Cyber security culture principles
How to create the right cultural conditions in an organisation that support and encourage people to carry out the desired cyber security behaviours.
Pages
Page 10 of 10
Putting people at the heart of an organisation's approach to cyber security

How to help people make good security choices, and minimise the chances of mistakes happening
People – including leaders – play a significant role in the security of an organisation. Throughout the working day, people navigate numerous security encounters of different size and scale, all whilst managing the other demands of their jobs. No one is perfect, and mistakes will inevitably happen. But there are many opportunities to minimise the chances of mistakes happening, and good security means taking advantage of those opportunities. If we don't, we're setting people up to fail.
Focus on how people behave and why they do what they do
The human aspects of cyber security are still immature and often overlooked or forgotten. Although we've seen progress, the field is still dominated by very narrow approaches, rather than systemic interventions. And the NCSC wants this to change. Organisations that help people make good security choices have greater resilience and fewer security gaps.
Human behaviour is driven by far more than just what we know. It also significantly depends on:
-
how we feel
-
what we (and others) value
-
how much time and effort we can afford to invest
-
our physical and mental capabilities
-
our inclination to seek help when needed
Consider the gap between people who have the information to know how to live a healthy lifestyle and those who are able to maintain a healthy lifestyle. Eventually, providing people with information hits a point of diminishing returns, and so we need a new approach which incentivises people by default.
To take advantage of the many opportunities to improve the human aspects of cyber security, an organisation puts effort into understanding and working on the 3 key areas of:
- People-centred design of secure systems
- Cyber security education
- Cyber security culture
Focusing on these 3 areas helps the organisation build a productive and secure workforce.
1. People-centred design of secure systems
Everyone in the organisation needs to be able to use a range of tools and processes easily, effectively and securely – and that requires good whole-system design. The solution to the security challenge faced by one person may not be appropriate for another, for many different reasons.
You should develop security-critical tools and processes with this variety of needs in mind.
Conduct research to understand the context for cyber security tool use, such as:
- people’s experience
- the environment
- local ways of working
- any other tasks competing for people’s attention
Ideally, involve people in co-creating the tools and processes they will be using.
Conduct thorough user testing to identify ways that help to:
- reduce the time and effort needed for people to be cyber secure
- prevent user errors
- ensure accessibility
- avoid situations where people need to choose between being secure and pursuing another important goal
Implement an ongoing feedback and testing process
To ensure that changes over time don’t cause a buildup of issues that are only discovered after an incident occurs.
Consider system resilience and adaptability
Applying a whole system approach to system design, with people and security in mind, provides the opportunity to consider the resilience of the system. This helps ensure that a single human action cannot cause catastrophic failure, and that the system can still function even when unexpected changes do occur. Resilience and adaptability are also essential for an organisation to innovate and capitalise on new opportunities as they emerge.
Methods such as Design Thinking, and other developments in the field of UX design, have much to contribute to the human aspects of cyber security, but in practice they're often siloed from security considerations.
Collaborating and sharing expertise across these disciplines is vital to developing secure and user-friendly systems.
2. Cyber security education
Cyber security best practice is continually changing due to new research, evolving attack methods and advancements in technology. And best practice also varies according to context. As a result, most people won’t have all the information they need at any one time to make the best security choices.
Make sure security information is up-to-date and readily available
It's important to give people access to relevant and up-to-date information which they can refer to as they need it to keep themselves and the organisation secure. It's also good to ensure that people know where they can find further information or assistance if they need it, especially when there is a long time lag between them receiving training and applying what they learned.
Although access to information is important, you should take care not to overwhelm people. The focus should be on providing the information in those areas where people are most likely to need it and can apply it.
When training doesn’t address insecure practices, find another way
If people have the information they need but there is still evidence of poor cyber security, recognise that further training isn’t going to solve the problem. Instead, shift the focus to other opportunities for intervention. Repeated training which doesn’t address the underlying cause of poor security is a waste of everyone’s time.
Enhance learning through safe practice environments
Beyond just sharing information, providing people with a safe learning environment to practice handling complex scenarios can significantly boost their understanding, both individually and as a team. This approach helps them develop strategies and mental models that can be effectively applied during real incidents.
Security education is the most established of the three areas, but in many cases we have reached a point where it no longer brings significant improvements. To continue making progress we must ensure our organisations are using the latest techniques to equip people with the information they need and diversify our interventions away from a purely educational approach.
3. Secure organisational cultures
Security culture refers to how people think about and approach cyber security within an organisation. It's how people feel about security, and their role in it. It also reflects how leaders take responsibility for influencing and shaping it.
Consider the organisation’s social norms
The organisation’s culture has a huge influence on people’s behaviour as it tells them what their peers and leaders value. Even if people in the organisation know what they need to do to be secure, they won’t want to do it if it doesn’t align with the socially valued behaviour, also referred to as the ‘social norm’. When socially valued behaviour conflicts with secure behaviour, the insecure but socially valued behaviour is likely to win out.
Build psychological safety to encourage a whole team approach, including the security professionals
Culture also informs if and how people collaborate. It teaches people to expect particular outcomes when they ask for help, admit a mistake or volunteer an idea. In a psychologically safe environment the team can collectively navigate complex security scenarios, rather than relying solely on the experience and knowledge of a single individual. In addition, in a safe environment security personnel are seen as allies protecting the team, rather than the enemy looking to catch people out.
Promote continuous improvement through a learning culture
Promoting a learning culture enables the organisation to recognise its potential for continuous improvement. It motivates people to seek and make suggested improvements to processes and tools, to make them more secure and user-friendly. It helps people see the value in investing their time in upskilling, rather than seeing it as a chore to be completed as quickly as possible.
Realising a people-centred security culture
Security culture is a well-established concept, but current approaches often overlook the underlying cultural factors and simply repackage security education under another name.
Other business functions are ahead of cyber security in thinking about the foundational cultural elements that influence things like employee retention, inclusion, safety and productivity. Now it's time for cyber security to do the same.
We encourage organisations to use the NCSC’s Cyber security culture principles and the NPSA’s Security Culture Tool to assess their current cyber security culture and identify gaps. These resources can help an organisation take deliberate steps to evolve their culture – placing people at the heart of every decision. In this way, we can build environments where secure behaviour is not just expected, but is naturally supported and valued – and enables your business goals.


