• About Us
  • Advertising
  • Digital Magazine
  • Supplements
  • Media Pack
  • Privacy Policy
  • Contact us
CXO Insight Middle East
  • News
  • Opinion
  • Business
    • Industries
      • Transport
      • Retail
      • Government
      • Real Estate
      • Education
      • Energy
      • Banking and Finance
    • Channel
  • Future
    • Tech
    • Gadgets
    • Science
    • Space
    • Sustainability
  • Events
    • Channel Awards
      • 2025
      • 2024
      • 2023
    • Channel Insights Summit 2025
    • Insight Innovation Summit
    • CXO50 Oman
    • CXO50
    • ICT Awards
      • Dubai 2025
      • Saudi Arabia
    • Cyber Strategists Summit
    • Cloud Connect 2025
    • All events
  • Digital Magazine
  • GITEX GLOBAL
No Result
View All Result
CXO Insight Middle East
  • News
  • Opinion
  • Business
    • Industries
      • Transport
      • Retail
      • Government
      • Real Estate
      • Education
      • Energy
      • Banking and Finance
    • Channel
  • Future
    • Tech
    • Gadgets
    • Science
    • Space
    • Sustainability
  • Events
    • Channel Awards
      • 2025
      • 2024
      • 2023
    • Channel Insights Summit 2025
    • Insight Innovation Summit
    • CXO50 Oman
    • CXO50
    • ICT Awards
      • Dubai 2025
      • Saudi Arabia
    • Cyber Strategists Summit
    • Cloud Connect 2025
    • All events
  • Digital Magazine
  • GITEX GLOBAL
No Result
View All Result
CXO Insight Middle East
No Result
View All Result

Managing Human Risk: Discoveries from SANS 2023 Security Awareness Report

by CXO Staff
July 27, 2023
in News

Providing Critical Data-Driven Insights and Actionable Steps for Security Professionals

Managing Human Risk: Discoveries from SANS 2023 Security Awareness Report

As artificial intelligence (AI) amplifies the sophistication and reach of phishing, vishing, and smishing attacks, understanding and managing human cyber risks has become increasingly vital. Addressing this, SANS Institute is proud to announce the release of the SANS 2023 Security Awareness Report, ‘Managing Human Risk.’ Rooted in the experiences of nearly 2,000 participants from 80 countries, the report underscores the escalating stakes in human cyber risks, particularly at a time when 20% of organisations worldwide reported security incidents involving remote workers in the past year.

“The digital world is expanding rapidly, and with it, the human element of cybersecurity becomes ever more important as it evolves as a primary target for cyber threats globally,” says Lance Spitzner, SANS Security Awareness Director and co-author of the report. “The report serves as a compass, guiding organisations not just to understand but proactively manage human cyber risks. By unifying data from thousands of participants globally, we’ve uncovered patterns and practical approaches that can empower organisations to transform their human risk landscapes.”

The report provides an in-depth analysis and actionable steps for security professionals to mature their awareness programmes, advance their careers, and benchmark their programmes globally using the Security Awareness Maturity Model. Notably, the study found that mature security programmes, marked by robust teams and leadership support, are characterised by having at least three full-time employees in their Security Awareness Teams.

Key Findings:

Top Human Risks: The primary threats include Phishing/Vishing/Smishing attacks; Password/Authentication risks mitigated by advanced tools; the challenge of fostering a security culture for effective Detection/Reporting; and the risk of IT Admin Misconfigurations, especially in complex cloud environments.

Leadership Perspective: As in previous years, security awareness remains predominantly considered a part-time commitment within organisations. A noteworthy 70% of security awareness practitioners disclosed that they dedicate half or less of their working time to it this year. This insight underscores the ongoing challenge of elevating the importance of continuous cybersecurity awareness in the day-to-day operations of organisations.

Compensation: For the first time, our data reveals that professionals specialising in human risk management earn up to 5% more than their peers in broader security roles. This underlines the increasing demand and value for these skill sets in the industry.

Key Action Items to Increase Programme Success:

Talk in Terms of Risk:  Leadership and Security Teams often perceive security awareness as not part of security, but rather as a compliance effort that has little relevance to managing risk. To help change such perceptions, focus on and speak in terms of human risk management. Human risk is far more likely to align with most organisations’ strategic security priorities, gain leadership buy-in, and resonate with a Security Team. Help your Security Team members understand how you help them, and work with them to identify the top human risks and the key behaviors that manage those risks. Demonstrate how effective communications, training, and engagement is changing those key behaviors and reducing human risk. Partner with Security Operations Centre, Incident Response and Cyber Threat Intelligence Teams not only to learn their work but also to show them how you can help solve their human-risk-related challenges.

Leadership Support: Dedicate two to four hours a month to collecting metrics about the impact and value of your Security Awareness Programme and communicating that value to leadership. This information can include informal metrics, established key performance indicators, and even success stories to enable leadership to better understand and regularly see the value that your programme is providing.

Team Size: While technical security has been a focal point for organisations, the human side of security has often been overlooked. This imbalance leaves the workforce as an appealing target for cyberattacks. It’s not uncommon to find a 50-member security team with 49 focusing on technology, leaving just one person to manage human risk. This underinvestment in human-focused security contributes to the prominence of human cyber risks. We recommend a starting point of a 10-to-1 ratio of technical to human-focused security professionals, to begin bridging this gap.

“The traditional model of yearly compliance-focused training is inadequate in today’s cyber threat landscape, so we’ve included practical, actionable advice throughout the report,” Spitzner said. “From addressing the top human risks, which according to our data, involve email phishing, to tackling the common challenge of securing adequate resources and budget, we aim to equip organisations with the necessary tools to improve their human risk management strategies and help ensure that organisations proactively invest in the personnel, resources, and tools to robustly address the human dimension of cybersecurity risks.”

To read the full report and benchmark your programme against industry standards, download the SANS 2023 Security Awareness Report “Managing Human Risk” here.

Tags: Lance SpitznerManaging Human RiskSANS 2023 Security Awareness ReportSANS Institute
ShareTweet

Related Posts

Redington and Intel to accelerate AWS innovation and growth for META
Business

Redington and Intel to accelerate AWS innovation and growth for META

December 8, 2025

Redington announced a landmark Memorandum of Understanding (MoU) with Intel, marking the beginning of a strategic five-year collaboration aimed at...

Confluent launches Confluent Private Cloud in Middle East
Future

Confluent launches Confluent Private Cloud in Middle East

December 8, 2025

Confluent announced the launch of Confluent Private Cloud, the simplest way to deploy, manage, and govern streaming data on private...

Discussion about this post

Latest Issue

Redington and Intel to accelerate AWS innovation and growth for META

Redington and Intel to accelerate AWS innovation and growth for META

December 8, 2025
Confluent launches Confluent Private Cloud in Middle East

Confluent launches Confluent Private Cloud in Middle East

December 8, 2025
Qualys selects Security Matterz as first mROC partner for the Kingdom of Saudi Arabia

Qualys selects Security Matterz as first mROC partner for the Kingdom of Saudi Arabia

December 8, 2025

The most trusted source of strategic intelligence for IT decision makers in the Middle East.

About

  • About Us
  • Advertising
  • Digital Magazine
  • Supplements
  • Media Pack
  • Contact Us

Policies

  • Privacy Policy
© 2025 – CXO Insight Middle East. All Rights Reserved.
Facebook-f X-twitter Linkedin
Separated they live in Bookmarksgrove right at the coast of the Semantics, a large language ocean. A small river named Duden.

About

  • About Us
  • Site Map
  • Contact Us
  • Career

Policies

  • Help Center
  • Privacy Policy
  • Cookie Setting
  • Term Of Use

Join Our Newsletter

© 2024 – CXO Insight Middle East. All Rights Reserved.

Facebook-f Twitter Youtube Instagram

Welcome Back!

Login to your account below

Forgotten Password?

Retrieve your password

Please enter your username or email address to reset your password.

Log In
Join our mailing list
Sign up here to get the latest news, updates and special offers delivered directly to your inbox.
No Result
View All Result
  • News
  • Opinions
  • Business
    • Industries
      • Transport
      • Retail
      • Government
      • Real Estate
      • Education
      • Energy
      • Banking and Finance
  • Channel
  • Future
    • Tech
    • Gadgets
    • Science
    • Space
    • Sustainability
  • Events
    • Channel Awards
      • 2025
      • 2024
      • 2023
    • Channel Insights Summit 2025
    • Insight Innovation Summit
    • CX50 Oman
    • CXO50
    • ICT Awards
      • Dubai
      • Saudi Arabia
    • Cyber Strategists Summit
    • Cloud Connect 2025
    • All events
  • Videos
  • GITEX GLOBAL
  • Digital Magazine

© 2025 - CXO Insight Middle East. All Rights Reserved.