Cyber Security Toolkit for Boards
Resources to help Boards implement the actions outlined in the Cyber Governance Code of Practice.
Pages
Page 14 of 27
Developing a positive cyber security culture

People are the strongest link; they’re what make your organisation thrive.
Introduction
Security culture refers to the values that determine how people are expected to think about and approach security in an organisation. These are shaped by the goals, structure, policies, processes, and leadership of your organisation. This includes external partners, suppliers and stakeholders an organisation will work with for their business to succeed.
A positive cyber security culture is essential because it’s people that make an organisation secure, not just technology and processes. If this is in place, people view security as a collective and collaborative endeavour that supports and is supported by their everyday work. If there’s a good security culture:
- employees are more likely to spot problems and suggest potential improvements, which leads to greater resilience
- employees can communicate openly about issues without fear of reprisals, and are much less likely to make use of shadow IT services
- you’ll improve employee wellbeing and retention, driven by inclusivity and an understanding of why security rules exist
Without a good security culture, people won't engage with cyber security, so you won't know about potential workarounds or unofficial approaches. Not only will you have an inaccurate picture of your organisation's cyber security, but you will also miss the opportunity for valuable employee input into how policies or processes could be improved.
Developing the right culture is a continuous process. It takes time, investment, and buy-in from senior leadership. You can encourage behaviours that create the right cyber security culture. You can’t simply ‘change’ a culture to create the right behaviours around cyber security. Culture is an outcome, rather than an input.
Essential activities
Leadership
There must be strong cyber security leadership that is communicated and championed by the board. Board members set the tone when it comes to cyber security culture. If senior leaders ignore policies and processes, or ask for special treatment in some way, this tells everyone else in the organisation that it is acceptable to try to bypass them.
Clear communication
Ensure your cyber policies are developed in collaboration with the workforce and that they are clearly communicated so that everyone in your organisation can understand the risks, their responsibilities and what actions they need to take if required. Your senior leadership should be communicating clearly about cyber risks and policies (for example, through ‘town hall’ meetings, in-house communications and team meetings). The Board should not be working solely in a top-down fashion; they should be listening carefully to people from across the organisation and understand how changes impact the way in which they engage with cyber security.
Simple reporting for incidents
Whilst technical monitoring can look for anomalies, people can act as an early-warning system and intuitively spot something that looks unusual. Ensuring there is a simple process in place for employees to report incidents (where they feel comfortable reporting concerns) can save the organisation a huge amount of time and money. If staff are working around a set procedure, this may highlight a particular policy or process that needs to be addressed . Work with your policymakers to adapt it. The following video below provides common examples of how staff working around security policies can highlight problems with security policies.
Your organisation’s cyber resilience approach should include a strategy for learning from incidents, and what went well, so that your security posture improves over time. Treat incidents as a learning opportunity so that individuals can reflect openly on what happened and feel confident to speak up and report concerns. Put in place processes to capture this information.
Training
Your organisation should have a cyber security training programme. Programmes should be evaluated and (where necessary) improved on a regular basis. Consider rewarding people for demonstrating good cyber behaviours.
Indicators of success
Board members should be good role models when it comes to cyber security behaviours. This includes keeping the data and information you use safe and secure, and knowing what to do if you feel you have been targeted. Speaking openly and positively to employees about why cyber security is important to the organisation will improve the cyber security culture within your organisation.
Cyber security is a shared responsibility. If your organisation is developing a positive cyber security culture, it should be possible for your security team to demonstrate how security policies and processes have been designed in collaboration with HR and training teams to really address the problem and improve the culture. If it is hard to point to ways in which policy or process has been shaped by the wider organisation (including business process owners), this may indicate a less mature cyber security culture.
No blame doesn’t mean no accountability. Learning from incidents is key to understanding why something happened and preventing it in the future. For organisations with a positive culture, incident reports provide an opportunity to reflect on what could have been done differently, including the root cause, the actual response and how the organisation could improve. If the report focuses on individuals or teams who are 'behind the problem’, this is a sign that you have a less mature cyber security culture.
Metrics express the organisation’s values, and if you appear to value the absence of reports of problems, you incentivise people to keep quiet about issues. Consider how you can formulate your security metrics in terms of successes. For example, as well as measuring how many people clicked on a phishing email, focus on how many people reported it.


