
The SANS 2026 security culture action plan is barely about content. A CEO and board member on why that means rewriting your awareness strategy and bringing the SOC closer to employees.

The SANS 2026 security culture action plan is barely about content. A CEO and board member on why that means rewriting your awareness strategy and bringing the SOC closer to employees.

The 2026 SANS Security Awareness & Culture Report names five barriers to program success. The fifth, weak relationships at 18%, comes last and quietly drives the other four.

In the 2026 SANS Security Awareness & Culture Report, more than 1,700 practitioners named the risks they are focusing on, and social engineering came out on top at 77%. The fifth risk on the list gets no section of its own, and that is exactly the one I want to talk about.

AI is pushing cyber defense to machine speed, but the answer is not to remove people from the equation. It is to treat the human layer — the judgment, decisions and reports of employees — as part of the security stack.

A look at what the leadership styles from Good to Great and Multipliers mean for a company’s cybersecurity – from incidents hidden out of fear to teams that act independently during a cyberattack.

Swiss IT publication itbusiness.ch has featured Cyberdise, and the headline says it all: cyber defense begins with behavior. Its June 2026 article argues that security awareness training alone no longer protects organizations.

Cyberdise is moving from traditional security awareness to Behavioral Defense Engineering (BDE). Employees already know phishing is dangerous, yet under the pressure of daily business they still click: the issue is not a lack of knowledge, it is a behavioral gap.

Nearly half of all successful cyberattacks start with a negligent employee. Search engines will tell you it comes down to phishing, weak passwords and careless data handling. Look closer and all three say the same thing: this is about people.

Behavior-oriented awareness measures success by observable change in risk behavior, not by knowledge completion, positive feedback scores or course consumption. It treats employees as human decision systems – not as information storage units.

Cyberdise V3.0 and higher offers two new features, the Email Threat Agent and Automated Incident Feedback. These two features turn every reported email into a measurable security measure, not just a forwarded message.

In 2025, CYBERDISE won 10 new partners and 400,000 new users under license, yet missed its targets by a significant margin. Only conversations with colleagues showed that what the team achieved in 2025 was extraordinary.

Attitude and behavior are related, but they are not the same. Confusing them is one of the main reasons why many awareness programs fail to deliver lasting risk reduction.