Skip to main content
Guidance

Cyber security culture principles

How to create the right cultural conditions in an organisation that support and encourage people to carry out the desired cyber security behaviours.

Page 3 of 10

Principle 2. Build the safety, trust and processes to encourage openness around security

Gremlin via Getty Images

Effective cyber security needs people to be able to ask for help, report issues, admit mistakes, or suggest new ideas. Even with good training, no one in the organisation can have all of the information and the experience to make the right decision all of the time. 

People need to feel safe from negative repercussions before they will speak up. Without that feeling of safety - often called psychological safety - people in the organisation will be pushed into self-preserving behaviours. This could include covering up mistakes, not challenging poor behaviour or rule-breaking by others, or not volunteering ideas that could help improve security.

Psychological safety is the “belief that one will not be punished or humiliated for speaking up with ideas, questions, concerns or mistakes” (Professor Amy C. Edmondson).

People need to have quick, easy and accessible routes to reach the people they need to talk to, such as help desks, reporting portals or local security experts. These routes should be tested to reduce any friction that may cause people to give up and avoid future contact. 

Acknowledging people’s contributions, and taking action where possible, can create a positive feedback loop which encourages future contributions. 

What good looks like

  • The organisation is committed to building a psychologically safe environment where people feel willing, able and supported to speak openly about cyber security.

  • There are quick, easy and accessible routes for people to ask questions or report security issues.

  • Incidents are investigated with a view to learn and improve, not to blame.

  • People involved in an incident are treated fairly, with no punishment for innocent mistakes.


Published

Reviewed

Version

1.0