Published Date:
A Look at Cybersecurity Awareness and Human Defenses from the Perspective of a CEO and Board Member. Part 1/2
No, most security awareness strategies don’t start with selecting the provider! They still start with content and this is still a better start. Which training should we run? Which topics should we cover? How often should we simulate attacks and should they be Phishes, Smishes or something else? Which communication should go out next?
The 2026 SANS Security Awareness & Culture Report proposes an alternative security culture action plan worth investigating especially for the board members. Its awareness plan for team size, sustaining leadership support and ultimately building a stronger security culture is barely about content at all. Instead, SANS recommends that organisations:
I like this action plan a lot. No, I love it (did you read #4?!, awesome). And I think it may be one of the most useful parts of the entire report. Not because every recommendation is completely new, but because taken together they suggest something more fundamental: if you want to build security culture, you probably need to rethink what your security awareness strategy is actually supposed to achieve.
Security culture is not a content problem
For years, awareness has often been organised around the assumption that the core task is educating employees. Create content, distribute it, test whether people understood it, run fully automated standardized phishing exercises and repeat the process.
Education, be it with exercises or CBTs, certainly has a role, but culture is created differently. Culture develops through relationships, shared experiences, behaviours, values and the way people interact when something actually happens. That means an awareness team needs much more than good content. It needs an understanding of the organisation, access to leadership, cooperation with other departments and, especially in my view, a much closer relationship with the operational security teams.
SANS recommends partnerships with Communications, HR and Business Operations, but it also specifically encourages awareness professionals to work with the SOC, incident response and cyber threat intelligence teams to understand their challenges and determine how the human side of security can support them.
That point deserves more attention.
In many companies, awareness and security operations are still surprisingly far apart. The SOC monitors endpoints, identities, network traffic, cloud services and threat intelligence, while the awareness team runs training and simulations. Employees somehow sit between those two worlds.
In an AI-driven threat landscape, that separation makes increasingly little sense.
Employees experience things that technical systems cannot always interpret. They get a strange phone call, see the slightly unusual request from a colleague, notice that the wording does not quite fit, or recognise that a technically convincing message simply makes no sense in its business context.
That judgement can have defensive value, but only when there is a short, fast and trusted path from the user to the people defending the organisation.
This is where I would extend the SANS action plan. Awareness should not only collaborate with the SOC when planning campaigns. The two should become operationally much closer.
If threat intelligence shows that a certain role is being targeted, that information can influence the next exercise. If users report suspicious emails, calls or messages, those reports can provide additional information to the SOC. If the SOC discovers a new campaign, awareness teams can quickly prepare our employees for exactly that situation.
The flow begins to look more like this: Threat intelligence – realistic exercise – employee behaviour – reporting – SOC signal – feedback – adaptation
That is also why we put Report + Feedback first in our Behavioral Defense Engineering methodology, followed by Analyze + Engage, Simulate + Exercise and Educate + Teach.
Education remains important, but it becomes part of a wider defensive process rather than the centre of everything.
An employee who quickly reports a convincing social-engineering attempt is not merely demonstrating that a training module worked. She may be providing one of the earliest signals that something is happening! And in an environment where for the bad guys AI is increasing both the quality and the speed of attacks, the speed of that signal increasingly matters.
There is a sentence in the SANS action plan that I particularly like: “People follow people, not policies.” The report describes how somebody who genuinely cares can become a cybersecurity champion.
That connects directly to the previous article in this series about weak relationships being the silent killer of security awareness. Technology can automate campaigns to a certain extent. AI can create scenarios, translate content, widely personalise exercises and remove enormous amounts of manual work. External specialists can provide expertise and help teams move much faster.
But relationships and context remain internal.
Someone still has to understand the context, how the organisation works, know which groups have which problems, listen to employees, design awareness campaigns really adapted to the company context, build trust with management and maintain a genuine working relationship with the security team.
For this reason, I am extremely sceptical about the idea that an organisation can simply outsource security culture (and awareness exercises) through a full-service awareness offering. You can outsource activities and use technology to increase capacity, but culture itself has to develop inside the organisation.
The same applies to (threat) reporting. A beautifully designed report button is useful, but employees still need to believe that reporting something suspicious is appreciated. They need confidence that somebody on the other side is listening. That is where culture becomes operational.
Another strong recommendation in the SANS plan is to talk to leadership and the security team in terms of risk and culture. SANS notes that awareness can still be perceived as a compliance activity rather than a meaningful part of risk management, and recommends connecting awareness initiatives to the organisation’s strategic security priorities.
I think the principle should go even further: speak the language of whoever you are trying to reach. When talking to leadership, “we need a new awareness initiative” is rarely a compelling argument. A much stronger conversation is about the business problem.
Perhaps employees are being targeted by increasingly convincing SMS or vishing attacks. Perhaps reporting is too slow. Perhaps AI adoption is creating new data-handling risks. Perhaps the SOC receives employee reports, but too late and without enough context to act quickly (this I just heard from one of our customers). Those are business and security problems. Awareness activities are part of the response.
The same applies when communicating with employees. Most people do not care about improving the organisation’s “human risk posture”. They care about doing their jobs properly without creating unnecessary problems. So the language should reflect their reality. What should I do when a senior manager suddenly asks me to change payment details? Which information may I enter into a chatbot? How can I verify a suspicious call without creating an awkward situation? And: Where do I report something strange, and what happens after I do?
The closer the security communication gets to real work, the more useful it becomes.
Count the heads – There is a mismatch of investment – It is absolutely undisputed that technical cybersecurity systems are essential for the security of organizations, and yet SANS proposes a very simple way to demonstrate today’s investment gap between technical and human-focused security: count the people: The report describes the familiar example of a 50-person security organisation with 49 people focused on technology and only one focused on the human side. As a starting point, SANS recommends considering approximately one human-focused security professional for every ten technical security professionals. I will come back to that ratio in a separate article because it deserves more attention.
Here, however, the more interesting point is what the ratio says about strategy: Many organisations describe employees as an important part of cybersecurity while allocating almost all their security resources to technology. There is nothing wrong with investing heavily in technical security; obviously we need it. But if social engineering remains the leading human risk, AI is making attacks more personalised, and employees can contribute valuable detection signals, then the human side of security cannot remain a small awareness function somewhere on the (often disconnected) organisational edge. If people are genuinely part of the defense, the organisational model and the awareness professionals headcount should eventually reflect that.
The final element of the SANS approach is refreshingly simple and especially appealing to me as CEO and board member. Build the case using three elements:
This sounds almost obvious, yet it produces a very different conversation from the traditional compliance argument of my colleagues.
“We need to run annual security training because regulation requires it” may justify an activity, but it does not describe a security strategy.
A stronger case could start with the changing threat environment. AI allows attackers to create more personalised social-engineering attacks, operate across multiple channels and move faster. Technical defenses will continue to stop huge volumes of malicious activity, but some interactions will reach employees.
The organisation therefore needs people who can recognise unusual situations, react safely and report quickly. Those reports need to reach the professional defenders (read: our SOC), become useful signals and trigger an appropriate response.
Now the awareness program is no longer justified because people need another course.
It is justified because the organisation needs another defensive capability!
This is why I find the SANS security culture action plan so compelling. It quietly moves the centre of gravity away from content.
A traditional awareness strategy might begin with topics, training calendars and campaign plans. A more mature human-defense strategy begins with organisational risk and the behaviours needed to manage it. From there, it builds relationships with the workforce, connects with the SOC and threat intelligence teams, exercises realistic situations, creates effective reporting and feedback loops, measures behavioural change and communicates the resulting value to leadership.
This is also where the SANS report increasingly overlaps with what we mean by Behavioral Defense Engineering. The question is no longer simply how much employees know about cybersecurity. The more important question is how they behave when something actually happens, and how that behaviour connects with the rest of the security system.
That shift affects the technology, the metrics, the organisational structure, the role of the awareness professional and at the end the whole error culture (read: resilience!). More importantly, it changes the relationship between employees and the professional security team around them.
And perhaps that is the most important part of the whole action plan. Security culture should not sit beside the security architecture as something soft and separate.
It should become part of it.
An organisational defense capability.
So Long, Palo
PS: More action plans for awareness practitioners – Do you know CYBERDISE’s Awareness Playbook? It fills the operational awareness execution gap in the NIST documents, especially in NIST CPLP. So it’s the plan for setting up your own, custom cybersecurity awareness program
– Palo Stacho is CEO of CYBERDISE and a cybersecurity entrepreneur with 30 years of industry experience. He is also a board member, scale-up trainer and speaker. He lives with his family in Switzerland.
What is the SANS 2026 security culture action plan?
The SANS 2026 Security Awareness & Culture Report lists six action items to grow the awareness team and keep leadership support: develop partnerships, talk to leadership and the security team in terms of risk and culture, demonstrate the investment gap between technical and human-focused security, communicate regularly with leadership, break down your needs, and build a business case. Almost none of them are about content.
Why should security awareness work closely with the SOC?
Employees notice things technical systems cannot always interpret: an odd phone call, a request that makes no business sense. That judgement only has defensive value if it reaches the SOC quickly and in a usable form. SANS recommends partnering with the SOC, incident response and threat intelligence teams; Behavioral Defense Engineering (BDE) connects exercises, reporting and SOC signals in one loop.
How do you build a business case for security awareness?
SANS recommends a Problem–Solution–Value structure. Problem: which business or security problem needs solving, and why now? Solution: what should change? Value: how does that change support the organisation’s priorities? “Regulation requires annual training” justifies an activity. A business case describes a defensive capability the organisation needs.
Can you outsource security culture?
You can outsource activities such as content, campaigns and simulations, and use technology and external specialists to add capacity. Culture itself has to develop inside the organisation, because it rests on internal relationships: knowing how departments work, trust with management, and a genuine working relationship with the security team.
What does “people follow people, not policies” mean for security awareness?
The line comes from a practitioner quoted in the SANS 2026 report: once somebody who genuinely cares takes on the topic, they become a cybersecurity champion and others follow. Another respondent found peer influence stronger than incentives or gamification. Security culture spreads through relationships, not through policy documents.
SANS Institute, SANS 2026 Security Awareness & Culture Report, 11th edition, 2026. Based on responses from more than 1,700 security awareness practitioners worldwide. Section “Action Items to Increase Team Size and Sustain Long-Term Leadership Support”. sans.org/mlp/ssa-security-awareness-report
Further reading:
5 Culture Challenges Destroying Security Awareness (And Why #5 is Your Silent Killer)
8 Hard Truths About Security Awareness Team Size (SANS 2026)
The 5 Biggest Human Risks in Cybersecurity — and Why #5 Is Ignored
You need to load content from reCAPTCHA to submit the form. Please note that doing so will share data with third-party providers.
More InformationYou are currently viewing a placeholder content from Turnstile. To access the actual content, click the button below. Please note that doing so will share data with third-party providers.
More InformationYou are currently viewing a placeholder content from Vimeo. To access the actual content, click the button below. Please note that doing so will share data with third-party providers.
More InformationYou need to load content from reCAPTCHA to submit the form. Please note that doing so will share data with third-party providers.
More InformationYou are currently viewing a placeholder content from Vimeo. To access the actual content, click the button below. Please note that doing so will share data with third-party providers.
More InformationYou are currently viewing a placeholder content from Bunny Stream. To access the actual content, click the button below. Please note that doing so will share data with third-party providers.
More InformationYou are currently viewing a placeholder content from Wistia. To access the actual content, click the button below. Please note that doing so will share data with third-party providers.
More InformationYou are currently viewing a placeholder content from Facebook. To access the actual content, click the button below. Please note that doing so will share data with third-party providers.
More InformationYou are currently viewing a placeholder content from Instagram. To access the actual content, click the button below. Please note that doing so will share data with third-party providers.
More InformationYou are currently viewing a placeholder content from Instagram. To access the actual content, click the button below. Please note that doing so will share data with third-party providers.
More InformationYou are currently viewing a placeholder content from Google Maps. To access the actual content, click the button below. Please note that doing so will share data with third-party providers.
More InformationYou are currently viewing a placeholder content from Google Maps. To access the actual content, click the button below. Please note that doing so will share data with third-party providers.
More InformationYou are currently viewing a placeholder content from Google Maps. To access the actual content, click the button below. Please note that doing so will share data with third-party providers.
More InformationYou are currently viewing a placeholder content from X. To access the actual content, click the button below. Please note that doing so will share data with third-party providers.
More Information