Cybersecurity Awareness Trends 2026
Cybersecurity Awareness Month is observed in October in the United States and marks a period of heightened awareness activity across Europe, which makes now a good moment to take stock of how security awareness is changing. The discipline keeps evolving quickly — what the biggest human risks are, what gets in the way of good programmes, and what success actually looks like. Below are four of the cybersecurity awareness trends 2026 has produced so far, drawn from the newest research in the field.
1. Changes in AI Use Are Creating Greater Risk

AI has climbed from the fourth- to the second-highest human risk in just two years.
Artificial intelligence has featured among the top human risks in the SANS Security Awareness Report in recent years, but its trajectory is what stands out. Ranked fourth just two years ago, AI has now climbed to second place, trailing only social engineering, according to SANS’s 2026 survey of more than 1,700 security awareness professionals worldwide.
The finding reflects a simple reality: organisations are adopting AI-powered ways of working faster than they can put the policies, guardrails, and employee behaviours in place to use them safely. Employees have moved well beyond asking a chatbot for help. Many are now experimenting with vibe coding, building their own automations, and deploying agentic AI that can interact directly with business systems — often without security teams’ knowledge or approval.
It’s the shadow IT problem organisations have battled for years, except this form of shadow AI can write code, connect to business applications, and take autonomous action on an employee’s behalf. A related risk is overreliance: as staff get used to treating AI as their default source of answers, the critical thinking and routine security checks that used to catch mistakes are more likely to get skipped.
Whether reviewing AI-generated code, assessing a suspicious email, or summarising a sensitive document, people still play a critical role in reviewing AI outputs and deciding when action is appropriate. Awareness programmes need to focus not only on helping staff use AI well, but on reinforcing when not to trust it blindly.
2. Time Pressure Is Still the Biggest Obstacle

Lack of time has topped the list of barriers for five years running.
One of the more striking findings in this year’s report is how persistent the biggest obstacle has become: lack of time has now been the number one challenge facing security awareness programmes for five consecutive years. That pressure can be particularly difficult for operational teams, who are often measured on efficiency and service delivery rather than security outcomes.
Effective awareness was never going to be a single annual training module. It involves phishing simulations, role-specific guidance, microlearning, new reporting procedures, stronger authentication requirements, and changes to everyday workflows. Each initiative might only take a few minutes, but together they introduce friction into environments where every minute is already accounted for. From that angle, security awareness can look less like a security initiative and more like another operational demand competing for scarce time.
Getting buy-in from operations managers, department heads, and finance teams comes down to showing that a well-designed awareness programme reduces business risk without unnecessarily disrupting day-to-day work. The programmes most likely to succeed are the ones that fit naturally into existing workflows, minimise unnecessary friction, and clearly communicate the value they deliver.
3. Leading Teams Focus on Behaviour Change, Not Just Training

The highest-performing programmes now measure themselves by behaviour, not by attendance.
SANS’s 2026 report reframes the security awareness role itself: less a training or technical function, more a behaviour-change discipline. The professionals running the highest-performing programmes increasingly describe their job less as educating people and more as designing the habits that hold up under real pressure — recognising and reporting a suspicious request, questioning an unusual instruction, escalating early.
That shift is clearest in how phishing simulations are evolving. Some organisations are moving away from generic “gotcha” campaigns towards realistic, role-specific scenarios that reflect the threats employees are actually likely to face. The simulation itself is only part of the process — immediate feedback, brief micro-learning moments, and positive reinforcement all help build the specific behaviour a security team is trying to encourage.
The same philosophy is reshaping awareness programmes more broadly. Rather than concentrating learning into one annual session, some organisations are moving towards a continuous, threat-driven approach that keeps security visible throughout the year — short videos, current threat updates, live demonstrations, and concise content tied to real-world attacks, in place of long compliance modules.
4. Completion Doesn’t Prove Behaviour Has Changed
For years, many programmes measured success with straightforward completion metrics: training completion rates, quiz scores, whether staff finished their mandatory module on time. Those numbers demonstrate policy compliance, but they say surprisingly little about whether people will actually make better decisions when a real threat lands in their inbox.
The industry is shifting towards behavioural metrics instead. SANS’s own guidance on phishing simulation points to measures like the Normalised Reporting Score and the Resilience Ratio — the number of employees who report a phishing attempt divided by the number who click it — rather than raw completion rates. Instead of asking whether employees finished their training, the better question is whether they report suspicious emails faster, challenge unusual requests, or show improved decision-making over time. That can provide a more meaningful signal of security culture, because it tracks the outcome that actually matters: a workforce that completes every module but still falls for common phishing attempts has not demonstrated security awareness in the situations that matter most.
The Next Step Towards a Stronger Security Culture

Behaviour that holds up under a real attack is built through practice, not a single training session.
The tools attackers use keep evolving, but the human element remains at the centre of cyber risk. Artificial intelligence is changing how employees work and how convincingly cybercriminals can craft an attack, but social engineering is still the primary way that trust gets exploited.
Building behaviour that holds up against real-world attacks is the challenge every awareness programme is ultimately trying to solve. DIESEC’s social engineering simulations help organisations do exactly that — exposing employees to realistic phishing and social engineering scenarios while reinforcing the habits and decision-making skills needed to recognise today’s threats, including those increasingly sharpened by AI.

