Skip to main content
Guidance

Cyber security culture principles

How to create the right cultural conditions in an organisation that support and encourage people to carry out the desired cyber security behaviours.

Page 2 of 10

Principle 1. Frame cyber security as an enabler, supporting the organisation to achieve its goals

Gremlin via Getty Images

The role of cyber security is to ensure that the technology and information that underpin the organisation's functions aren't compromised or disrupted by malicious actors. But if the function of cyber security is carried out separately from other functions, it makes it difficult for people to see how it enables every other function in the organisation. There is a risk that:

  • cyber security is seen as a barrier to getting the job done
  • the impact of cyber security policies and processes on the organisation’s people aren't appreciated or understood
  • cyber security policies don't actually serve the organisation and people choose to bypass them, which leads to further possible security risks

Having a ‘shared purpose’, or an organisation-wide understanding of the organisation’s goals, creates a shared reference point. Decisions at all levels and across all functions should be made based on what helps the organisation achieve its overall goals, rather than what achieves local goals at the expense of others.

What good looks like

  • People in the organisation know the important role cyber security plays in keeping their vital technology functioning, and their important information confidential and available.

  • People know how their own secure behaviours contribute to achieving the shared purpose.

  • People don’t see your cyber security policies and processes as barriers to doing their jobs.

  • The people who design and implement cyber security controls are fully aware of how they impact on people’s ways of working, and proactively engage to reduce any negative impact.


Published

Reviewed

Version

1.0