AI Is the Second-Biggest Human Risk in the Workplace, SANS Institute's 2026 Security Awareness & Culture Report Finds
Now in its 11th year, the report is the only annual benchmark built by and for security awareness practitioners.
Bethesda, MD, Aug. 27, 2026 (GLOBE NEWSWIRE) -- Two years ago, AI ranked fourth among the human risks tracked by security awareness professionals. Today it trails only social engineering, according to the SANS Institute's 2026 Security Awareness & Culture Report. It also finds most programs still don't have enough staff to move past baseline compliance training, despite growing salaries across the field.
The survey draws on responses from more than 1,700 security awareness practitioners across North America, Europe, Asia, Africa, Australia, and South America, with the findings guided by a newly formed 12-person advisory board that included practitioners from Bank of Ireland, Medibank, and Datadog.
Employees have adopted AI faster than most security teams can govern it. The 2026 report adds a section dedicated to AI-related human risk, covering three areas practitioners are now expected to manage: unauthorized use of generative AI tools, vibe coding by employees with no software development background, and the risks introduced by AI agents operating without a human reviewing their actions. The same section notes that 75% of security awareness teams are already using AI to build and manage their own programs, while only 2.4% tried it and decided it wasn't useful.
Program maturity comes down to two variables more than any other: team size and time. Changing workforce behavior takes at least 3 dedicated staff and 3–5 years to show results. The next stage, building a lasting security culture, takes a larger team; just over 4 dedicated staff and 5–10 years. Most programs surveyed fall short of both staffing thresholds. The report also includes a new Interactive Benchmarking Tool that lets practitioners compare their own program's maturity, team size, and resourcing against the full dataset in real time.
“Every year we hear the same thing from practitioners: they know where their program stands, but they aren't sure what to do next. What actions will have the greatest impact? Especially when facing limited time and budget. That's the gap we wanted to close with this edition. We updated the Indicators Matrix to better align with the Maturity Model, so practitioners get concrete actions matched to where their program actually stands. That same data gives them something real to bring into budget conversations with leadership," said Lance Spitzner, Technical Director, SANS Workforce Security and Risk Training.
Pay is climbing even though staffing hasn't caught up. The global average salary for security awareness professionals reached $123,624 in 2026, up roughly $7,000 from last year, with North America averaging $131,783. The report breaks salary data down further by region, industry, and professional background.
The SANS 2026 Security Awareness and Culture Report is free to download today at https://go.sans.org/1xCbxt. Registration for the accompanying SANS 2026 Security Awareness & Culture Report Insights Webcast, featuring Lance Spitzner and Rachael Saffer, Global Product Marketing Manager, is available at https://go.sans.org/TVoa5C. The report's release coincides with the SANS Security Awareness & Culture Summit in Las Vegas, August 27-28.
About SANS Institute: The SANS Institute is the global leader in cybersecurity training and certifications, trusted by governments, enterprises, and security professionals worldwide. For over three decades, SANS has set the industry standard for technical excellence, equipping practitioners with the real-world skills needed to defend today’s most complex digital environments. As cybersecurity evolves, SANS continues to lead the way, defining best practices and establishing the global benchmark for AI security and emerging technologies.

Jenn Elston SANS Institute 301-654-7267 jelston@sans.org
Legal Disclaimer:
EIN Presswire provides this news content "as is" without warranty of any kind. We do not accept any responsibility or liability for the accuracy, content, images, videos, licenses, completeness, legality, or reliability of the information contained in this article. If you have any complaints or copyright issues related to this article, kindly contact the author above.