Guidance
Cyber security culture principles
How to create the right cultural conditions in an organisation that support and encourage people to carry out the desired cyber security behaviours.
Our advice & guidance covers a broad range of topics
Resources for individuals and organisations in the UK who have experienced an online scam or cyber attack.
Find a range of products & services from NCSC and certified 3rd party suppliers
Working with industry, government and academia to support the next generation of researchers, students and cyber security professionals
All the latest information to help you keep track of what's happening
How to create the right cultural conditions in an organisation that support and encourage people to carry out the desired cyber security behaviours.
Page 4 of 10

The ability to adapt to change, and continuously improve, is core to a resilient organisation. This is especially true for cyber security which must evolve alongside new technologies and an ever-changing threat landscape.
In addition to adapting to market and regulatory changes, and handling unexpected events – including cyber incidents – organisations need to actively seek and use these risk events as opportunities for improvement. While maintaining the status quo may seem easier and safer, it actually leaves the organisation vulnerable. Risks go unrecognised and unmanaged and valuable opportunities for growth and improvement are missed.
The whole organisation must work together to implement changes at a pace that suits all business functions, recognising that if any function either stagnates or moves ahead without broader consensus, it could harm the organisation.
The cyber security team plays an active part in these conversations, ensuring that the balance of risks and opportunities is carefully allocated to teams and individuals best equipped to manage them, rather than being imposed on those unable to handle them.
The organisation’s culture is positive about change, seeing it as a route to improve organisational outcomes – including security resilience.
Decisions about change are well-considered and only implemented when necessary, to reduce change fatigue and disruption.
People feel supported to cope with change and confident that responsibility for new risks goes to those best equipped to manage it.


