Key Takeaways
- 95% of GDPR fines link to insider errors
- 82% of orgs mandate annual SAT for compliance
- HIPAA requires SAT, 70% non-compliance rate without
- SAT ROI averages $6 per $1 spent on compliance
- Average SAT program cost $50-100 per employee/year
- Breaches cost $4.45M avg, SAT saves $2M+
- 83% of organizations experienced a successful phishing attack in 2023
- Security awareness training reduced phishing click rates by 40% on average
- 74% of employees who completed training were less likely to fall for phishing
- 70% of insider threats start with phishing
- 34% of breaches due to insider negligence
- Untrained insiders cause 60% of incidents
- 91% of phishing emails target untrained users
- Click rates on phishing sims average 15% pre-training
- 36 million phishing attacks daily worldwide
Security awareness training sharply reduces human error and phishing, improving compliance and cutting breach costs.
Compliance and Adoption
Compliance and Adoption Interpretation
Cost Benefit Analysis
Cost Benefit Analysis Interpretation
Effectiveness Metrics
Effectiveness Metrics Interpretation
Insider Threats
Insider Threats Interpretation
How We Rate Confidence
Every statistic is queried across four AI models (ChatGPT, Claude, Gemini, Perplexity). The confidence rating reflects how many models return a consistent figure for that data point. Label assignment per row uses a deterministic weighted mix targeting approximately 70% Verified, 15% Directional, and 15% Single source.
Only one AI model returns this statistic from its training data. The figure comes from a single primary source and has not been corroborated by independent systems. Use with caution; cross-reference before citing.
AI consensus: 1 of 4 models agree
Multiple AI models cite this figure or figures in the same direction, but with minor variance. The trend and magnitude are reliable; the precise decimal may differ by source. Suitable for directional analysis.
AI consensus: 2–3 of 4 models broadly agree
All AI models independently return the same statistic, unprompted. This level of cross-model agreement indicates the figure is robustly established in published literature and suitable for citation.
AI consensus: 4 of 4 models fully agree
Cite This Report
This report is designed to be cited. We maintain stable URLs and versioned verification dates. Copy the format appropriate for your publication below.
Priyanka Sharma. (2026, February 13). Security Awareness Training Statistics. Gitnux. https://gitnux.org/security-awareness-training-statistics
Priyanka Sharma. "Security Awareness Training Statistics." Gitnux, 13 Feb 2026, https://gitnux.org/security-awareness-training-statistics.
Priyanka Sharma. 2026. "Security Awareness Training Statistics." Gitnux. https://gitnux.org/security-awareness-training-statistics.
Sources & References
- Reference 1PROOFPOINTproofpoint.com
proofpoint.com
- Reference 2KNOWBE4knowbe4.com
knowbe4.com
- Reference 3SANSsans.org
sans.org
- Reference 4VERIZONverizon.com
verizon.com
- Reference 5CISCOcisco.com
cisco.com
- Reference 6MICROSOFTmicrosoft.com
microsoft.com
- Reference 7NISTnist.gov
nist.gov
- Reference 8GARTNERgartner.com
gartner.com
- Reference 9IBMibm.com
ibm.com
- Reference 10ISACAisaca.org
isaca.org
- Reference 11OKTAokta.com
okta.com
- Reference 12PONEMONponemon.org
ponemon.org
- Reference 13SPLUNKsplunk.com
splunk.com
- Reference 14CISAcisa.gov
cisa.gov
- Reference 15PHISHMEphishme.com
phishme.com
- Reference 16ROI-NATIONroi-nation.com
roi-nation.com
- Reference 17DARKREADINGdarkreading.com
darkreading.com
- Reference 18ESECURITYPLANETesecurityplanet.com
esecurityplanet.com
- Reference 19TRAININGINDUSTRYtrainingindustry.com
trainingindustry.com
- Reference 20ELEARNINGINDUSTRYelearningindustry.com
elearningindustry.com
- Reference 21CSOONLINEcsoonline.com
csoonline.com
- Reference 22KEEPERSECURITYkeepersecurity.com
keepersecurity.com
- Reference 23HOXHUNThoxhunt.com
hoxhunt.com
- Reference 24METACOMPLIANCEmetacompliance.com
metacompliance.com
- Reference 25HELPNETSECURITYhelpnetsecurity.com
helpnetsecurity.com
- Reference 26COFENSEcofense.com
cofense.com
- Reference 27SOPHOSsophos.com
sophos.com
- Reference 28FBIfbi.gov
fbi.gov
- Reference 29ZDNETzdnet.com
zdnet.com
- Reference 30DARKTRACEdarktrace.com
darktrace.com
- Reference 31LOOKOUTlookout.com
lookout.com
- Reference 32BARRACUDAbarracuda.com
barracuda.com
- Reference 33APWGapwg.org
apwg.org
- Reference 34ISC2isc2.org
isc2.org
- Reference 35MIMECASTmimecast.com
mimecast.com
- Reference 36CHECKPOINTcheckpoint.com
checkpoint.com
- Reference 37ANTIPHISHINGantiphishing.org
antiphishing.org
- Reference 38CODE42code42.com
code42.com
- Reference 39CYBERARKcyberark.com
cyberark.com
- Reference 40FORCEPOINTforcepoint.com
forcepoint.com
- Reference 41ESETeset.com
eset.com
- Reference 42JOURNALOFACCOUNTANCYjournalofaccountancy.com
journalofaccountancy.com
- Reference 43NIGHTFALLnightfall.ai
nightfall.ai
- Reference 44SPECTEROPSspecterops.io
specterops.io
- Reference 45BLACKFOGblackfog.com
blackfog.com
- Reference 46DNVdnv.com
dnv.com
- Reference 47HHShhs.gov
hhs.gov
- Reference 48PCISECURITYSTANDARDSpcisecuritystandards.org
pcisecuritystandards.org
- Reference 49DELOITTEdeloitte.com
deloitte.com
- Reference 50ENISAenisa.europa.eu
enisa.europa.eu
- Reference 51PWCpwc.com
pwc.com
- Reference 52DODCIOdodcio.defense.gov
dodcio.defense.gov
- Reference 53DILIGENTdiligent.com
diligent.com
- Reference 54ISOiso.org
iso.org
- Reference 55DELOITTEwww2.deloitte.com
www2.deloitte.com
- Reference 56HEALTHITSECURITYhealthitsecurity.com
healthitsecurity.com
- Reference 57DOCEBOdocebo.com
docebo.com
- Reference 58DFSdfs.ny.gov
dfs.ny.gov
- Reference 59BERSINbersin.com
bersin.com
- Reference 60FEDRAMPfedramp.gov
fedramp.gov
- Reference 61IAPPiapp.org
iapp.org
- Reference 62TALENTLMStalentlms.com
talentlms.com
- Reference 63EBAeba.europa.eu
eba.europa.eu
- Reference 64WORKDAYworkday.com
workday.com
- Reference 65CIOcio.com
cio.com







