For 11 years now, SANS Institute publishes its report on the state of security awareness and culture, assessing the current state and shaping its development. I find it very good, thought provoking and even inspiring at times. When I show it to others, though, that sentiment does not quite catch on. I'm not going to go through the whole report; you can do that yourself:

SANS 2026 Security Awareness and Culture Report
The field's most trusted practitioner-built benchmark for security awareness programs. Now in its 11th year, the 2026 edition covers program maturity, AI-related human risk, team resourcing, and compensation data from over 1,700 practitioners worldwide.
https://www.sans.org/for-organizations/workforce/resources/security-awareness-report

I'll pick some aspects from it and put my perspective on those.

Whom to teach

The report starts of with a great quote:

Your job isn't to educate humans on security - it's to educate the security team on humans.

This is something I do struggle with regularly. As a self proclaimed user's advocat I often have to argue with security folks and even more upper and middle management about how to not just put the hefty burden on the employees to sort out security but instead to shape the surrounding system so that people can easily choose the secure option. This got me the comment of "being soft on people" which apparently is a thing that didn't happen twenty years ago. It's not about being soft on people, although there's nothing wrong about that. It's about applying models that work on socio-technical systems.

Talking about socio-technical systems assumes, that people, technology and processes (and some more, depending on the model) form an interconnected system with feedback loops and friction and the whole shebang. People don't just act, they act according to the tech they are using, according to the processes they know and the processes they find effective (which often are two separate things). Processes are shaped by humans, often in relation to the tech in use or the tech that had been in use for the last 10 years. Tech is chosen by people, often influenced by different goals (price, features, interoperability, the good name). You get the gist.

My point is: Just dumping some knowledge on people, doesn't quite influence the system. It just applies more pressure which, apparently, worked absolutely fine twenty years ago1. Security often is friction management. Apply friction to risky actions, remove friction from legit and trusted actions. This is mostly done by influencing the other parts of the system. Tech and processes being two of them, the elusive culture being another.

But this is one central point I take from comparing this report to what I experience in my daily work. SANS is pretty advanced in their approach. They refuse to blame the individuals for system issues, claiming the culture as the reason for their behavior.

Security Culture

You already have a security culture; but what is it and is it increasing your security?

There are several factors feeding into the security culture of an organisation. People knowing, what's at stake, how to react, where to ask, feeling safe to ask questions or to admit mistakes for example. But this drives a wedge between the practitioners and management, because you cannot reliably measure these things. There are no pretty numbers like training completion rate or click rate in phishing simulations that you can lay out over time and put in your compliance spreadsheet2. How do you measure psychological safety? Well, that's what maturity models are for, amirite?

The SANS report features their Security Awareness & Culture Maturity Model. There are others, of course, like the KnowBe4 Security Culture Maturity Model or the MIT Sloan Cybersecurity Culture Maturity Model. All of them address the issue of how to measure a security awareness & culture program and how to sketch out a development path. It's basically always going from compliance driven programs through awareness and behavioral change to long term cultural change (for the better, mind) and then it's leading into cyber resilience or something like that. Every model defines more or less reliable indicators for each stage.

These are still pretty soft models and they carry very little in terms of actual measure to apply in your org. How to go about. On the technical side we do have best practices, we have example configs, labs, admin guides, the lot of it. But that's not that easy on the people/culture side of things. So, we lack an objective operationalization of security culture development. And also, as far as I can tell, we are quite a long way from having solved the translation between security awareness & culture practitioners and decision makers.

Proofpoint, for example (just because thats the vendor I work with), has a different stance. As laid out in their blog and their Proofpoint Human Risk Management Maturity Model they shift the focus also from awareness, but also from culture towards risk. Which is a great for alignment with GRC. Oh, and now it's called Human Risk Management. Forrester approves.

Human Risk Management

Many a vendor is on track for a few years now to establish platforms to measure, and hopefully remediate, human risk, pulling in much data from different sources on the status, position and privilege of users, looking at their behavioral markers in using their identity, mail and SaaS apps. You can create neat dashboards full of numbers and graphs and individual risk scores and can say: "Damn, Bob's risky as heck!" Your single glass of pain ... single pane of glas, sorry.

I don't know if you can tell that I'm not convinced, but I'm not.

Disclaimer: I haven't worked with Human Risk Management Platforms yet nor have i directly spoken to people who did about it. It's just a hunch I get when i read the marketing material and compare it, to what I've learned about infosec as a whole and behavioral science, organisational culture development and such.

I expect these programs to be able to achieve a better security under the assumption that the numbers game is complemented with solid, benevolent cultural measures, proper feedback loops into processes and technological solutions. But I do fear that it again shifts the blame onto the individuals by assigning an individual risk score. Furthermore, I fear we are falling right into Goodhart's Law:

When a measure becomes a target, it ceases to be a good measure.

Data-driven human focused security just has an ick to it for me. I do understand the need for metrics in order to steer an organisation. I do fear that the reliance on a product, a platform that puts scores on people and their behavior incentivises decisionmakers to cling to these numbers and middle management to game them.

Again, this might work if measures also address cultural aspects and processes are in place to prevent the overreliance on the scores. But HRM platforms do rely on a quite mature organisation to begin with in order to gain all these insights in real-time and with integrity.

Going on a tangent here: Good luck introducing your (AI enhanced) HRM platform on the european market. GDPR, EU AI Act and the occasional workers council in bigger orgs put governance to the test.

What's it gonna be?

What do we do now? Awareness isn't enough. Security culture is too elusive. HRM is too technocratic. And yet, there are orgs who employ a great and successful program that creates vigilant, proactive employees that display great cybersecurity in action.

And the SANS report has an answer to that. Even though their maturity model is a bit of loose model that doesn't paint a step by step path on an operational level, you can get behind the notion that behavior change seems more like a resilient security posture than just compliance. Bear in mind that the report is based on an open survey that people fill out themselves. I did for example.

But if we look at the correlation between maturity of a program and program duration and team size we do see: the more the merrier. And this reflects on something I am observing. You do need a certain amount of expertise in security, operations, communication, behavioral science. You need to know your audience, your risks, your policies and processes and your overall culture. You have to get familiar with the tools (LMS, SCORM authoring tools, etc). This takes time. Getting all stakeholders on board takes time and convincing. Building trust with employees takes time and effort and rapport. Plus, when you have to do it alone, you'll miss a lot, which sets you back regularly.

Tackling this topic isn't done as a side hustle. It's not another task of a security engineer or a CISO or HR. It is its own specialisation. Yet, I find it hard to find an easy way into the field, since most sources and material approach this field on a meta layer. Of course it does; organisations are very different and people don't run on protocols and standards by the IETF. There's no RFC for "telling your malevolent superior that there's an issue" which is generally implemented (I think).

We also really have an issue in the words, hence the title. Security Awareness is almost guaranteed to bring you audible eye-rolling. That term is burned beyond repair. It is also not sufficient. Security Culture seems very soft, repels many technical people but also in management. It also risks being put along internal communications or the people team which might drop the integration of Cyber Threat Intelligence due to theoretical distance. Human Risk Management? Oh come on. You're just making stuff up at this point. It will get you products and services though. Human factors? Good luck finding Human Factors as Managed Service or as SaaS.

The theory advanced, the market did only partially. HRM is de facto the new product, but since it has quite some requirements to meet promises made, it's not an easy sell. Also it's not cheap, which doesn't help.

So, orgs keep looking for Security Awareness platforms and services and wonder why "people still click on links". They do awareness training and cybersecurity awareness month3, and train phishing awareness with phishing simulations.

In my view, we won't reliably prepare organisations for defending against cyber threats other than integrating the human factor honestly into our security posture. Not by pushing more policies top-down on them but by letting the operations-as-done shape policies, processes and technical measures. This will require people trained and supported accordingly. Trained how is a question, I don't have a good answer to yet.

We're done with awareness, though. And we're not. It's complicated.