Guidance
Cyber security culture principles
How to create the right cultural conditions in an organisation that support and encourage people to carry out the desired cyber security behaviours.
Our advice & guidance covers a broad range of topics
Resources for individuals and organisations in the UK who have experienced an online scam or cyber attack.
Find a range of products & services from NCSC and certified 3rd party suppliers
Working with industry, government and academia to support the next generation of researchers, students and cyber security professionals
All the latest information to help you keep track of what's happening
How to create the right cultural conditions in an organisation that support and encourage people to carry out the desired cyber security behaviours.
Page 2 of 10

The role of cyber security is to ensure that the technology and information that underpin the organisation's functions aren't compromised or disrupted by malicious actors. But if the function of cyber security is carried out separately from other functions, it makes it difficult for people to see how it enables every other function in the organisation. There is a risk that:
Having a ‘shared purpose’, or an organisation-wide understanding of the organisation’s goals, creates a shared reference point. Decisions at all levels and across all functions should be made based on what helps the organisation achieve its overall goals, rather than what achieves local goals at the expense of others.
People in the organisation know the important role cyber security plays in keeping their vital technology functioning, and their important information confidential and available.
People know how their own secure behaviours contribute to achieving the shared purpose.
People don’t see your cyber security policies and processes as barriers to doing their jobs.
The people who design and implement cyber security controls are fully aware of how they impact on people’s ways of working, and proactively engage to reduce any negative impact.


