Security Awareness Training Statistics for 2026: Phishing, Human Risk, and What Training Actually Changes
The human element was present in 62% of breaches analyzed in the Verizon 2026 Data Breach Investigations Report, up from 60% the year before.
Table of Contents
The human element was present in 62% of breaches analyzed in the Verizon 2026 Data Breach Investigations Report, up from 60% the year before. That single number is why security awareness training remains the most widely deployed control in the industry, and why journalists keep asking whether it works. The 2026 evidence says it does, with caveats. According to the KnowBe4 2026 Phishing by Industry Benchmarking Report, 33.2% of untrained employees will fail a simulated phishing test; after 12 months of training and simulation, that figure drops to 4.2%. Meanwhile, the global average cost of a data breach reached a record $4.99 million in IBM's 2026 Cost of a Data Breach Report, which is what those clicks now cost when they land.
This page collects the freshest security awareness training statistics available as of September 2026, sourced from the 2026 editions of the major industry reports wherever they exist.
Key security awareness training statistics at a glance
62% of breaches involved the human element in the 2026 Verizon DBIR, up two points from the 2025 edition (Verizon, 2026).
33.2% of untrained employees fail a phishing simulation, the global baseline Phish-prone Percentage across 64,000 organizations (KnowBe4, 2026).
4.2% is the failure rate after one year of consistent training and simulated phishing, down from 33.2% at baseline and 20.1% at 90 days (KnowBe4, 2026).
$4.99 million is the global average cost of a data breach, a 12% year-over-year jump and a record high; the US average is $11.5 million (IBM, 2026).
Phishing led all initial attack vectors for the fourth consecutive year, and voice and SMS phishing carried the highest average breach cost of any vector (IBM, 2026).
Mobile phishing click rates run 40% higher than email in simulations covering voice and text-message lures (Verizon, 2026).
AI indicators appeared in 56% of phishing attacks in December 2025, up from 4% the month before, a 14-fold jump in 30 days (Hoxhunt, 2026).
Employee reporting of real threats rises from 13% to 64% after 12 months of behavior-based training, and to 71% at 24 months (Hoxhunt, 2026).
67% of organizations report moderate or significant reductions in intrusions, incidents, and breaches after adopting awareness training (Fortinet, 2025 report published March 2026).
Roughly 70% of IT and security leaders still say employees lack sufficient security awareness (Fortinet, 2025 report published March 2026).
AI is now the second most-cited human risk by 1,700+ security awareness practitioners, up from fourth place two years earlier (SANS, 2026).
42% of US small and mid-sized businesses rank employee training and awareness as a top security investment for the coming year (ESET, 2026).
The human element in 2026 breaches
Every conversation about security awareness training starts with the same question: how much of the breach problem is people? The 2026 Verizon DBIR, built on more than 22,000 confirmed breaches and 31,000 incidents, puts the human element at 62% of breaches. That covers social engineering, credential misuse, errors, and policy violations, which is why the figure is broader than phishing alone.
Within that, the DBIR reports social engineering as the pattern behind 16% of all breaches. Phishing itself held steady at 16% of breaches, while pretexting, the synchronous "talk the victim into it" variant, reached 6% and is increasingly the on-ramp to ransomware and extortion. Credential abuse appeared somewhere in the attack chain in 39% of breaches, even though it fell to 13% as the initial access vector. Stolen passwords still move attacks forward once someone is inside.
The financial side is stark. IBM's 2026 report puts the global average breach at $4.99 million, up 12% in a single year, with US organizations averaging $11.5 million per incident, up 11%. Healthcare remained the costliest sector for the thirteenth straight year at $6.64 million. The mean time to identify and contain a breach rose to 247 days, reversing a five-year improvement trend; breaches that ran past 200 days cost roughly one-third more than faster ones.
Two IBM findings are especially relevant to training programs. Phishing led all initial entry points for the fourth consecutive year, and voice and SMS phishing (vishing and smishing) carried the highest average cost of any vector. The DBIR corroborates the mobile problem from the other direction: in phishing simulations, the median click rate on mobile-centric lures such as voice and text is 40% higher than on email. Training that only covers the inbox is missing the channel where people are most likely to fail.
How much security awareness training reduces phishing risk
This is the datapoint journalists cite most often, and it is worth getting the 2026 figures exactly right.
KnowBe4's 2026 benchmarking report analyzed 42 million phishing simulations across 14.8 million users at 64,000 organizations. The global baseline Phish-prone Percentage, meaning the share of users who click a link, open an attachment, or enter credentials with no prior training, is 33.2%. After 90 days of training plus simulated phishing, that falls to 20.1%. After 12 months, it falls to 4.2%. In North America specifically, the baseline is 34.5% and the one-year figure is 4.0%.
The baseline varies sharply by organization size and industry. Large enterprises (10,000+ employees) start at 39.5% phish-prone, while small businesses start at 24.7%. Healthcare and pharmaceuticals post the worst baseline of any industry at 42.7%, followed by insurance at 38.1% and retail and wholesale at 36.0%. Large healthcare organizations start at 54%. For readers evaluating managed IT services for healthcare, that baseline is the number to benchmark against.
Hoxhunt's data tells the same story using a different methodology. The Hoxhunt 2026 Phishing Trends Report, drawn from 50 million simulations and real attacks across 4 million users in 125 countries, measures a 20% failure rate at baseline that drops to 3% after 12 months of behavior-based training. Failure rates on malicious attachments fall from 11% to below 2% over the same period.
The more interesting Hoxhunt metric is reporting, not clicking. At the start of a program, only 13% of users report a real threat they receive. That share reaches 26% after one month, 50% at six months, 64% at 12 months, and 71% at 24 months. On simulations, the "success" rate (users who correctly report the lure) climbs from 7% to 67% over a year. Hoxhunt puts the reporting rate of a typical quarterly, compliance-style program at around 10%, against a Verizon industry benchmark of about 20%. The fastest 5% of trained reporters flag a phish within 39 seconds, which is the difference between an incident and a non-event.
Does the organization see fewer incidents?
Click rates are a proxy. The question executives ask is whether incidents actually go down.
The Fortinet 2025 Security Awareness and Training Global Research Report, published in March 2026 and based on 1,850 senior IT and security leaders, found that 67% of organizations report moderate or significant reductions in intrusions, incidents, and breaches after adopting awareness training. That is the closest thing to an outcome measure in the current literature, and it comes from the buyers rather than the vendors.
The same report is candid about the gap that remains. Nearly seven in ten leaders say their employees still lack sufficient security awareness. Only about 40% believe their workforce is prepared to identify, avoid, and report AI-based threats. More than 40% cite external threats, past breaches, and incidents in their industry as the primary reason they invested in training, and more than a quarter cite insider risk. Training, in other words, is still mostly bought after something goes wrong.
IBM's report adds a cost-side incentive. Organizations that made extensive use of AI and automation in security saved an average of $1.93 million per breach compared to those using none. Awareness programs are not automation, but they feed the same detection loop: a workforce that reports in seconds shortens the 247-day identification and containment window that drives breach cost.
Security awareness training programs by the numbers
What does a functioning program look like in 2026? The SANS 2026 Security Awareness and Culture Report, the eleventh annual edition and the largest to date with more than 1,700 practitioners surveyed, offers the clearest staffing benchmarks available.
According to SANS, a program that reliably changes employee behavior needs roughly three dedicated staff and three to five years to show results. Embedding security into organizational culture takes a larger team, just over 4.3 full-time equivalents, and five to ten years. Most programs are nowhere near that. The report also finds that 75% of awareness teams are already using AI to build and run their own programs, with only 2.4% having tried AI and abandoned it. Practitioner pay reflects the field's maturation: the global average salary is $123,624, and $131,783 in North America.
Among small and mid-sized businesses, training is now a budget line rather than an afterthought. The ESET SMB Cyber Readiness Index 2026, which surveyed 500 US SMBs as part of a 4,400-respondent global study, found that employee training and awareness tops the investment list at 42%. Some 64% of SMBs are concerned about a cyberattack in the next 12 months, 49% expect a higher security budget next year, and 69% enforce policies restricting unapproved or shadow AI use. Many of these organizations deliver training through an outsourced provider; the managed IT security services market increasingly bundles awareness training and phishing simulation with endpoint and email protection.
Emerging trends and what's new in 2026
The 2026 data introduces several angles that older statistics roundups do not cover.
AI-generated phishing went from fringe to mainstream in a single month. Hoxhunt's telemetry shows the share of phishing attacks with AI indicators jumping from 4% in November 2025 to 56% in December 2025, then settling at 40% in January 2026. KnowBe4 separately reports a 17.1% spike in phishing volume since late 2025, attributed to AI-enabled campaigns. Training content built around misspellings and awkward grammar is now obsolete.
Attackers are diversifying the lure. Hoxhunt tracked a 500% increase in callback phishing campaigns in Q4 2025, and 43% of business email compromise attempts now contain a callback lure. SVG file attachments increased fifty-fold year over year, and SVG calendar invites produce failure rates four to six times the baseline. The DBIR's finding that mobile lures convert 40% better than email fits the same pattern: the attack surface has moved to phone calls, texts, and file types most training never mentions.
AI is now the second-biggest human risk. SANS practitioners ranked AI the number two human risk in 2026, behind only social engineering and up from fourth place two years earlier. The three specific concerns are unauthorized generative AI use, non-programmers shipping AI-generated code, and unreviewed AI agents acting autonomously. IBM quantifies the downstream cost: 43% of organizations experienced a security incident involving unapproved "shadow AI" tools, more than double the prior year's share, and those breaches cost $5.39 million on average versus $4.63 million for organizations without shadow AI exposure. Close to seven in ten organizations still lack an AI governance policy.
AI-driven attacks carry a price premium. More than one in four organizations in IBM's 2026 study faced an AI-driven attack, a 56% increase over the prior year, and those incidents added roughly $1 million in cost. Deepfake impersonation accounted for 45% of AI attacks. Fortinet found that nearly nine in ten organizations say attackers' use of AI has actually raised employee awareness, which is one of the few silver linings in the 2026 data.
Ransomware is still the endgame. The DBIR reports ransomware present in 48% of breaches, up from 44%, with 69% of victims declining to pay and a median payment of $139,875. Third-party involvement in breaches rose 60% to reach 48% of cases, which means awareness programs increasingly need to extend to vendors and contractors, not just employees.
How managed IT services can help
For most organizations, especially those under 1,000 employees, the practical route to a program that hits the SANS staffing benchmarks is a managed service provider that already runs phishing simulations, delivers training, and monitors reporting rates across many clients. manageditservices.ai connects businesses with vetted MSSPs and cybersecurity consultants across the United States. Find a provider near you to compare options for security awareness training, phishing simulation, and managed detection.
Related Articles
- Third-Party Data Breach Statistics for 2026Third-party data breaches now account for nearly half of all confirmed breaches worldwide. According to the 2026 Verizon Data Breach Investigations Report, 48% of breaches involved a third-party…
- Small Business Ransomware Statistics for 2026Ransomware has become the defining cyber threat for small businesses. According to the Verizon 2026 Data Breach Investigations Report, ransomware now appears in 48% of all breaches analyzed, up from…
- Small Business Cybersecurity Statistics for 2026Small businesses face an unprecedented wave of cyber threats in 2026. According to the Hiscox Cyber Readiness Report 2026, 56% of U.S.
- Shadow IT Statistics for 2026: What the Latest Data RevealsShadow IT, the use of technology, software, and cloud services without IT department approval, continues to grow as one of the most persistent security and compliance challenges facing…
Hadley McIntosh
Updated Sep 24, 2026 · 10 min read