Insights · Awareness & training

Your Annual Cyber Training Is A Declaration, Not A Control

What the 2026 SANS Security Awareness & Culture Report actually says, translated for businesses that do not have a security team.

Free 2-minute checkSample

Where are your passwords kept?

Pick the closest to reality, not the ideal.

Your snapshotSample result
68out of 100
Passwords & identity72
Backups & recovery55
People & email64
See your snapshot

Every year SANS surveys the people who run security awareness programs and publishes what they found. The 2026 edition draws on more than 1,700 practitioners across the world, Australia included, and it is a good report. It is also written for a reader most Australian businesses do not employ: someone whose full-time job is changing how staff behave around security.

If you run a business with 20 to 200 people, you almost certainly do not have that person. You have an annual training module, a tick in a box on your insurance proposal, and a quiet hope that it is enough. This article is the report read on your behalf. Three findings transfer directly, and one of them should change what you do this quarter.

01

Finding one: completion is not a control

The report asked practitioners what failed. The dominant answer, in their words, was that 'compliance does not equal behaviour change'. One respondent described the pattern almost every mid-market business will recognise: an annual mandatory module, a 45-minute click-through deployed company-wide, with high completion rates on paper, little retention afterwards, and phishing results that barely moved in the months that followed. Their conclusion: 'we were measuring compliance, not comprehension'.

We have a name for this. It is the declaration gap: the distance between the controls a business declares and the controls that are actually running. Security awareness training is the clearest example on the whole insurance proposal form. The question asks whether staff receive security awareness training. You answer yes, because everyone completed the module. That is a declared control. Whether anyone in the business would recognise a fake invoice-change request on a Friday afternoon, or would report it if they did, is the running control, and the module tells you nothing about it.

That distinction matters more than it used to. Insurers are checking declared controls at claim time, not at renewal, and 'we ran the module' is a much weaker sentence than 'here is what our people did last month'.

'We were measuring compliance, not comprehension.'

Survey respondent, SANS Security Awareness & Culture Report 2026
02

Finding two: the threat is a person on the phone, and now a chatbot on the desk

The report ranks the human risks practitioners are focused on. Social engineering, meaning phishing, text-based smishing and voice-based vishing, is first at 77 per cent, and the report notes it is 'by far' the top risk because technology alone can only go so far against it. It also notes a rise in both volume and sophistication of the phone and text versions, partly because organisations have got better at catching email, and partly because AI now makes it easy to research a target and build a convincing story, including cloned voices.

Second, up from fourth two years ago, is inappropriate AI use at work, at 42 per cent. The open-ended answers explain what that looks like in practice. Respondents described staff 'pasting sensitive material into public AI tools without thinking twice. Customer details, internal documents, draft contracts, sometimes whole chunks of code.' Not from bad intent. The tools made work faster and, as one practitioner put it, the friction of 'should I be putting this here?' disappeared somewhere between deadline pressure and curiosity. Another reported staff overriding explicit security advice because 'Copilot said so'.

77%rank social engineering as their top human risk
42%rank inappropriate AI use at work, now the number two risk
#1operations teams are the top blocker of awareness efforts for the first time

Source: SANS Security Awareness & Culture Report 2026

For a mid-market business the translation is blunt. The two behaviours that will decide your next incident are whether your finance officer pauses before actioning a bank-detail change that arrived by email or phone, and whether your staff know which AI tools they are allowed to put customer data into. Neither is covered by a module recorded three years ago. Both can be taught in an hour, in the room, using your own invoices and your own tools.

03

Finding three: you cannot copy the enterprise playbook, and you do not need to

Here is the finding that does not transfer, and it is worth being honest about. The report's data says that changing workforce behaviour takes a dedicated team of at least three full-time people and three to five years, and that embedding a real security culture takes more than four and five to ten years. The most mature programs have six or more dedicated staff and a decade of history. The biggest barrier practitioners report, year after year, is not budget or technology. It is time.

No 60-person business is going to fund that, and pretending otherwise is how awareness training ends up as a licence renewal nobody looks at. But read past the headline numbers to what practitioners said actually worked, and a different picture appears, one a small business can execute better than a large one precisely because the room is smaller.

The successful approaches were not tools. They were focusing on the fewest behaviours possible and making them simple. They were short, realistic exercises tied to the work people actually do, with immediate feedback rather than a lecture. They were positive. One organisation replaced flagging failures with publicly recognising staff who did the right thing, and reported its phishing report rate rising nearly 40 per cent within about three months, with staff contacting security before incidents rather than after. Another found that when one or two respected employees started openly sharing their own catches, reporting rates rose by more than 70 per cent, an effect stronger than any incentive scheme. The report's summary of 4,500 open-ended answers is a single sentence: people are assets, not liabilities, but only when they are treated as partners rather than compliance subjects.

The report also carries a warning that applies with extra force to businesses with stores, sites and warehouses. For the first time, operations teams ranked as the number one blocker of awareness efforts, at 23 per cent, because training is seen as something that interrupts the work. If your people are on a shop floor or a site, training that pulls them off it to sit at a screen will always lose. Training that comes to them, on shift, in plain English, using their own scenarios, does not.

04

What to do this quarter

You do not need a program. You need four decisions.

  1. Pick three behaviours, not thirty. For most mid-market businesses: verify any payment or bank-detail change by a known phone number before acting; report the odd email or call, even when unsure; and put customer or company data only into the AI tools the business has approved. Write them down. That is the policy.
  2. Run one live session, in person, on site. An hour with the people who handle money, customer data and the front desk, using your own invoices, your own suppliers' names and the AI tools your staff are actually using. Ask what security advice they have quietly stopped following, and why. The report's most repeated advice to new practitioners was to start by listening, not launching.
  3. Make reporting a win, not a trap. No 'gotcha' phishing tests, no naming and shaming. The report is clear that fear-based campaigns backfired repeatedly. Thank people publicly for the report that turned out to be nothing. The report that turns out to be something will follow.
  4. Rehearse the first hour. The staff behaviours above stop most incidents. For the one that gets through, your leadership team needs to have decided who calls the insurer, who talks to customers, and who has authority to take systems offline, before the morning it happens. That is a tabletop exercise, and a 45-minute version you can run yourself is free.

Then apply the honest test. If your insurer asked tomorrow what your people did after the training, not whether they completed it, what would you say? If the answer is a completion percentage, you have a declaration. If it is a story about the invoice that got questioned last month, you have a control.

05

Where to start

If you want to know where the rest of your controls sit, declared or running, our free check takes two minutes, asks seventeen plain-English questions, and gives you an honest snapshot. No login, no sales call attached: https://app.vintaris.com

Free 2-minute check

Declared or running? Find out in two minutes.

Seventeen plain-English questions, an honest snapshot of your security posture, and the gaps worth closing first. No login, no sales call attached.

Start the free check →Want the session run for you? See on-site training

Prepared and reviewed by the Vintaris security team.Figures and quotations are from the SANS Security Awareness & Culture Report 2026. General information, not legal advice.