Keepnet – AI-powered human risk management platform logo
Menu
HOME > blog > security awareness program benchmarks

Security Awareness Program Benchmarks 2026: Team Size, Timeline and Metrics

Behavior change needs at least three full time people and three to five years. See the 2026 benchmarks for team size, timeline and metrics.

Ozan Ucar, Founder and CEO of Keepnet

Illustration of three security professionals looking at two bars labelled 3.0 behavior change and 4.3 culture change, the 2026 security awareness program benchmarks for team size.

A security awareness program needs at least three dedicated full time people to change how a workforce behaves, and at least 4.3 to change the culture around that behavior. Behavior change takes three to five years. Culture change takes five to ten. Those are the 2026 benchmarks from a survey of more than 1,700 practitioners, and they are the numbers most programs are measured against without ever being told.

Most programs are not staffed for either target. This article sets out what the benchmarks say, where the average program actually sits against them, and what to do when the gap will not be closed by hiring.

How many people does a security awareness program need?

Start with the definition, because it changes the answer. A full time employee here means someone who spends 75 percent or more of their time on security awareness and culture. Four people who each spend a quarter of their week on it do not add up to one.

Against that definition, the thresholds are:

Three full time people to have an impact on how employees behave.

At least 4.3 to move the organization's culture rather than only its behavior.

More than six in the programs that reach the highest maturity level, which have usually been running for more than ten years.

The correlation between team size and maturity has held for six years running. Average team size by maturity stage:

Non-existent, 1.47 people. Compliance focused, 2.51. Promoting awareness and behavior change, 3.02. Long term culture change, 4.36. Optimization and resilience, 6.49.

Average team size rises with every maturity stage. Source: SANS Security Awareness and Culture Report, 2026, p. 16.

Source: SANS Security Awareness and Culture Report, 2026, p. 16.

Does team size scale with headcount?

Not in a straight line. The research looked for a simple ratio, one person for every 10,000 or 20,000 employees, and did not find one. Whether an organization has 5,000 employees or 250,000, many core responsibilities take a similar amount of effort: partnering with HR and communications, identifying top human risks with the security team, sourcing and tracking training, building simulations, writing the communications around them.

Average number of people by organization size:

Fewer than 1,000 employees, 2.70. From 1,000 to 5,000, 2.78. From 5,001 to 10,000, 3.37. From 10,001 to 25,000, 3.66. From 25,001 to 75,000, 4.37. More than 75,000, 5.78.

Two practical anchors come out of this. Even an organization of roughly 1,000 people still needs a baseline of at least two dedicated people. And if you want a ratio, size the awareness team against the security team rather than the whole company: for every ten people on the security team, at least one should focus on the human side.

Source: SANS Security Awareness and Culture Report, 2026, p. 17.

How the average program compares with the benchmark

Put the two sets of numbers side by side and the picture is uncomfortable. The behavior change threshold is three people. Organizations under 1,000 employees average 2.70, and those between 1,000 and 5,000 average 2.78. Both sit below the threshold for the outcome they are being asked to deliver.

The culture threshold is 4.3. Only two of the six size bands reach it, 25,001 to 75,000 employees at 4.37 and more than 75,000 at 5.78. Every band below that is staffed for behavior change at best, while usually being measured on culture.

Four of six organization size bands sit below the culture change threshold. Source: SANS Security Awareness and Culture Report, 2026, p. 16 and p. 17.

This is the gap worth naming in a budget conversation. Not "we need more people," but "we are staffed at 2.78 against a benchmark of 3.0 for the outcome you asked for, and 4.3 for the one in the strategy deck."

How long does it take?

Three to five years to genuinely change behavior across an organization. Five to ten years to shift culture. More than ten years before the strongest programs reach the optimization stage. Program age was the second strongest predictor of maturity after team size.

The uncomfortable part of that finding is what it says about annual planning. Behavior and culture change take years, not quarters, and a program restarted every time a sponsor changes never gets past the compliance stage.

Source: SANS Security Awareness and Culture Report, 2026, p. 17.

What actually blocks programs

Not budget, and not tooling. The top barriers reported for 2026:

Lack of time, 30 percent. Budget, 26 percent. Lack of personnel, 25 percent. Difficulty measuring or communicating program value, 19 percent. Weak relationships with other departments, 18 percent. Security fatigue and training overload, 17 percent.

Time has been the number one barrier for five years running. That matters for how you read the staffing numbers: a program that is short on hours does not fail loudly. It quietly drops the things that take the most time and pay back the slowest, which are exactly the things the maturity research says drive behavior change.

Source: SANS Security Awareness and Culture Report, 2026, p. 12.

Where the program sits changes what it can do

43 percent of awareness teams report into the security team and 22 percent into IT. The remaining third sit under operations, risk, legal, audit, compliance, HR, training or communications.

The distinction is not cosmetic. The security team is where an organization's top human risks are identified and prioritized, and where policy changes and tool rollouts originate. A program run from outside that loop tends to optimize for completion and audit evidence, because those are the only outputs it can produce on its own.

Source: SANS Security Awareness and Culture Report, 2026, p. 13.

Completion rate is not behavior change

Here is the contradiction at the center of the 2026 data. The benchmark for behavior change is three full time people and three to five years. Meanwhile 84 percent of security leaders name training completion as one of their top program metrics, more than any other measure, while only 16 percent track employee risky behaviors and 10 percent track deepfake recognition and reporting.

Source: Gartner, "6 Ways to Transform Your Cybersecurity Awareness Program" (G00840741, March 2026), 2025 Secure Behavior Strategies Survey (n=65).

Completion is easy to collect and it moves fast, which is exactly why it survives. It also does not correlate with the outcome. The human element appeared in 62 percent of breaches in the 2026 Verizon report, and social engineering was the third most common breach pattern at 16 percent.

Source: Verizon, 2026 Data Breach Investigations Report, 2026, p. 12.

Read the two findings together and the staffing question answers itself. A metric one person can collect in an afternoon will always beat a metric that needs three people and five years, unless somebody decides otherwise. Which metric you report is a staffing decision in disguise.

What to measure instead is a longer conversation and we have already had it, in what a security behavior and culture program measures.

The risks the 2026 benchmark says to plan for

Top human risks selected by practitioners for 2026:

Social engineering across phishing, vishing, smishing and deepfake, 77 percent. Inappropriate AI use at work, 42 percent. Sensitive data mishandling, 39 percent. Weak passwords and poor authentication, 22 percent. Failing to detect or report incidents, 17 percent.

Source: SANS Security Awareness and Culture Report, 2026, p. 11.

One line in the research deserves more attention than it usually gets. Smishing and vishing are rising in both volume and sophistication, and the reason given is twofold: organizations have got better at detecting and stopping email phishing, and fewer organizations have any control over or visibility into employees' mobile devices (p. 10).

That is the blind spot. Detection improved on the channel security teams own, so attackers moved to the channel they do not. Independent simulation data points the same way: the median click rate in email simulations is around 1.4 percent, while phone centric simulations run near 2 percent, a failure rate roughly 40 percent higher.

Source: Verizon, 2026 Data Breach Investigations Report, 2026, p. 50.

We measured the reporting side of the same gap and published the numbers in The Mobile Phishing Visibility Gap. A program that reports on email only is reporting on the channel it has already hardened.

What the strongest programs do differently

Two patterns come out of the open ended responses, and neither one costs headcount.

The first is recognition instead of punishment. One team stopped publishing click rates and policy violations and started publicly recognizing employees who showed strong security behavior. Within about three months, the phishing report rate rose by nearly 40 percent, and employees began contacting the security team before incidents rather than after (p. 35).

The second is peer influence. Where a few respected employees started talking openly about security and sharing their own catches, reporting rates rose by more than 70 percent. The practitioners reporting this said the effect was stronger than incentives or gamification (p. 36).

Both findings line up with what employees say when they are asked directly: 50 percent are motivated by recognition and 20 percent by punitive measures.

Source: Gartner, "Drive Secure Behavior With 4 Employee-Focused Tactics" (G00840742, February 2026), 2025 Secure Behavior: Employee Perspectives Survey (n=175).

If your program still leads with click rate leaderboards, this is the cheapest change on the list.

Closing the gap when you cannot hire

Most teams reading this will not get to three people, let alone 4.3. The benchmark is still useful, because it tells you what one person has to cover, and that is a coverage problem rather than an effort problem.

Three quarters of teams now report using AI in some form, 25 percent have not started, and only 2.4 percent tried it and decided it was overhyped (p. 22). Content creation is the most common use, and it maps onto the number one barrier, which is time.

The practical version looks like this. Automate the work that scales with volume, which is simulation build, translation, reporting triage and the write up that follows an incident. Keep the work that needs judgement, which is choosing which risk to target next and how to talk to the business about it. We covered the arithmetic behind this in how AI increases the efficiency of small awareness teams.

The second lever is channel coverage. If social engineering is the top risk and the growth is on mobile, one person running email only simulations is covering the smallest part of the problem. Running email, voice, SMS, QR and callback from the same platform, against the same target group, turns five separate programs into one. That is what Keepnet's phishing simulator, vishing simulator and smishing simulator are built to do, with Incident Responder handling what happens after someone reports.

A benchmark checklist for 2026

Count your team in full time equivalents, using the 75 percent rule. The number is usually lower than the org chart suggests.

Write down which outcome you are funded for, behavior or culture, and compare your count against three and 4.3.

State your program age. If it is under three years, behavior change is still ahead of you, and saying so protects the program.

Check your reporting line. If you sit outside the security team, book the standing meeting that puts you back in the risk conversation.

Replace completion rate with reporting rate and time to report as your headline metric.

Add at least one non email channel to your simulation calendar this quarter, and report it separately rather than blending it into an overall click rate.

Swap one punitive mechanic for one recognition mechanic. It is the fastest measurable change in this list.

Where to start

If you only take one number from the 2026 benchmarks, take this one: the strongest predictor of a mature program is not budget, tooling or training hours. It is how many people are actually on it, and how long they have been left alone to do the work.

Everything else in this article is about buying coverage back when that number is smaller than the benchmark. See what a full program costs, or book a 30 minute demo and we will map your current coverage against these benchmarks channel by channel.

SHARE ON

twitter
linkedin
facebook

How does your program compare with the 2026 benchmark?

Book a 30 minute Keepnet walkthrough and we will map your current coverage against these benchmarks channel by channel.
tickCount your team in full time equivalents.
tickMeasure reporting rate, not completion.
tickCover the channels attackers actually use.

Frequently Asked Questions

How many people do you need to run a security awareness program?

arrow down

At least three full time people to change employee behavior, and at least 4.3 to change security culture. A full time person here means someone spending 75 percent or more of their time on the program, so part time contributors do not add up the way an org chart suggests. Even an organization of around 1,000 employees needs a baseline of two dedicated people. Source: SANS Security Awareness and Culture Report, 2026, p. 16 and p. 17.

Does the team need to grow with the size of the company?

arrow down

Not proportionally. There is no reliable ratio such as one person per 10,000 employees, because core responsibilities take similar effort at 5,000 employees and at 250,000. Larger organizations do need larger teams, mainly for scale and localization, but not on a linear curve. A more useful rule is one person on the human side for every ten people on the security team.

How long does it take to change security behavior?

arrow down

Three to five years for organization wide behavior change, and five to ten years for culture change. The strongest programs have usually been running for more than ten years. Program age is the second strongest predictor of maturity after team size.

What is the biggest obstacle to an awareness program?

arrow down

Time, named by 30 percent of practitioners, ahead of budget at 26 percent and lack of personnel at 25 percent. Time has been the top barrier for five years running, which is why the work that pays back slowest tends to be the first thing dropped.

Is training completion rate a good metric?

arrow down

It is the most tracked metric and the weakest one. 84 percent of security leaders name completion as a top metric while only 16 percent track risky employee behaviors, and the human element still appeared in 62 percent of breaches in the 2026 Verizon report. Reporting rate and time to report measure behavior instead of attendance, and both change the outcome of a real incident.

Why are smishing and vishing rising faster than email phishing?

arrow down

Two reasons are given in the 2026 research. Organizations have become better at detecting and stopping email phishing, and fewer organizations have control over or visibility into employees' mobile devices. Independent simulation data shows phone centric simulations failing at roughly 40 percent higher rates than email.