Published Date:
If you ask security leaders about the biggest human risks in cybersecurity, they will usually start with phishing. They are not wrong.
In the 2026 SANS Security Awareness & Culture Report, more than 1,700 practitioners worldwide named the risks they are focusing on this year, and social engineering came out on top at 77%. But the list runs to twelve risks, and SANS writes up only the top four.
The fifth — failing to detect or report incidents, at 17% — gets no section of its own at all. That is exactly the one I want to talk about.
At first glance, number five does not look dramatic. It is “only” fifth place, and SANS does not even give it a paragraph. That is precisely why it matters so much. Many organizations still treat #5 as a secondary awareness topic, when in reality it has become one of the most strategically important human defense capabilities in the age of AI.
Phishing remains dominant, for sure. Today it is not just classic phishing. SANS now puts phish, vish, smish and deepfake-enabled social engineering into this one category. That matters, because the attack surface is no longer email only.
We are clearly seeing a rise in both the number and the sophistication of vishing and smishing attacks. AI makes it easier for threat actors to research victims, tailor messages, imitate tone, and even create convincing voice-cloning scenarios. A CISO of a global service company told me today: “Skills and scale changed — your average script kiddie now has state-actor toolsets in his hands.” Right. And yes, social engineering deserves its number-one position.
But it also tells us something bigger: attackers continue to go after humans because the human path is still one of the most reliable ways into a company — and, as we will see at #5, also one of the fastest ways to catch an attack.
This is the most obvious climber in the list, moving from fourth place to second in two years. Employees are already using AI at work. They apply it with or without clear rules, approved tools or proper guidance. That creates new risks: entering confidential data into public tools, relying blindly on AI-generated output, or using AI in workflows where it quietly bypasses security judgement.
This risk is real and it is growing fast. The important part, however, is that “AI risk” is not only a policy issue. It is a behavior issue.
People do not misuse AI because they are malicious. They do it because it is useful, fast, easy and often rewarded by productivity pressure. That is why annual awareness content will never be enough.
Ha! A great example where theory is easy and reality is messy. It sounds so simple: “Do not share sensitive data.” Until you look at day-to-day work. Employees handle customer data, internal documents, screenshots, contracts, source code, chat messages, exports, notes, spreadsheets and AI prompts. Suddenly “secure data handling” is not one behavior. It is a jungle of context.
Is that not exactly the problem?
Many organizations still communicate data handling as if it were a simple compliance reminder, easy to fulfill. In reality, people need practical guidance in real contexts: what may I paste where, what can I upload, what can I summarize, what must stay internal, what must be anonymized first?
The risk does not stem solely from negligence or ignorance. The risk lies in ambiguities in operational processes, or in the usage practices for IT and AI systems.
Weak passwords and poor authentication are still a human risk, but it is telling that they now sit behind AI misuse and data mishandling.
Why is that? Because many technical controls have improved. Password managers, MFA, passkeys and better identity tooling have reduced some of the burden. This is still an important area, but it is no longer the only human-risk conversation worth having.
That is good news, and it means the field is finally moving beyond the old-fashioned, narrow view of awareness as “passwords, phishing and annual CBT.”
That is my top pick, and I would mark it with a big red circle. Modern cybersecurity systems already filter enormous amounts of malicious traffic. Most attacks never reach the employee. The messages, calls or interactions that do get through are often the more convincing, better crafted and potentially more dangerous ones.
In other words: what reaches the employee may be exactly what the technical stack did not fully stop.
And in the age of AI, that makes speed the decisive element. A suspicious email that gets reported quickly is not just an employee doing the right thing. It is a defense signal. A reported smishing message may help identify a wider campaign. A flagged vishing call may reveal a targeted attack pattern. A suspicious deepfake request may expose a new attacker technique before damage spreads.
This is why, for me, risk number five is not receiving nearly enough strategic attention. Many programs still concentrate on whether users clicked, whether they completed training, or whether they can pass a quiz. But if the workforce does not detect, escalate and report quickly, then one of the most important defensive capabilities remains unused. How reporting happens, and what comes back to the employee afterwards, turns out to matter as much as whether it happens at all.
There are two aspects. First, AI helps attackers create better lures: more credible language, more personalization, more believable context, faster iteration, and increasingly multi-channel attacks across email, SMS, voice and collaboration tools. Second, AI increases the tempo of attacks — and when the speed of attack increases, the speed of human response becomes more important too.
It is no longer just about: did the employee know this was phishing? It is about: did the employee recognize something unusual quickly enough? Did they react safely? Did they report it in time for the organization to act?
That moves us away from awareness as content delivery, toward awareness as operational defense — and to an entirely different maturity model.
Behavioral Defense Engineering (BDE) embraces a simple idea: the real challenge is not what people know. The real challenge is how people behave when something actually happens.
That is why, for us, the relevant human dimensions are report and feedback, analyze and engage, simulate and exercise, and educate and teach — in that order.
Reporting comes first. Not because education is unimportant, but because in real attacks the employee’s behavior has direct defensive value. If employees recognize, react and report quickly, they become part of the detection and security fabric of the organization. Their reports become signals for the SOC, and their judgment becomes operationally relevant.
That is a different mindset from traditional awareness.
The SANS risk list is useful. But the list alone does not tell the whole story. Yes, social engineering is number one. Yes, AI misuse is rising fast. And yes, data handling remains hard. The insight about which risk gets forgotten is this:
If your workforce does not detect and report what gets through, then the rest of your security investment is slower, blinder and weaker than it should be.
That is why #5 deserves far more attention than its ranking suggests. In an AI-driven threat landscape, it is becoming central to cyber defense.
So long — and prepare for Cybersecurity Awareness Month. Palo
What are the biggest human risks in cybersecurity in 2026?
According to the 2026 SANS Security Awareness & Culture Report, practitioners named social engineering (77%), inappropriate AI use at work (42%), sensitive data mishandling (39%), weak passwords and poor authentication (22%), and failing to detect or report incidents (17%) as their top areas of risk focus. The survey covers twelve risk categories in total and draws on more than 1,700 respondents worldwide.
Why is failing to report incidents an underrated human risk?
Because it is measured by how many practitioners are focusing on it, not by how much damage it causes. At 17% it sits fifth, and SANS does not give it a section of its own. Yet the attacks that reach an employee are the ones the technical stack did not stop, so employee detection and reporting is the last signal available before an incident becomes a breach.
Is inappropriate AI use at work really a bigger risk than weak passwords?
In terms of where security awareness teams are putting their attention in 2026, yes: 42% versus 22%. AI has moved from fourth place to second in two years. Passwords have not become safe — password managers, MFA and passkeys have simply absorbed part of the problem, which frees attention for risks that have no technical control yet.
What is the difference between security awareness and Behavioral Defense Engineering?
Awareness changes what employees know. Behavioral Defense Engineering (BDE) changes how they act when an attack actually arrives, and treats those actions as defensive signals. Awareness is a component within BDE, not something BDE replaces: the four BDE dimensions are report and feedback, analyze and engage, simulate and exercise, and educate and teach.
How do you measure whether employees actually report suspicious messages?
Not by training completion or quiz scores, which measure attitude. Measure the report rate on realistic simulations and on real threats, the median time from delivery to first report, and what proportion of reports the security team can act on. Those three numbers tell you whether your workforce is functioning as a detection layer.
SANS Institute, SANS 2026 Security Awareness & Culture Report, 11th edition, 2026. Based on responses from more than 1,700 security awareness practitioners worldwide. Risk percentages from “Top Human Risks (Your Risk Focus)”, page 10.
Further reading: 8 Hard Truths About Security Awareness Team Size (SANS 2026)
You need to load content from reCAPTCHA to submit the form. Please note that doing so will share data with third-party providers.
More InformationYou are currently viewing a placeholder content from Turnstile. To access the actual content, click the button below. Please note that doing so will share data with third-party providers.
More InformationYou are currently viewing a placeholder content from Vimeo. To access the actual content, click the button below. Please note that doing so will share data with third-party providers.
More InformationYou need to load content from reCAPTCHA to submit the form. Please note that doing so will share data with third-party providers.
More InformationYou are currently viewing a placeholder content from Vimeo. To access the actual content, click the button below. Please note that doing so will share data with third-party providers.
More InformationYou are currently viewing a placeholder content from Bunny Stream. To access the actual content, click the button below. Please note that doing so will share data with third-party providers.
More InformationYou are currently viewing a placeholder content from Wistia. To access the actual content, click the button below. Please note that doing so will share data with third-party providers.
More InformationYou are currently viewing a placeholder content from Facebook. To access the actual content, click the button below. Please note that doing so will share data with third-party providers.
More InformationYou are currently viewing a placeholder content from Instagram. To access the actual content, click the button below. Please note that doing so will share data with third-party providers.
More InformationYou are currently viewing a placeholder content from Instagram. To access the actual content, click the button below. Please note that doing so will share data with third-party providers.
More InformationYou are currently viewing a placeholder content from Google Maps. To access the actual content, click the button below. Please note that doing so will share data with third-party providers.
More InformationYou are currently viewing a placeholder content from Google Maps. To access the actual content, click the button below. Please note that doing so will share data with third-party providers.
More InformationYou are currently viewing a placeholder content from Google Maps. To access the actual content, click the button below. Please note that doing so will share data with third-party providers.
More InformationYou are currently viewing a placeholder content from X. To access the actual content, click the button below. Please note that doing so will share data with third-party providers.
More Information