SANS – Security Awareness and Culture Report 2026

Author: Melonie Cole  |  Founder and CEO, Mindshift

The SANS Security Awareness and Culture Report 2026 is published. The report, in its 11th year, draws on feedback from over 1,700 awareness practitioners across the globe. 

This is the 10th year I’ve personally contributed to this report and this year I was pleased to see NZ not only featured geographically correct but also highlighted as a contributing country to the report.

This marks a significant milestone in the growth of security awareness and culture practitioners in Aotearoa NZ, reflective of the value organisations are putting on embedding a strong security culture.

One clear message was ‘Behaviour and culture change take years, not quarters.’ For those organisations in our part of the world who have low-touch, immature, or “could do better” awareness programmes – take note.

The second very clear message, a constant across this report year on year, is that the biggest barrier is not technology or budget, it’s time. Mindshift have observed the same happening in NZ, this year more than ever. People underestimate the commitment required to influence security behaviours, develop and deliver training, be available to support teams with security initiatives, strategise, create customised and meaningful content, and measure behavioural change. This simply cannot be done with a few hours a week.

Whilst the report didn’t drop any massively unsurprising findings for me, the new sections covering AI and open-ended questions provided new food for thought.

Here are my thoughts on the report findings:

Overview of security awareness and culture programmes

Unsurprisingly there is a direct correlation between size of a security awareness and culture team and the maturity of the programme. Big orgs have more people and therefore the need to educate and influence culture at scale. In NZ, we are still relatively immature in this space – with “awareness” being assigned to a security analyst or consultant, hoping to make a material difference in a few hours a week. Realistically, this will barely keep the lights on in an awareness programme. In Mindshift’s experience, an organisation with 500+ employees requires commitment to at least one FTE.

The report states “organisations that were effectively changing behaviours had teams of at least three dedicated full-time employees and could take three to five years for organisation-wide impact.” With that in mind, we have a long way to go in NZ. This table illustrates the report survey results (“SA” = security awareness). From a local perspective, it would be rare to find an organisation with less than 1,000 staff supported by 2.70 FTEs.

Source: SANS Security Awareness Culture Report 2026.


Programme maturity

The SANS Security Awareness & Culture Maturing Model can be a useful model to figure out your current and aspirational states. Mindshift are aware of a couple of NZ-based organisations who have referenced the model, but have not used it for regular self-assessment for programme maturity. The model certainly provides a good range of metrics useful to benchmark maturity though and is certainly useful at the outset of an awareness and culture programme.

The report indicates a shift in maturity distribution from ‘non-existent’ (3%) and ‘compliance focused’ (19%) to ‘promoting awareness and behaviour change’ (45%) and ‘long-term culture change’ (21%). Great to see 12% saying their programme is at the highest level possible ‘Optimisation and resilience’ (12%). Those 12% of respondents have a programme with a robust metrics framework aligned with, and supporting the organisations mission and business goals. Their programme is no longer measuring and reporting on changes in behaviour and culture but reporting on how changes are reducing risk and enabling leadership to achieve their strategic priorities.

It would be interesting to know how NZ businesses benchmark their maturity on the SANS model, my guess based on what Mindshift see and hear, would be in the ‘Compliance focused’ and ‘Promoting awareness and behaviour change’ ratings.


Top human risks

Identifying and managing the top human risks is the foundation of any awareness programme. The top risks called out in this year’s report are the same as 2025, but the priority order is different. Not surprisingly, AI jumped from the #4 position to #2.

The report featured a detailed section on human related AI risks, breaking them down into six areas:

  • Generative AI

  • Authorised systems: only using sanctioned AI tools in the workplace, similar to most cloud based solutions 

  • Authorised data: only sharing authorised data with AI solutions, similar to most cloud based solutions 

  • Reduced critical thinking: trust and use of AI output, unlike other cloud based solutions 

  • Vibe coding: the process of using Gen AI to create software programmes 

  • Agentic AI: the automated use of Gen AI

Social engineering holds its #1 position. #2 AI. #3 Incorrect handling of sensitive information. And #4 Passwords and authentication takes the #4 slot. Interestingly, this risk has dropped in priority over the past two years, with one reason being the active deployment of stronger authentication controls. This is aligned to Mindshift’s recent work where the use of single sign-on (SSO) and the use of enterprise password manager has reduced the previous emphasis on detailed password guidance. Mindshift are, however,  seeing more emphasis on guiding staff on how to handle unexpected password and MFA prompts and also explaining how passkeys work. 

Source: SANS Security Awareness Culture Report 2026.


Most common challenges

The top challenge to building and managing an effective programme, for the fifth year running, is lack of time. Mindshift are often asked ‘How many FTE’s does an organisation of my size need?’ The report states there is no simple linear approach to this question eg, one FTE for every 10,000 employees. In part, this is because every organisation has different goals, mission and risk tolerances. “Whether an organization has 5,000 or 25,000 employees, many of the programme’s core responsibilities require a similar level of effort. This includes partnering with HR and communications, working with the security team to identify top human risks, sourcing, launching and tracking e-learning, creating engaging content, launching phishing simulations and developing new training materials.”

A clear message here is that an effective programme cannot rely solely on tools. Whilst tools to manage phishing and deliver pre-built training can be ‘set and forget’, you simply cannot subscribe to a tool and expect it to solve your problems. This is observed by Mindshift in many organisations who believe that running phishing simulations and one annual training equates to “a training and awareness programme”.


Artificial intelligence

A big change since the 2025 report, AI has become the second-highest human risk organisations are most concerned about. This has certainly been observed by Mindshift in the past 12 months. A large proportion of awareness teams are using AI to some extent with content creation being the most common usage.

The report demonstrates many awareness professionals are using AI for communications and content creation. However, using AI for more strategic higher-leverage planning capabilities such as programme planning and identifying training focus, lag behind. Mindshift predict these percentages will change dramatically in the coming 12 months as awareness professionals learn the different ways to use AI at both a strategic and operational level.

Source: SANS Security Awareness Culture Report 2026.


Compensation and career

This year’s report went deep into compensation and pay, stating the goal being to “enable you to grow your skills and career, including your compensation.” Whilst interesting to know what a top-paying awareness professional is being paid, it’s clear in a report where 1,700 people contributed, there are regional, industry, and professional background reasons for variances in pay across the globe.

In NZ, how would a security awareness professional’s compensation be determined? Most likely industry, experience, and salary benchmarking across similar roles in communications and maybe marketing. The good news is that salaries in Australia and NZ stack up well.

Source: SANS Security Awareness Culture Report 2026.


Mindshift wrap-up

  • The longer your organisation runs a structured programme focussed on the people part of cybersecurity, the more likely your programme is to succeed. 

  • Impacting security behaviours takes time – don’t expect instant results in your first year or two. Treat awareness and culture as a ‘maturity’ the same as other security focus areas.   

  • Size matters. A dedicated person or team is needed to reach your target level of maturity. Don’t expect to progress past ‘compliance-focused’ maturity if you don’t have dedicated resource. 

  • Develop partnerships with teams like communications to engage and communicate, with people and culture to support new staff and build a good culture, and with the wider business to gather and analyse data. It takes time to build trust so don’t expect overnight results. 

  • When considering AI training, think again if you’re considering generic training. What makes AI different from most previous human-risk challenges is how quickly it cuts across every role in an organisation. Consider the use of AI for specific case studies, identify the risks, and support staff as and when they need it. 


Source: SANS 2026 Security Awareness and Culture Report, SANS Institute. 

Next
Next

The human side of cyber security: what the data is telling us