logo
SANS report finds humans still the main attack vector as 80% of organizations flag social engineering as their number one risk

SANS report finds humans still the main attack vector as 80% of organizations flag social engineering as their number one risk

Al Bawaba2 days ago
The latest survey data from SANS Institute, the world's most trusted provider of cybersecurity training, reveals that 80% of organizations rank social engineering as the number one human-related risk—an already formidable threat now supercharged by AI. As attackers use artificial intelligence to craft more convincing and scalable deception tactics, the stakes for human error have never been higher. The data was a key insight from the 10th anniversary edition of SANS Institute's Security Awareness Report®: Embedding a Strong Security Culture. The report is based on SANS's largest survey ever, with feedback from over 2,700 security awareness practitioners from more than 70 countries who shared their unique perspectives to create the most comprehensive and revealing report yet. Lance Spitzner, Technical Director of SANS Workforce Security & Risk Training, highlights the report's significance on its 10th anniversary: "The launch of the 10th edition of our Security Awareness Report is a major milestone for us and our most ambitious and far-reaching report to date. Designed as a dual-purpose playbook, it empowers security awareness professionals to not only drive organization-wide behavior and culture change but also advance their careers."Key Findings and Insights• Top human risks: This year's data makes it clear: social engineering remains the top human risk by a wide margin (according to 80% of respondents), with phishing still leading, and smishing and vishing attacks growing in both frequency and sophistication. In a shift from last year's results, incorrect handling of sensitive data has now taken the second spot, followed by weak passwords and poor authentication. These changes reflect the evolving ways in which humans remain the primary attack vector, and why targeted, behavior-focused training continues to be essential.• Program challenges: Lack of time and staffing remain the two biggest challenges limiting industry professionals from building and managing an effective program. The report emphasises the use of tools like Generative AI to help security teams accelerate their impact at a global scale.• Benchmarking and maturity: For the sixth year in a row, the data confirms that larger security awareness teams drive more mature programs. On average, it takes at least 2.8 dedicated FTEs to meaningfully influence behavior—and four or more FTEs to begin shifting organizational culture. But staffing isn't everything. Sustained effort over time matters just as much. The longer your program has been in place, the more likely it is to be improving processes, strengthening partnerships and effectively engaging the workforce to reduce human risk. • Career development: In 2025, the average global annual salary for individuals working in security awareness is $116,091. In terms of geography, North America has the highest average annual salary at $129,961, almost identical to 2024's findings. In Europe, the average annual salary is $93,661. Spitzner concludes: 'This year's findings come against the backdrop of organisations facing rising threats like generative AI, deepfakes and other emerging threats. The report delivers timely, data-driven insights into how security teams are adapting, where gaps remain and which strategies are moving the needle. In a field where human risk is still under-reported, this report shines a spotlight on one of cybersecurity's most urgent challenges.'
To read the full report and benchmark your program against industry standards, download the report here.
Orange background

Try Our AI Features

Explore what Daily8 AI can do for you:

Comments

No comments yet...

Related Articles

ChatGPT experiences widespread outage
ChatGPT experiences widespread outage

Roya News

time42 minutes ago

  • Roya News

ChatGPT experiences widespread outage

ChatGPT is currently experiencing a significant outage, with thousands of users reporting issues starting Wednesday evening. The problems began around 7:19 PM Jordan time (GMT+3) on August 20, 2025. Downdetector, a popular outage-tracking website, saw a sharp spike in reports, with over 1,941 users flagging issues with the service within minutes. Users across social media platforms quickly began reporting error messages and an inability to generate responses from the chatbot. OpenAI has officially acknowledged the problem on its status page. A message posted by the company confirms the ongoing disruption, "We're currently experiencing issues." Under the ChatGPT section, the status is listed as "Degraded Performance," with a specific note clarifying the problem as "ChatGPT Conversation Errors." This indicates that while the main site might be accessible for some, the core function of engaging in a conversation with the AI is failing.

Arabic.AI launches AI academy to empower Arab talent
Arabic.AI launches AI academy to empower Arab talent

Wamda

time6 hours ago

  • Wamda

Arabic.AI launches AI academy to empower Arab talent

Press release: the region's pioneer in secure Arabic-first artificial intelligence solutions, today announced the launch of AI Academy, the first dedicated hub for Arabic-language AI education and enterprise upskilling in the Middle East. Building on more than 16 years of expertise in Arabic language technologies and enterprise AI, AI Academy is designed to close the region's skills gap by equipping governments, enterprises, and professionals with the knowledge, tools, and certifications required to lead in the era of artificial intelligence, both regionally and globally. Launching this year with flagship programmes across 2025, AI Academy will deliver a curated calendar of industry-focused workshops, hands-on training, and tailored AI programmes. These initiatives will serve the unique needs of Arab world talents and key sectors such as public services, finance, healthcare, and telecommunications. 'AI Academy is about more than just training; it's about building the Arab world's future workforce. By providing sovereign, secure, and culturally rooted AI education, we are empowering our region not only to adopt AI, but to lead in Arabic-first innovation on the global stage,' said Nour Al Hassan, Founder & CEO of Accessible both online and on-site, the Academy will collaborate with leading academic and industry partners to deliver certifications and programmes covering: AI literacy and leadership for decision-makers and teams. Technical enablement for developers and data professionals. Applied enterprise use cases tailored to regional challenges and opportunities. is the Arab world's leading secure and private artificial intelligence company, specialising in Arabic Large Language Models, AI Agents, and enterprise solutions for governments and organisations across the MENA region.

Google Gemini can now read your Docs aloud
Google Gemini can now read your Docs aloud

Ammon

time8 hours ago

  • Ammon

Google Gemini can now read your Docs aloud

Ammon News - Google Docs will now let you generate an audio version of your documents using AI. In a post announcing the rollout, Google says you can customize Gemini's AI audio output with different voices and playback speeds. This feature isn't just for a document's creator, as Google says readers can access a shared document's AI-generated audio by selecting the Tool dropdown menu and selecting Audio > Listen to this tab. Authors can also add a customizable audio button directly in a document by choosing Insert > Audio, which readers can click to start listening. Google announced plans to let you turn your documents into AI podcasts in April, but this feature seems a lot handier if you just want to listen to what you've written. You can only generate audio versions of documents in English and on desktop devices for now. Google is rolling out audio in Docs to Workspace users with business, enterprise, or education plans, as well as users who have AI Pro and Ultra subscriptions. The Verge

DOWNLOAD THE APP

Get Started Now: Download the App

Ready to dive into a world of global content with local flavor? Download Daily8 app today from your preferred app store and start exploring.
app-storeplay-store