SANS 2026 Security Awareness & Culture Report

The SANS Security Awareness & Culture Reportยฎ has tracked the human side of cybersecurity for eleven years. The 2026 edition is the most expansive yet, drawing on responses from over 1,700 security awareness practitioners from around the world to identify and benchmark how organizations are managing their human risk.

Built for practitioners at every stage, the report delivers the benchmarks and actionable guidance needed to mature your program, make the case for investment, and drive real change.

In this download you will find:

๐Ÿ‘‰ Program maturity benchmarks โ€” where programs stand in 2026 by maturity stage, team size, and program age, measured against the updated Security Awareness & Culture Maturity Modelโ„ข
๐Ÿ‘‰ AI risk guidanceโ€” dedicated coverage on GenAI misuse, Vibe Coding, and Agentic AI, grounded in what practitioners are experiencing right now
๐Ÿ‘‰ Resourcing data โ€” how many FTEs it takes to shift behavior and embed a security culture by organization size and maturity stage
๐Ÿ‘‰ Compensation and career development โ€” global average salary, regional and industry breakdowns, and career pathways for practitioners at every stage
๐Ÿ‘‰ 4,500+ open-ended practitioner insights โ€” the most direct community voice in the reportโ€™s history, covering what is working, what is not, and what surprised practitioners
๐Ÿ‘‰ The new SANS Security Awareness and Culture Maturity Assessment โ€” benchmark your program in real time against 1,700+ global peers and identify your next step.

Download the full report: https://www.sans.org/mlp/ssa-security-awareness-report

Gartner Magic Quadrant for Endpoint Protection 2026

Rapid AI adoption and emerging supplier sovereignty requirements are shaping buyer priorities for endpoint protection products. Buyers should factor in sovereignty objectives, as well as requirements for AI discovery and usage control on corporate endpoints, when selecting vendors.

Strategic Planning Assumptions

  • By 2028, 90% of endpoint protection vendors will offer AI discovery and usage control features.
  • By 2029, 30% of midsize organizations will converge endpoint, data security and identity security capabilities into a workspace security platform, enabling holistic protection and centralized policy management.
  • By 2029, organizations that integrate endpoint security tools, management processes and operations teams will reduce incident response times by at least 40%.

Download the full report: Gartner Reprint

The Forrester Waveโ„ข: Cybersecurity Consulting Services, Q1 2026 Report

The Forrester Waveโ„ข: Cybersecurity Consulting Services, Q1 2026 report is just out.

Cybersecurity consulting is in transition as genAI and automation promise faster, tailored insights โ€” yet client expectations outpace current capabilities. Buyers increasingly expect real-time adjustments to risk assessments and policy recommendations, but most providers still operate on structured phases rather than continuous delivery. This gap fuels scrutiny of engagement economics: While firms advertise AI-driven efficiencies, customers rarely see proportional cost reductions. Procurement teams now demand transparent pricing and measurable ROI, challenging providers to reconcile innovation claims with actual savings. CISOs must navigate a mature market where differentiation depends on operationalizing AI without sacrificing governance or trust.

Cybersecurity consulting services customers using this evaluation to inform a purchase decision should consider:

  • AI and automation embedded in workflows
  • Strategy aligned with business outcomes
  • Transparent economics and ROI evidence as requirements

Congrats PwC, EY and McKinsey for being Leaders on this report.

Download the full report: https://reprint.forrester.com/reports/the-forrester-wave-tm-cybersecurity-consulting-services-q1-2026-960c10c6/index.html

SANS 2025 Security Awareness Report

The 2025 SANS Security Awareness Reportยฎ analyzes data provided by over a thousand security awareness professionals from around the world to identify and benchmark how organizations are managing their human risk.

This data-driven report provides actionable steps and resources to enable organizations at any stage of their Awareness program to mature said programs and benchmark them against others.

In this download you will find:

๐Ÿ‘‰ The analysis, insights, and actionable data that make great programs successful
๐Ÿ‘‰ The top challenges awareness programs face in managing human risk
๐Ÿ‘‰ Program maturity benchmarking trends, as measured against the Security Awareness Maturity Modelยฎ
๐Ÿ‘‰ How security awareness professionals can grow and develop their careers including detailed salary information and a Career Development path
๐Ÿ‘‰ Action items to proactively grow your team and your budget to mature your program

โ€ฆand so much more! Download the report now to unlock actionable insights to growing and maturing your security awareness program to excel at Managing Human Risk.

Download the full report: https://www.sans.org/mlp/ssa-security-awareness-report

2025 Gartner Magic Quadrant for Endpoint Protection Platforms

Customer experience and vendor trust are key drivers for provider selection due to the maturity and mainstream adoption of EPPs. Buyers should assess solutions in the context of a broader integrated workspace security strategy as part of their cybersecurity technology optimization efforts.

Strategic Planning Assumptions

By 2029, 30% of midsize organizations will converge workspace, data security and identity security capabilities into a workspace security platform, enabling holistic protection and centralized policy management.

By 2030, 25% of enterprises will adopt a continuous assessment and optimization process to assess and remediate workspace security controls in a targeted fashion to reduce the attack surface.

Market Definition/Description

Gartner defines an endpoint protection platform (EPP) as security software designed to protect managed endpoints โ€” including desktop PCs, laptop PCs, virtual desktops, mobile devices and, in some cases, servers โ€” against known and unknown malicious attacks. EPPs provide capabilities for security teams to investigate and remediate incidents that evade prevention controls. EPP products are delivered as software agents, deployed to endpoints, and connected to centralized security analytics and management consoles.

EPPs provide a defensive security control to protect end-user endpoints against known and unknown malware infections and file-less attacks using a combination of security techniques (such as static and behavioral analysis) and attack surface reduction capabilities (such as device control, host firewall management and application control). EPP prevention and protection capabilities are deployed as a part of a defense-in-depth strategy to help reduce the endpoint attack surface and minimize the risk of compromise. EPP detection and response capabilities are used to uncover, investigate and respond to endpoint threats that evade security protection, often as a part of broader threat detection, investigation and response (TDIR) capable products.

Mandatory Features

โ€“ Protection against malware and file-less attacks using endpoint real-time scanning and anti-malware techniques
โ€“ Endpoint attack surface reduction capabilities, such as device control, host firewall, exploit protection or application control
โ€“ Detection and blocking of endpoint threats using behavioral analysis of endpoint, application and end-user activity

    Common Features

    โ€“ Integrated endpoint detection and response (EDR) functionality enabling real-time telemetry collection, detection customization, postincident investigation and response
    โ€“ Assessment of endpoints for software and OS vulnerabilities and misconfigurations, as well as built-in or integrated patch management and virtual patching capabilities
    โ€“ Capabilities for continuous assessment and optimization of EPP policies and settings against configuration best practices and emerging threats
    โ€“ Workspace security platform integrations with email security, security service edge, identity protection, data security controls and endpoint management tools
    โ€“ Integrations with native and third-party TDIR capable products enabling telemetry collection, correlation, investigation and remediation across multiple security controls
    โ€“ Extended support for end-of-life, uncommon operating systems or legacy server workloads
    โ€“ Partner- and vendor-delivered service wrappers, such as managed detection and response (MDR) and co-managed security monitoring services

    Read the full report: https://www.gartner.com/doc/reprints?id=1-2LFIK3DH&ct=250711&st=sb

    English
    Exit mobile version