Skip to main content
Annual Review

NCSC Annual Review 2025

Looking back at the National Cyber Security Centre's ninth year and its key developments and highlights, between 1 September 2024 and 31 August 2025.

Page 13 of 32

Don't wait for the breach: why don't organisations act earlier?

The role of leadership, culture, and behavioural science in encouraging proactive approaches to cyber security.

Cyber security needs to be a boardroom issue. It affects financial performance, operational continuity, and corporate reputation. Yet, despite the rising frequency and severity of cyber incidents, many organisations still do not act until after a breach has occurred. The consequences – legal, financial, and reputational – can be devastating, as seen in several high-profile attacks this year.

This delay is not simply a matter of oversight. It reflects a complex mix of behavioural, cultural, and financial dynamics that shape how organisations perceive and respond to cyber risk. Drawing on behavioural science theory and recent research into cyber security culture, this article explores why action is often deferred, and what senior leaders can do to change that.

At a basic level, the lack of preventative action can be explained by not having a full understanding of:

  • the likelihood of a cyber attack happening to them
  • the possible impact this could have on their business
  • their ability to prevent (or recover from) a cyber attack

Furthermore, research suggests that individuals are more likely to act when they:

  • feel positively about the action
  • believe others expect them to do it
  • feel confident in their ability to follow through  

Therefore, a focus on understanding the true cyber risk facing organisations, the impact breaches could have and the actions that could be taken will help organisations take action before they are victims of a cyber attack.




What is cyber security culture?

Cyber security culture is the collective understanding of what is normal and valued in the workplace with respect to cyber security. It sets expectations on behaviour and relationships, influencing people's ability for collaboration, trust, and learning.

Leaders have a vital role to play in setting the tone for their organisation's culture. While some goals can be achieved by the cyber security team, significant and sustained impact needs leadership buy-in and advocacy

This year, the NCSC published its Cyber Security Culture Principles, outlining what good culture looks like and how to shift perceptions and behaviours. Applying the principles will help you tackle the behavioural barriers identified in this article and provide a foundation for change. To support implementation, the NPSA launched the Security Culture Tool, helping organisations assess and shape their entire security culture.

Improving cyber risk culture is not a technical issue – it’s a leadership issue. Boards must set the tone from the top and embed cyber resilience into the organisation’s DNA.


Published

Reviewed

Version

1.0