Skip to content

Blog

Research, guides and category thinking on Behavioral Defense.

awarenessSecurity Awareness Salary: Are Awareness Professionals Underpaid?

In Europe, a security awareness professional earns €92K (about $107K) on average, in North America $131K, according to the 2026 SANS Security Awareness & Culture Report. Set against everything the same report expects of the role, that is less a pay question than a priority question.

awarenessWe Finally Have a Flawless Security Culture Action Plan

The SANS 2026 security culture action plan is barely about content. A CEO and board member on why that means rewriting your awareness strategy and bringing the SOC closer to employees.

bdeThe 5 Biggest Human Risks in Cybersecurity - and Why #5 Is Ignored

In the 2026 SANS Security Awareness & Culture Report, more than 1,700 practitioners named the risks they are focusing on, and social engineering came out on top at 77%. The fifth risk on the list gets no section of its own, and that is exactly the one I want to talk about.

research8 Hard Truths About Security Awareness Team Size (SANS 2026)

I read the new SANS Security Awareness & Culture Report from a slightly unusual perspective: I manufacture security awareness software. What stayed with me was security awareness team size, not tooling — here are my eight takeaways, including a conclusion I fundamentally disagree with.

bdeWhy the Employee Has to Become Part of the Security Stack

AI is pushing cyber defense to machine speed, but the answer is not to remove people from the equation. It is to treat the human layer — the judgment, decisions and reports of employees — as part of the security stack.

research$4.99 Million: What a Data Breach Costs in 2026

IBM’s Cost of a Data Breach Report 2026 puts the global average cost of a breach at a record USD 4.99 million. Two other figures in the same report tell you more: 63% and 247.

aiHow Do You Recapture an AI That Has Run Amok?

In July and August 2026, three AI labs and one government evaluator reported that autonomous agents attacked real systems outside their test scope during security evaluations. Where does an AI actually “escape” to — and how do you contain an agent once the sandbox has failed?

awarenessCybersecurity Awareness Was Designed for Yesterday’s Attacks

AI lets attackers produce convincing attacks at almost no cost, and people are now the largest and fastest-growing attack category. This essay explains why annual training can't keep pace, and why behaviour changes most when people repeatedly make decisions under realistic conditions.