SANS Security Awareness & Culture Summit 2026: Beyond awareness 

Author: Melonie Cole  |  Founder and CEO, Mindshift

Two early starts and two packed days at the virtual SANS Security Awareness & Culture Summit 2026 left me with plenty to think about.

With around 5,000 security awareness and culture practitioners attending, a few themes kept coming through: trust, meaningful metrics, partnerships, training design and how we help people make safer decisions, many of them pushing well beyond traditional awareness training, and closely connected to the challenges we see with Mindshift clients. 


Trust is built, not assumed

Shawnee Delaney set the tone early on day one with a line that stuck with me: security always comes down to people, and vulnerabilities always come down to the person.

Trust ran through day one as something of an unintentional theme. It isn't something you can mandate, it's something you build over time, and that matters when we think about the core vulnerabilities and motivations behind human behaviour.

It's not always about knowing what to do

Elodie BRIDOUX made a point that really resonated with me: many security failures don't come from ignorance. They come from pressure, friction and poor design.

The  E.A.S.E framework, eliminating choices, automating protection, simplifying work and embedding security by default, is a useful way of thinking about whether we're actually making secure behaviour achievable.

Dr. Bob Hausmann added another perspective with the Speed Accuracy Tradeoff: the faster we work, the more mistakes we make. We often tell people to “slow down” in cyber training, but that's not always realistic under pressure.

For me, both talks reinforced the same point: we need to design security around how people actually work.


AI is changing the signals we trust

I particularly enjoyed Jessica Barker MBE PhD's insights into what she described as a new decision-making environment.

A perfectly written email, convincing voice or realistic video can now be something to be wary of. AI is changing some of the signals we've traditionally relied on to decide whether someone can be trusted.

Jess shared lots of the latest research and case studies, alongside a framework she’s been working on for how we can understand, embed and influence positive behaviour change in this changing space.

Kerry Tomlinson’s look at celebrity scams reinforced that challenge: attackers can be persistent, work across multiple channels and play the long game. As determining what's real gets harder, helping people make good decisions has to be part of the conversation.

Measure what matters

Metrics were, unsurprisingly, a big topic. We heard ideas beyond traditional compliance measures, including voluntary incident reports, near-miss disclosure, peer intervention and time to report. One comment from Lisa M. stuck with me: “The key is what you're doing with data. If you're not doing anything with it, why are you collecting it?” Exactly. Measurement should help us understand behaviour and risk, not simply produce another dashboard.


Designing training people actually need

Nadine Rose-Smith’s session on improving mandatory training through role-reliance and gamification was as much about process as content.

What stood out for me was her emphasis on the analysis that happens before you build anything: security data, HR data, staff interviews and framework analysis, to properly understand your audience before you design a single module. Engaging training isn't a problem you solve at the end, it's something you build in from the start.

Good programmes need good partnerships

Trust and partnerships also came through strongly. Your SOC, incident response team, People & Culture, communications, Service Desk and wider security team all provide valuable sources of intelligence based on real-life events to help shape your programme.

Grazielle A. talked about using real-world events seen by SOC and SIRT teams to shape practical awareness and training. Her description of the result, “real understanding, not compliance theatre”, really landed with me.

But partnerships are a two-way street, and meaningful ones take time to build. “Get to know people” is one of our values at Mindshift, so this was a theme I was very happy to hear reinforced.


Meet people where they are

Gustavo G.’s session on the unconnected workforce was spot on for me. We see this challenge regularly with clients: field workers, contractors and support staff who may not have a work device, company email or access to an LMS.

His point was simple and practical: meet people through channels they already use, and embed security into existing daily rituals. That applies more broadly too, understand your audience and build your approach around their reality.

Who's helping your customers stay secure?

Mark Sayewich raised a question I hadn't heard framed that way before: who helps our customers act securely? It points to a capability gap outside the usual employee-focused work, and a new dimension for practitioners to consider.

Make the safer decision easier

Pooyan Hamidi, MBA, CISSP asked another useful question: how do we help people make safer decisions in the moment? His three-phase approach was to make the safe path easy before a risky action, interrupt the moment during it, and learn from near misses afterwards.

I like that because it moves us away from relying on someone remembering a piece of training at exactly the right moment. Awareness matters, but so does what supports the decision.


Three questions worth asking

Oz Alashe MBE finished with three questions that stuck with me, ones I think are worth taking back into any human cyber risk programme: What's actually most likely to get us breached here, and where in the business? Is any of this working, and how do we know? And if a behaviour we're not currently looking at becomes a problem, how fast can we act and how narrowly?

They're the kind of questions that are easy to nod along to and harder to honestly answer, which is probably the point.

That's a wrap. After two very full days, I came away brimming with ideas to share with Mindshift clients and our team.

If there's one thing that ties it all together, it's this: getting beyond awareness means designing human cyber risk programmes around how people actually work, not just what we tell them to do.

https://www.sans.org/blog/a-visual-summary-of-sans-security-awareness-culture-summit-2026 

Next
Next

SANS – Security Awareness and Culture Report 2026