Skip to main content
Guidance

Cyber security culture principles

How to create the right cultural conditions in an organisation that support and encourage people to carry out the desired cyber security behaviours.

Page 8 of 10

Principles in practice

Culture plays a huge role in how people behave. But culture can be hard to perceive directly. The following scenarios are designed to show how poor security outcomes can arise from certain cultures, and how the principles can help prevent this. Their aim is to help you consider how the poor outcomes you can observe may indicate a deeper cultural challenge you need to tackle.

These scenarios were inspired by real behaviours and real security outcomes discovered during research and testing of the principles. 

Key:

  • Scenario where principle has not been applied ('bad')

  • Scenario where principle has been applied ('good')

Principle 1. Frame cyber security as an enabler, supporting the organisation to achieve its goals

  • Scenario where principle has not been applied ('bad')

    A fast-paced sales team thinks their security procedures waste time because they prevent them from responding to customer needs efficiently, which inevitably means they lose the sale. The security team believes the sales team is being wilfully negligent in bypassing the security procedures. 

  • Scenario where principle has been applied ('good')

    The sales and security teams' agree their shared purpose is securing sales through responsive customer relationships, strengthened by personal data protections and underpinned by reliable and secure operational systems.  The two teams can now co-create a set of security procedures that meet the needs of the sales team's ways of working as well as managing the specific risks of working online.

Principle 2. Build the safety, trust and processes to encourage openness around security

  • Scenario where principle has not been applied ('bad')

    A junior member of staff receives an email from a senior demanding that he send sensitive documents to an email address he has not seen before. The junior member of staff doesn't dare question this demand and instead complies. Regardless of whether the email is legitimate or a phishing attempt, it could pose a significant security risk.

  • Scenario where principle has been applied ('good')

    A culture of psychological safety would allow the junior member of staff to ask the senior some questions to verify the authenticity of the email, suggest secure alternatives and challenge any potential policy breaches, without fear of reprisals.

Principle 3. Embrace change to manage new threats and use new opportunities to improve resilience

  • Scenario where principle has not been applied ('bad')

    The organisation’s marketing team is eager to boost social media impact and has collaborated with an external agency to create video content. The security policy on file size limitations prevented the team from using email to share the material, and there were no other approved file sharing apps. Security refused to change the policy, being concerned about data exfiltration. So the marketing team decided to use a free data sharing app, bypassing the policy restrictions and neglecting to consider the potential risks.

  • Scenario where principle has been applied ('good')

    If the marketing and security teams had come together to decide and agree how to proceed to achieve the best business outcome, they might have identified a secure solution to file sharing which could fulfil a wider business need, helping the organisation to better communicate with its suppliers, customers and partners. Or they might have arrived at a one-off solution which could be carried out in a risk managed way. Alternatively, if the risk was deemed too great for the organisation, early discussions would have allowed the marketing team to change plans before the project began.

Principle 4. The organisation’s social norms promote secure behaviours

  • Scenario where principle has not been applied ('bad')

    An organisation has an important visitor who wants Wi-Fi access. It is the norm to share the password to the corporate network for guests who need internet access whilst visiting. However, this means the guest has the potential to access the entire corporate network, which is a security risk. Declining the visitor's request is considered impolite and people cannot be expected to do this to meet their organisation’s cyber security policy.

  • Scenario where principle has been applied ('good')

    A better way to approach this problem would be to ensure that only corporate devices can connect to the main network, and to provide a secure alternative for guests. This solution offers the further benefit of providing guest access to any future visitors to the organisation as a welcoming gesture.

Principle 5. Leaders take responsibility for the impact they have on security culture

  • Scenario where principle has not been applied ('bad')

    A senior employee has amassed excessive IT access privileges, far beyond what is needed for their role. They insist that they should have this level of access because they are too busy to have to request access to individual documents as they need them. Other seniors are starting to follow suit, seeing this elevated level of access as a mark of seniority privilege. Between them, they are carrying a huge amount of risk for the organisation, and a cyber attack to steal credentials is likely to cause a major incident.

  • Scenario where principle has been applied ('good')

    A leader who recognises their responsibility to security understands that their behaviour carries risk beyond their own actions. In this instance, following the organisation’s IT access policies would not only reduce their own level of risk, but would also role-model the right behaviour to others.

    If the IT access policies were unworkable in the first place then a leader could use their influence to get the policies updated, ensuring a better experience for all.

Principle 6. Provide well-maintained cyber security rules and guidelines, which are accessible to all and easy to understand

  • Scenario where principle has not been applied ('bad')

    During the covid lockdowns, many organisations had to establish new ways of working to ensure business continuity. For example, global shortages of computing equipment forced many to implement policies allowing employees to use their home IT. These policies may have changed frequently during this period, potentially causing confusion about what is and is not permitted.

  • Scenario where principle has been applied ('good')

    Now that work practices have stabilised, it is crucial to test the latest policies against current ways of working and today’s threats, update them as necessary and clearly communicate changes to the organisation. Temporary policies should be archived and updated policies clearly signposted to ensure everyone is following the latest version. Reporting mechanisms should be established so people can seek help if they have issues with the policies or their local work practices.

Published

Reviewed

Version

1.0