Skip to main content
Guidance

Cyber security culture principles

How to create the right cultural conditions in an organisation that support and encourage people to carry out the desired cyber security behaviours.

Page 4 of 10

Principle 3. Embrace change to manage new threats and use new opportunities to improve resilience

Gremlin via Getty Images

The ability to adapt to change, and continuously improve, is core to a resilient organisation. This is especially true for cyber security which must evolve alongside new technologies and an ever-changing threat landscape. 

In addition to adapting to market and regulatory changes, and handling unexpected events – including cyber incidents – organisations need to actively seek and use these risk events as opportunities for improvement. While maintaining the status quo may seem easier and safer, it actually leaves the organisation vulnerable. Risks go unrecognised and unmanaged and valuable opportunities for growth and improvement are missed. 

The whole organisation must work together to implement changes at a pace that suits all business functions, recognising that if any function either stagnates or moves ahead without broader consensus, it could harm the organisation.

The cyber security team plays an active part in these conversations, ensuring that the balance of risks and opportunities is carefully allocated to teams and individuals best equipped to manage them, rather than being imposed on those unable to handle them. 

What good looks like

  • The organisation’s culture is positive about change, seeing it as a route to improve organisational outcomes – including security resilience. 

  • Decisions about change are well-considered and only implemented when necessary, to reduce change fatigue and disruption.

  • People feel supported to cope with change and confident that responsibility for new risks goes to those best equipped to manage it.


Published

Reviewed

Version

1.0