Guidance
Cyber security culture principles
How to create the right cultural conditions in an organisation that support and encourage people to carry out the desired cyber security behaviours.
Our advice & guidance covers a broad range of topics
Resources for individuals and organisations in the UK who have experienced an online scam or cyber attack.
Find a range of products & services from NCSC and certified 3rd party suppliers
Working with industry, government and academia to support the next generation of researchers, students and cyber security professionals
All the latest information to help you keep track of what's happening
How to create the right cultural conditions in an organisation that support and encourage people to carry out the desired cyber security behaviours.
Page 5 of 10

In addition to formal rules, every group, including the workplace, has unwritten rules on how to behave. These unwritten rules - or social norms - are picked up through observing others in the group. Most of us unconsciously follow these rules as it’s part of what makes us feel like we belong.
People’s attitudes towards cyber security are often shaped by different social norms. These norms can strongly encourage secure behaviours, ensuring that new members of the organisation adopt these behaviours and reinforcing continued secure behaviour among all employees.
In an ideal world, an organisation’s social norms would only promote desirable security behaviours. However, these unwritten rules can sometimes undermine secure practices by suggesting that it is OK to bypass security procedures, or take risks. These types of norm might be derived from other values, such as wanting to be polite or helpful, or they could be the result of habitual rule-breaking by influential figures.
When this happens, simply asking people to not follow these unwritten rules rarely leads to behaviour change - especially if the security rules and practices don’t align with their needs to get the work done. Instead, you need to get to the heart of the norm and the underlying values at play in order to work out appropriate interventions.
If you don’t consider the organisation’s social norms when developing your security culture, it’s likely that people will continue to ignore your policies and processes. This will lead to additional security risk and erode trust and compliance around security more generally.
You have identified the social norms (desirable and undesirable) associated with cyber security in your organisation.
You have worked out how to ensure the social norms work in tandem with your security policies.


