Finding two: the threat is a person on the phone, and now a chatbot on the desk
The report ranks the human risks practitioners are focused on. Social engineering, meaning phishing, text-based smishing and voice-based vishing, is first at 77 per cent, and the report notes it is 'by far' the top risk because technology alone can only go so far against it. It also notes a rise in both volume and sophistication of the phone and text versions, partly because organisations have got better at catching email, and partly because AI now makes it easy to research a target and build a convincing story, including cloned voices.
Second, up from fourth two years ago, is inappropriate AI use at work, at 42 per cent. The open-ended answers explain what that looks like in practice. Respondents described staff 'pasting sensitive material into public AI tools without thinking twice. Customer details, internal documents, draft contracts, sometimes whole chunks of code.' Not from bad intent. The tools made work faster and, as one practitioner put it, the friction of 'should I be putting this here?' disappeared somewhere between deadline pressure and curiosity. Another reported staff overriding explicit security advice because 'Copilot said so'.
Social engineeringphishing · smishing · vishing77%
Inappropriate AI use at worksensitive material in public AI tools42%
up from #4 two years ago#1Operations teams are now the top blocker of awareness efforts, for the first time.
Source: SANS Security Awareness & Culture Report 2026