Published Date:
Most security awareness professionals are probably not surprised the five biggest barriers to awareness program success identified in the 2026 SANS Security Awareness & Culture Report:
The first four are exactly the problems we expect to see. They are visible, measurable and relatively easy to explain to our management. They know when we do not have enough time. They know when the budget is too small. Our bosses certainly know our your sec team is understaffed. And we usually notice when c-level starts critically asking if all those awareness activities are progressing and what the benefits are.
Mambo #5 – The fifth barrier is different: Weak relationships can remain invisible for years. And that is precisely what makes them so dangerous.
SANS itself makes an important connection here. Securing the workforce does not just mean producing training. It means building trust and partnerships with other departments, understanding human risks together with the security team, engaging employees, measuring impact and coordinate with leadership. The report is unusually clear that these activities require people and, above all, time.
This also explains why lack of time, budget and personnel are so closely connected. If a security awareness professional has duties outside the awarenes space, with admin work or with managing und preparing awareness activities, there is very little capacity left for the work that actually creates a culture:
Talking to people, understanding how departments operate, listening to employees, working with the SOC and developing trust across organizational boundaries.
Technology can help with the workload. Good platforms can make a small awareness team dramatically more productive. But good platforms can not take away all awareness and campaign related work from a professional and AI can automate campaign and content production, personalization, translation, campaign creation and analysis – but only to a certain extend without loosing effectiveness and impact.
And technology certainly cannot automate a relationship.
I think we underestimate how important that distinction is becoming. The fourth challenge in the SANS ranking (difficulty demonstrating value) is already a symptom of the same problem. Awareness teams have traditionally communicated metrics such as training completion, phishing click rates or perhaps knowledge or risk scores. But most of these numbers are increasingly disconnected from the actual security mission.
What matters is whether people behave differently when something happens. Do they recognize something suspicious? Do they react safely? Do they verify an unusual request? And, increasingly important, do they report it quickly enough for somebody else to act?
This connects directly to the previous article (The 5 Biggest Human Risks in Cybersecurity) in this series. In the SANS ranking of human risks, failing to detect or report incidents is already the fifth most frequently cited risk. My argument there was that its fifth-place ranking actually understates its importance. A modern security stack already blocks huge quantities of malicious activity. What reaches an employee may therefore be precisely the attack that managed to get through the technical defenses.
At that moment the employee is no longer merely a person to be trained, because in this very situation the employee is a potential sensor.
But a sensor only creates value if the signal gets through (not only transmitted, but also ‘heared’). And this is where relationships suddenly become a cybersecurity issue. Imagine an employee receives an unusual call from somebody claiming to be the CFO. The voice sounds right. The context makes sense. The caller knows details about an ongoing project. In the age of AI, none of this is particularly difficult to manufacture anymore.
Will that employee challenge the request?
Will she contact the real CFO or somebody in Finance?
Will he report the call afterwards?
And perhaps most importantly: will this be done immediately?
The answer does not depend only on whether that employee once completed a vishing, phishing or training module. It also depends on something much more human: whether the organization has created an environment in which questioning, verifying and reporting are normal, accepted and awarded behaviors.
If you shout into the woods and nothing comes back, you’ll soon stop—and the same goes for relationships and user reports, most employees stop using the phish-button if they’re not getting feedback. And if phishing simulations have traditionally been designed to catch them out, they learn that security is watching them rather than working with them I can say that, fortunately, I’ve never encountered the latter in my professional environment, so to speak. Of course, as a software manufacturer, I’ve always advised against that kind of approach.
SANS reaches much the same conclusion in its qualitative findings. It explicitly describes people as assets rather than liabilities and reports that the traditional “weakest link” narrative is increasingly being rejected by practitioners themselves. Punitive and fear-based simulations can even produce the opposite of the intended result: people disengage, lose trust or hide mistakes. That matters even more for the age of AI as attacks become faster and more convincing.
AI can generate highly personalized phishing messages. It can help attackers research their targets. It can clone voices, create synthetic video and orchestrate increasingly believable social-engineering attacks across email, SMS, phone calls and collaboration platforms.
We are therefore entering a slightly paradoxical situation:
The more artificial our digital environment becomes, the more valuable genuine human relationships may become.
AI can imitate the signals of a relationship. It can write like my colleague, sound like my manager and potentially look like my CFO. But there remains a difference between reproducing those signals and actually being part of the human relationships inside an organization.
Knowing how somebody normally behaves matters. Feeling comfortable calling a colleague to verify a request matters. Trusting the security team enough to admit, “I think I may have clicked something,” matters. Having a SOC that values employee reports rather than treating them as noise matters as well, of course. These relationships create instant context and context is becoming increasingly valuable when artificial content becomes less and less distinguishable from theauthentic one.
This is also why I struggle with the way we sometimes talk about “security culture” as if it were something that could simply be produced through enough communications, training campaigns and posters. Culture does not live in a Learning Management System. Culture is exemplified; without relationships, it cannot be exemplified. Short: Culture exists between people.
SANS actually hints strongly at this when it advises awareness professionals to understand their organization, its workflows, motivations and pain points before launching campaigns. It even recommends spending the first months listening rather than immediately producing more content. And of course then the phishing excercise become much more spicy 😉
Yes, that is not soft advice. It is probably one of the harder parts of the job.
And it brings us back to those five challenges.
Lack of time,
insufficient budget
weak KPI and
too few people
make it difficult to invest in relationships.
Poor relationships then make it harder to demonstrate the value of the program (barrier #4), to gain leadership support and ultimately to create the security culture everybody claims to want. That is why I would not treat “weak relationships = 18%” as just another bar in the SANS chart. I would treat it as one of the underlying causes.
At CYBERDISE, this is also central to how we think about Behavioral Defense Engineering. Employees and professional defenders should not exist in separate worlds. Employees recognize, react and report. Security teams analyze, respond and defend. The employee report becomes a security signal, and the feedback from the security organization strengthens future behavior. The technology connects the processes and automates (really) quantitative work.
The relationship connects the humans.
And perhaps that is the most important point of all: as our environments fill with more machines, agents and non-human identities, we should not allow cybersecurity to weaken one of the things that still makes human defense uniquely powerful.
Our ability to trust, question, communicate and act together.
There is no security culture without that. So long, Palo
What are the biggest barriers to a strong security awareness culture?
According to the 2026 SANS Security Awareness & Culture Report, the five most-cited barriers are lack of time (30%), budget (26%), lack of personnel (25%), difficulty measuring or communicating program value (19%), and weak relationships (18%).
Why is “weak relationships” the most dangerous barrier, even though it ranks last?
Because unlike time, budget or headcount, weak relationships between security teams and the rest of the organization can stay invisible for years — there is no dashboard that flags it — while it quietly undermines the other four barriers.
How is a security awareness culture different from security awareness training?
Training builds knowledge and delivers content. Culture is built through relationships: how comfortable an employee feels reporting a mistake, verifying an unusual request, or trusting that the security team treats their report as a signal, not noise.
Why does difficulty proving program value connect back to weak relationships?
Metrics like training completion or click rates are disconnected from the actual security mission. Demonstrating real value requires visibility into behavior change, which in turn depends on the trust and cross-department relationships a security team has built.
How does Behavioral Defense Engineering address the relationship gap?
Behavioral Defense Engineering treats the employee report as a security signal and feeds security-team feedback back to employees, so reporting, reacting, and analyzing form one connected loop instead of two separate worlds.
SANS Institute, SANS 2026 Security Awareness & Culture Report, 11th edition, 2026. Based on responses from more than 1,700 security awareness practitioners worldwide.
Further reading:
The 5 Biggest Human Risks in Cybersecurity — and Why #5 Is Ignored
8 Hard Truths About Security Awareness Team Size (SANS 2026)
You need to load content from reCAPTCHA to submit the form. Please note that doing so will share data with third-party providers.
More InformationYou are currently viewing a placeholder content from Turnstile. To access the actual content, click the button below. Please note that doing so will share data with third-party providers.
More InformationYou are currently viewing a placeholder content from Vimeo. To access the actual content, click the button below. Please note that doing so will share data with third-party providers.
More InformationYou need to load content from reCAPTCHA to submit the form. Please note that doing so will share data with third-party providers.
More InformationYou are currently viewing a placeholder content from Vimeo. To access the actual content, click the button below. Please note that doing so will share data with third-party providers.
More InformationYou are currently viewing a placeholder content from Bunny Stream. To access the actual content, click the button below. Please note that doing so will share data with third-party providers.
More InformationYou are currently viewing a placeholder content from Wistia. To access the actual content, click the button below. Please note that doing so will share data with third-party providers.
More InformationYou are currently viewing a placeholder content from Facebook. To access the actual content, click the button below. Please note that doing so will share data with third-party providers.
More InformationYou are currently viewing a placeholder content from Instagram. To access the actual content, click the button below. Please note that doing so will share data with third-party providers.
More InformationYou are currently viewing a placeholder content from Instagram. To access the actual content, click the button below. Please note that doing so will share data with third-party providers.
More InformationYou are currently viewing a placeholder content from Google Maps. To access the actual content, click the button below. Please note that doing so will share data with third-party providers.
More InformationYou are currently viewing a placeholder content from Google Maps. To access the actual content, click the button below. Please note that doing so will share data with third-party providers.
More InformationYou are currently viewing a placeholder content from Google Maps. To access the actual content, click the button below. Please note that doing so will share data with third-party providers.
More InformationYou are currently viewing a placeholder content from X. To access the actual content, click the button below. Please note that doing so will share data with third-party providers.
More Information