• Skip to primary navigation
  • Skip to main content
  • Skip to primary sidebar
  • Skip to footer

My TechDecisions

  • Best of Tech Decisions
  • Topics
    • Video
    • Audio
    • Mobility
    • Unified Communications
    • IT Infrastructure
    • Network Security
    • Physical Security
    • Facility
    • Compliance
  • RFP Resources
  • Resources
  • Podcasts
  • Project of the Week
  • About Us
    SEARCH
Compliance, Network Security, News

How to Improve Your Cybersecurity Awareness Program

SANS Institute 2022 Security Awareness Report suggests that communication, compensation issues are impacting security awareness programs.

July 11, 2022 Zachary Comeau Leave a Comment

Infosec, Cybersecurity Awareness
alfa27/ stock.adobe.com

Despite the rising proliferation of the ransomware-as-a-service industry and sophisticated attack methods being adopted by nation state actors, human error remains the biggest threat to an organization’s cybersecurity. That means security awareness has never been more important, according to the SANS Institute’s 2022 Security Awareness Report.

The Maryland-based cybersecurity training organization’s report found that phishing, ransomware and business email compromise—three threats all associated with some level of social engineering and human error—are the top three security risks cited by cybersecurity professionals.

“People have become the primary attack vector for cyber-attackers around the world,” said Lance Spitzner, SANS security awareness director and co-author of the report, in a statement. “Humans rather than technology represent the greatest risk to organizations and the professionals who oversee security awareness programs are the key to effectively managing that risk.”

The report, the result of analyzing data of more than 1,000 global security awareness professionals, points the blame at those very professionals, as more than 69% of them are spending less than half of their time on security awareness. In addition, just 18% are dedicated to supporting awareness programs full time. The SANS Institute defines a full-time security awareness professional as someone that spends at least 70% of their time on security awareness.

Instead, those security awareness responsibilities are being assigned to technical staff who may already be part of the IT team who lack the necessary soft skills to effectively communicate the importance of cybersecurity in laymen terms.

Another issue impacting security awareness is the disparity in compensation between full-time security awareness professionals and IT staff who are taking on additional awareness responsibilities. According to the study, the average U.S. salary for a full-time security awareness employee was $86,626, while those who are tasked with awareness responsibilities in addition to their technical job averaged $117,584.

According to SANS Institute, the problem here is perceived value.

“Too often, security awareness professionals are perceived as being in the ‘entertainment business’ because they talk exclusively about engaging and training the workforce,” the organization says in the report.  “But this overlooks the fact that security awareness professionals are not just in the business of changing human behavior; ultimately they are key to managing human risk.”

What the SANS Institute says technical and non-technical staff should do

For technical professionals tasked with their organization’s security awareness program, the SANS Institute suggests partnering with others in the organization to help craft and distribute their message.

Cybersecurity can be complex and confusing to non-IT staff, so awareness professionals should ask communication professionals in their marketing or public relations department to help or acquire the appropriate skills themselves to engage with the workforce more effectively.

To address the disparity in compensation, SANS Institute suggests demonstrating how awareness and training can change key behaviors that lead to human error, such as clicking links or opening attachments from suspicious emails.

In addition, security awareness pros should work with the IT and security teams to expand their role to help manage rollouts of security tools and policies, as well as partner with senior leadership to help spread buy in.

While security awareness professionals should have better soft skills than IT professionals, they still need a working knowledge of cybersecurity fundamentals, according to the report.

If you enjoyed this article and want to receive more valuable industry content like this, click here to sign up for our digital newsletters!

Tagged With: Cybersecurity, Training

Related Content:

  • Cloud, SASE, Aryaka How the Cloud is Redefining Media Production and…
  • Singlewire Software mass notification interview Singlewire Software on Mass Notification Solutions
  • URI catchbox 1 Catchbox Plus: The Mic Solution That Finally Gave…
  • Engaging virtual meeting with diverse participants discussing creative ideas in a bright office space during daylight hours Diversified Survey: Workplace AV Tech is Falling Short,…

Free downloadable guide you may like:

  • Download TechDecisions' Blueprint Series report on Security Awareness now!Blueprint Series: Why Your Security Awareness Program is Probably Falling Short

    Learn about the evolution of phishing attacks and best practices for security awareness programs to ensure your organization is properly prepared to defend against them in this report from TechDecisions' Blueprint Series.

Reader Interactions

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Latest Downloads

Practical Design Guide for Office Spaces
Practical Design Guide for Office Spaces

Recent Gartner research shows that workers prefer to return to the office for in-person meetings for relevant milestones, as well as for face-to-fa...

New Camera Can Transform Your Live Production Workflow
New Camera System Can Transform Your Live Production Workflow

Sony's HXC-FZ90 studio camera system combines flexibility and exceptional image quality with entry-level pricing.

Creating Great User Experience and Ultimate Flexibility with Clickshare

Working and collaborating in any office environment today should be meaningful, as workers today go to office for very specific reasons. When desig...

View All Downloads

Would you like your latest project featured on TechDecisions as Project of the Week?

Apply Today!

More from Our Sister Publications

Get the latest news about AV integrators and Security installers from our sister publications:

Commercial IntegratorSecurity Sales

AV-iQ

Footer

TechDecisions

  • Home
  • Welcome to TechDecisions
  • Contact Us
  • Comment Guidelines
  • RSS Feeds
  • Twitter
  • Facebook
  • Linkedin

Free Technology Guides

FREE Downloadable resources from TechDecisions provide timely insight into the issues that IT, A/V, and Security end-users, managers, and decision makers are facing in commercial, corporate, education, institutional, and other vertical markets

View all Guides
TD Project of the Week

Get your latest project featured on TechDecisions Project of the Week. Submit your work once and it will be eligible for all upcoming weeks.

Enter Today!
Emerald Logo
ABOUTCAREERSAUTHORIZED SERVICE PROVIDERSYour Privacy ChoicesTERMS OF USEPRIVACY POLICY

© 2025 Emerald X, LLC. All rights reserved.