culture Report with a slightly unusual perspective: I manufacture security awareness software. And the finding that stayed with me is about security awareness team size — not about tooling at all.
So, obviously, I should be looking for statistics that prove companies need more technology, more automation and preferably more software. Because most people in the industry tell everyone that awareness is really simple and happens automatically. But that is NOT what stuck with me.
Some findings strongly confirm where I believe our industry needs to go. Others challenge the way awareness vendors, and including me, tend to think. And at least one conclusion in the report I fundamentally disagree with.
Here are my eight takeaways.
This may be the most uncomfortable finding for software vendors.
SANS finds that organisations effectively changing workforce behaviour have around three dedicated awareness FTEs. Moving from behaviour change to security culture requires, on average, 4.3 dedicated people.
Think about that.
We vendors like to explain how much work our platforms automate. And they do it a lot. But technology doesn’t build relationships with HR, understand employees, convince management, define the right behaviours or establish trust. And full-service solutions are unable to capture the true context and its nuances in campaigns, emails, and training sessions.
A good tool gives a good team leverage, but it doesn’t replace the team.
Two details in the report make this harder to argue with. SANS counts someone as an FTE only if they spend 75% or more of their time on security awareness and culture — so this is not a matter of adding the work to three people’s existing jobs. And the numbers come attached to timeframes: organisations changing behaviour at scale needed three to five years, embedding culture took five to ten, and the most mature programmes ran more than six dedicated FTEs for more than a decade. Security awareness team size and programme age were the two variables that predicted maturity most strongly.
SANS offers another number I think every CISO should look at: as a starting point, have one human-focused security professional for every ten technical security professionals.
I like this metric because it exposes an investment imbalance. Companies spend enormous amounts securing endpoints, identities, networks, applications and cloud environments. But attackers increasingly target the person sitting in front of them (well, they always did, right?)
Human defense cannot remain the small awareness corner somewhere next to the “real” security team. It is PART OF THE SECURITY team — which is the same argument we made when we asked why the human layer belongs in your security stack.
This was one of my biggest question marks. SANS puts security culture at the very top of its maturity model. Mature organisations are described as places where employees believe in, support and prioritise security in their daily activities.
Good.
But I miss something fundamental: values.
You cannot seriously discuss organisational culture without asking which values create that culture. Do we value openness when someone makes a mistake? Responsibility? Judgement? Reporting early rather than hiding an incident? Helping a colleague? Germans call this ‘Fehlerkultur’.
If we want security culture, those questions deserve much more attention.
Here I disagree with the report, because it stops too early.
To be fair, SANS is very positive about AI. It covers content creation, communication, personalisation, data analysis, assessments, program planning, policies and even business cases. But this still looks at AI largely as an assistant to the awareness professional.
The bigger change is AI becoming part of the awareness machinery itself.
If you really want to run proper awareness campaigns with high personalization instead of standardized stuff: Why manually design every campaign when AI can help prompt and generate it? Why stop at personalised training when OSINT can support realistic deepfake or social-engineering exercises? Why not dynamically adapt simulations to roles, languages, attack channels and observed behaviour?
AI can do much more than create prettier awareness content.
And that’s a good thing ☺ One of my favourite parts of the report is its advice to awareness professionals: think like a marketer.
SANS goes even further in the qualitative section, describing the role as neither primarily a training job nor a technical job, but a behaviour-change role operating in a security context. Exactly! Because the best awareness professional does not necessarily know the most about firewalls.
They understand people, communication, motivation, behaviour, marketing, etc. And they know enough about cybersecurity to connect all of this to real risk. In other words: we may need fewer technical nerds — and more bridge-builders.
The report puts the European average at roughly $107,000 per year (around €92K). The global average is $123,624.
This number surprised me, not because it seems low to me in absolute terms. But because of what we increasingly expect from these people. They should understand cybersecurity, human behaviour, risk, communication, marketing, AI, (people, stakeholder, project, etc) – management, analytics and metrics, organisational change. And ideally build relationships between employees, leadership and the SOC.
My perception from the market is that good people combining those capabilities are harder to find. I also think they are more valuable than this average suggests.
This part made me smile. When SANS asked practitioners about their most effective approaches to shifting security behaviour, realistic simulations featured prominently. Successful programs used role-based scenarios, immediate feedback and short learning interventions tied directly to what the employee had just experienced.
That is the critical difference. Knowing what phishing is is not the same as recognising one under pressure. Knowing that suspicious messages should be reported is not the same as actually reporting one quickly during an attack.
It’s not the first time you read this from me: You cannot train behaviour with knowledge alone. You need to exercise the behaviour. We have written about this split before — training shapes attitude, simulation shapes behaviour, and the combination is what holds.
Perhaps the most important change in the whole report appears in the qualitative responses.
Across more than 4,500 answers, SANS says one common theme emerged: “people are assets, not liabilities.” The traditional weakest-link narrative is explicitly challenged.
I couldn’t agree more. Fear, punishment and negative style ‘gotcha’ phishing undermine trust. SANS found exactly that: punitive simulations can cause employees to disengage or hide mistakes, while transparency and positive reinforcement work much better. The employee should not be treated as the vulnerability we somehow need to totally control.
They can recognise. They can react. They can report, and their report can become one of the earliest security signals your SOC receives.
That, to me, is the bigger message hidden inside the 2026 SANS report.
Security awareness is slowly moving away from teaching people about security and towards making people an active part of the defense.
We call that Behavioral Defense Engineering (BDE).
How many FTEs does a security awareness program need?
The 2026 SANS report found that organisations effectively changing workforce behaviour had at least three dedicated FTEs, and that embedding a security culture took at least 4.3. SANS counts an FTE as someone spending 75% or more of their time on security awareness and culture. It explicitly rejects a linear rule such as one FTE per 10,000 employees, because the scale is not linear — but it does note that even an organisation of roughly 1,000 employees needs a baseline of two dedicated people.
What is the right ratio of awareness staff to technical security staff?
SANS suggests one human-focused security professional for every ten technical security professionals as a starting point. The same section offers a second framing: for every ten people on your security team, at least one should be focused on the human side.
How long does it take to change security behaviour?
Three to five years for organisation-wide behaviour change, and five to ten years to embed a strong security culture, according to the 2026 report. Team size and programme age were the two strongest predictors of maturity. Behaviour and culture change take years, not quarters.
Can an awareness platform replace a security awareness team?
No, and this is the finding least comfortable for vendors. Software automates production, delivery, personalisation and measurement. It does not build relationships with HR, negotiate with management, choose which behaviours matter in your context, or earn the trust that makes people report early. A good tool gives a good team leverage; it does not replace the team.
What does a security awareness professional earn?
The 2026 SANS report puts the global average annual salary at $123,624, an increase of about $7,000 on the previous year. Region of headquarters had the largest effect on pay, with North America highest at an average of $131,783.
SANS Institute, SANS 2026 Security Awareness & Culture Report, 2026 — based on responses from more than 1,700 security awareness practitioners worldwide, including more than 4,500 answers to five open-ended questions. Download the report from SANS.
#humanauthored
You need to load content from reCAPTCHA to submit the form. Please note that doing so will share data with third-party providers.
More InformationYou are currently viewing a placeholder content from Turnstile. To access the actual content, click the button below. Please note that doing so will share data with third-party providers.
More InformationYou are currently viewing a placeholder content from Vimeo. To access the actual content, click the button below. Please note that doing so will share data with third-party providers.
More InformationYou need to load content from reCAPTCHA to submit the form. Please note that doing so will share data with third-party providers.
More InformationYou are currently viewing a placeholder content from Vimeo. To access the actual content, click the button below. Please note that doing so will share data with third-party providers.
More InformationYou are currently viewing a placeholder content from Bunny Stream. To access the actual content, click the button below. Please note that doing so will share data with third-party providers.
More InformationYou are currently viewing a placeholder content from Wistia. To access the actual content, click the button below. Please note that doing so will share data with third-party providers.
More InformationYou are currently viewing a placeholder content from Facebook. To access the actual content, click the button below. Please note that doing so will share data with third-party providers.
More InformationYou are currently viewing a placeholder content from Instagram. To access the actual content, click the button below. Please note that doing so will share data with third-party providers.
More InformationYou are currently viewing a placeholder content from Instagram. To access the actual content, click the button below. Please note that doing so will share data with third-party providers.
More InformationYou are currently viewing a placeholder content from Google Maps. To access the actual content, click the button below. Please note that doing so will share data with third-party providers.
More InformationYou are currently viewing a placeholder content from Google Maps. To access the actual content, click the button below. Please note that doing so will share data with third-party providers.
More InformationYou are currently viewing a placeholder content from Google Maps. To access the actual content, click the button below. Please note that doing so will share data with third-party providers.
More InformationYou are currently viewing a placeholder content from X. To access the actual content, click the button below. Please note that doing so will share data with third-party providers.
More Information