Wednesday, August 19, 2026
EN FR
Admin
Compliance

SANS Security Awareness Maturity Model: Measuring Security Culture Instead of Assuming It

SANS Security Awareness Maturity Model: Measuring Security Culture Instead of Assuming It

The Assumption Problem in Healthcare Security Awareness

Healthcare organizations spend millions annually on mandatory training, phishing simulations, and awareness campaigns. Yet when a data breach occurs—whether through a credential compromise, social engineering, or a negligent employee—the inevitable post-breach assessment reveals a troubling pattern: the training existed, but the culture did not. This disconnect reflects a fundamental operational gap: most healthcare cybersecurity leaders are assuming security awareness is effective rather than measuring whether it actually changes behavior.

The HIPAA Security Rule (45 CFR §164.308(a)(5)) mandates that covered entities implement security awareness and training programs, but it specifies compliance through documentation and completion rates—not behavioral outcomes. Similarly, the HITRUST CSF, which many health systems use for third-party risk management, requires awareness training but does not prescribe measurement methodologies. This creates a compliance checkbox that may produce certificates but not culture change.

The SANS Security Awareness Maturity Model (SAMM) bridges this gap by providing healthcare leaders with a structured, measurable approach to quantifying security culture across five progressive maturity levels. Rather than counting training completions, the model evaluates whether awareness actually translates to behavioral change and risk reduction.

Understanding the SANS SAMM Framework

The Five Maturity Levels

The SANS SAMM organizes security awareness maturity into five stages, each representing increased sophistication in how organizations measure, reinforce, and sustain secure behaviors. Understanding where your organization sits on this continuum is the first step toward targeted improvement.

Level 1: Ad Hoc. Awareness activities are sporadic and uncoordinated. Training is often reactive—triggered by an incident rather than planned—and no metrics exist to assess impact. Many rural and critical access hospitals begin here due to resource constraints.

Level 2: Managed. Awareness programs are formally planned and documented, with basic metrics tracking completion rates and assessment scores. Most health systems meet this level during HIPAA and HITRUST audits. However, completion metrics do not reveal whether employees actually apply security principles in their daily workflows.

Level 3: Defined. Organizations establish baseline behavioral metrics, conduct risk assessments to identify high-risk user populations (e.g., clinical staff with EHR access, revenue cycle employees handling insurance data), and tailor awareness programs accordingly. Metrics now measure behavioral intent and knowledge retention, not just training attendance.

Level 4: Measured. Quantitative metrics track behavioral change across the organization. This includes phishing simulation performance by department, time-to-report for suspicious emails, and correlation between awareness scores and security incidents. Data-driven insights inform resource allocation.

Level 5: Optimized. Security culture is continuously refined using predictive analytics and feedback loops. Organizations at this level use FAIR (Factor Analysis of Information Risk) or similar quantitative risk models to calculate the cost-benefit of specific awareness interventions and adjust programs in real time.

Practical Implementation for Healthcare CISOs

Step 1: Conduct a Maturity Assessment

Before designing interventions, assess your current maturity level honestly. Work with your security awareness officer and compliance team to evaluate: Are awareness activities reactive or proactive? Do you track only completion rates, or do you measure knowledge retention and behavioral change? Can you correlate awareness metrics with incident data?

Step 2: Define Behavioral Metrics Aligned to Risk

Move beyond completion percentages. Instead, establish metrics that matter for your threat landscape:

  • Phishing simulation click-through rates by department: Clinical staff may have different risk profiles than IT. Target interventions accordingly.
  • Time-to-report suspicious emails: This behavioral metric reflects whether employees recognize phishing as a shared responsibility.
  • Password management practices: Use periodic audits (with proper authorization) to assess whether staff follow passphrase standards and avoid reuse.
  • Device lock compliance: Monitor login session patterns to identify unlocked workstations or shared credentials—common vectors in clinical environments.
  • Incident attribution by awareness level: Segment breach root causes by whether involved employees had received recent targeted training.

Step 3: Segment and Tailor Programs

Healthcare has distinct user populations with different risk exposures. A radiologist accessing images remotely has different threat vectors than a billing specialist processing insurance claims or a nurse at a clinical workstation. SANS SAMM emphasizes that maturity requires acknowledging these differences. Develop persona-based awareness tracks: clinical role-specific training, vendor/third-party training, and executive-level training aligned to their respective risk profiles and HIPAA responsibilities.

Step 4: Integrate with Governance Frameworks

Connect awareness metrics to your existing compliance and governance structures. The NIST Cybersecurity Framework's Govern function (RSC.Gov) explicitly calls for integrating security culture into organizational strategy. Document how awareness maturity supports your HITRUST remediation roadmap and quarterly board-level cybersecurity reporting.

Step 5: Create Feedback Loops

At Levels 4 and 5, maturity requires continuous learning. When a phishing campaign succeeds, that is a data point—not a failure. Use incident post-mortems to identify whether the user lacked training, received training but did not retain it, or understood the risk but made a conscious choice. This diagnostic approach shapes future programming.

Overcoming Healthcare-Specific Barriers

Healthcare has unique constraints. Clinical staff work extended shifts, off-shift access to patient data is legitimate, and turnover rates are high—all of which complicate sustained awareness culture. SANS SAMM accommodates this by allowing maturity progression at different rates across organizational segments. Your IT department may operate at Level 4 while clinical areas operate at Level 2 with a documented, resource-constrained improvement plan. Transparency about constraints is more credible than false claims of enterprise-wide maturity.

Measuring What Matters

The SANS SAMM's fundamental contribution is shifting healthcare cybersecurity from an assumption-based model to a measurement-based one. You cannot manage what you do not measure. By implementing this framework, CISOs move from asking "Did everyone complete training?" to asking "Did that training prevent the incident that would have otherwise occurred?" That reframing is both scientifically sound and operationally transformative.

📚 Recommended Reading

Books our AI recommends to deepen your knowledge on this topic.

📚
Implementing the NIST Cybersecurity Framework
by David Moskowitz
Moskowitz's work on NIST CSF implementation directly supports the governance and measurement requirements that align with SANS SAMM's emphasis on integrating security awareness into organizational frameworks and risk management.
View on Amazon →
📚
The Phoenix Project: A Novel About IT, DevOps, and Helping Your Business Win
by Gene Kim, Kevin Behr, and George Spafford
The Phoenix Project illustrates how organizational culture and systemic feedback loops drive operational outcomes, providing the DevOps and continuous improvement mindset essential for progressing through SANS maturity levels beyond ad hoc awareness training.
View on Amazon →
📚
Weapons of Math Destruction
by Cathy O'Neil
O'Neil's examination of metrics, their unintended consequences, and the importance of ethical measurement design is critical for healthcare leaders implementing SANS SAMM to avoid false positives and ensure behavioral metrics actually reflect risk reduction rather than gaming compliance.
View on Amazon →