The eleventh SANS Security Awareness & Culture Report delivers fresh data on the maturity of security programs worldwide — showing that artificial intelligence has climbed from the fourth to the second-largest human risk in just two years.

Social engineering remains the single biggest risk for organizations, but the gap to second place is narrowing: according to the SANS Security Awareness & Culture Report 2026, based on input from over 1,700 security practitioners worldwide, inappropriate AI use at work has jumped from fourth to second place among the top human-related risks.

The report, published annually by SANS Institute to track the maturity of corporate security awareness programs, again places phishing, smishing and vishing at the top of risk priorities at 77 percent. According to the study’s authors, inappropriate AI use at work follows at 42 percent, ahead of mishandling of sensitive data (39 percent) and weak passwords (22 percent).

SANS states that the rise is not driven by AI being inherently insecure, but by organizations struggling to establish adequate policies and controls — while employees increasingly move beyond generative AI into vibe coding and agentic AI systems, often without the security team’s knowledge.

Program maturity tied to team size and program age

A central finding of the report concerns the structural conditions behind successful programs. According to the authors, program maturity correlates most strongly with two factors: team size and program age. To achieve meaningful behavior change across a workforce, organizations reportedly need at least three full-time employees (FTEs) dedicating 75 percent or more of their time to the program. Embedding a genuine culture shift requires an average of 4.3 FTEs and a timeframe of five to ten years. The most mature programs typically had more than six dedicated FTEs and had been running for over a decade.

Respondents consistently cited lack of time (30 percent) as the biggest barrier to program success, followed by budget (26 percent) and lack of personnel (25 percent). Notably, this was the first year senior leaders appeared among both the top blockers and top supporters of programs.

Positive reinforcement outperforms fear-based campaigns

Among the more than 4,500 open-ended responses collected, a clear pattern emerged: programs built on positive reinforcement, recognition, and partnership with the workforce reported markedly better outcomes than those relying on punishment or shaming. One respondent noted that shifting away from a fear-based phishing campaign with public benchmarking of failure rates toward a more transparent approach led to significantly improved reporting behavior.

Salaries rise, satisfaction stays high

The report also tracks compensation trends: the average annual salary for security awareness professionals reached $123,624 in 2026 — up $7,000 from the previous year. North America recorded the highest average salary at $131,783, while Africa reported the lowest figures. According to the study, professional background and industry sector were the strongest predictors of pay — not whether the role was full-time or part-time.

Industry sentiment also stood out: 56 percent of respondents said they were satisfied with their current employer, while another 32 percent said they wanted to stay in the field but move to a different company. Fewer than 12 percent said they wanted to leave the profession altogether.

The report concludes by recommending that organizations stop treating security awareness as a pure compliance exercise and instead position it as a core part of enterprise-wide risk management, backed by sustained resourcing rather than one-off training efforts.

By Jakob Jung

Dr. Jakob Jung is Editor-in-Chief of Security Storage and Channel Germany. He has been working in IT journalism for more than 20 years. His career includes Computer Reseller News, Heise Resale, Informationweek, Techtarget (storage and data center) and ChannelBiz. He also freelances for numerous IT publications, including Computerwoche, Channelpartner, IT-Business, Storage-Insider and ZDnet. His main topics are channel, storage, security, data center, ERP and CRM. Contact via Mail: jakob.jung@security-storage-und-channel-germany.de

Leave a Reply

Your email address will not be published. Required fields are marked *

WordPress Cookie Notice by Real Cookie Banner