Skip to main content
Guidance

Cyber security culture principles

How to create the right cultural conditions in an organisation that support and encourage people to carry out the desired cyber security behaviours.

Page 6 of 10

Principle 5. Leaders take responsibility for the impact they have on security culture

Gremlin via Getty Images

Leaders at all levels agree and communicate the shared purpose, and ensure it remains central to their decision-making. They role model secure behaviours, which positively influence social norms. They create and promote an environment of psychological safety, learning and trust through their interactions with others.

Leaders who acknowledge their influence and use it to help improve the organisation's security culture will be a huge asset in improving security. A trustworthy leader is able to amplify key security messages and facilitate the adoption of new policies, inspiring the confidence in their staff to cope with challenges and change.

Leaders who ignore their responsibility to positively influence security culture can actually hinder culture change. People who look to them for guidance are likely to follow their example, thereby undermining any attempts to change culture or improve behaviours in that area.



Published

Reviewed

Version

1.0