Guidance
Cyber security culture principles
How to create the right cultural conditions in an organisation that support and encourage people to carry out the desired cyber security behaviours.
Our advice & guidance covers a broad range of topics
Resources for individuals and organisations in the UK who have experienced an online scam or cyber attack.
Find a range of products & services from NCSC and certified 3rd party suppliers
Working with industry, government and academia to support the next generation of researchers, students and cyber security professionals
All the latest information to help you keep track of what's happening
How to create the right cultural conditions in an organisation that support and encourage people to carry out the desired cyber security behaviours.
Page 7 of 10

Establishing rules and guidelines to create a cyber secure workplace requires a careful balance. The rules need to allow people the flexibility to work and solve problems within their local areas, but they also need to set expectations that everyone knows and respects. Done well, they help establish a trusted relationship between the organisation and its people.
Having rules which are too prescriptive will eventually be detrimental to security, as they will rapidly become unwieldy and outdated. On the other hand, guidance that is too casual or vague leaves people in the dark and exposed to risks that they are ill-equipped to manage. Both approaches can cause uncertainty and stress and could deter people from engaging further with cyber security.
Achieving this balance means engaging with different areas to learn where they are struggling, inviting stakeholders from these groups to contribute to rule development, listening to feedback and regularly reviewing and testing whether they are serving their purpose.
The rules and guidelines should be embedded in processes and onboarding and must be easy to find and reference, and make it clear when updates supersede any earlier content. If the rules or guidelines for any process are unclear, missing – or ineffective in certain situations – and people don’t know how to manage the security risks, then they should have quick and easy access to experts to help them.
You have tested every cyber security rule to ensure it makes a meaningful contribution to the security of the organisation, is usable and accessible by everyone, and aligns with the shared purpose.
Your cyber security rules and guidelines are designed for inclusivity, are easy to find and access, and are included in onboarding materials.
People understand the difference between the rules that must be followed and the guidelines that provide advice.
You invite and use people’s feedback to continue to refine and improve your security rules.
You widely communicate any changes to rules and ensure out of date material is archived to avoid confusion.


