6 Criteria For Building A Security Culture

Cyber security involves more than just IT policies and processes

Add bookmark

In business, it goes ‘People, Process, Technology.’ However, in cyber security it has to go in that order and perhaps most important is the People aspect of the saying. That’s because people are oftentimes the first and last line of defense within any organization … then come the processes and tools needed to help them do their jobs better.

Fortunately and unfortunately, because of the human nature and emotion of people – they will also always remain a target for hackers. But — neuroscientists, storytellers and marketers can teach us something about driving secure behaviors within an enterprise.

See Related: “Strengthen Enterprise Security By Understanding Human Emotion

In a recent book titled, “Transformational Security Awareness,” author Perry Carpenter explains how to empower security leaders with the information and resources they need to assemble and deliver effective, world-class security awareness programs that drive secure behaviors and culture change. The first step in doing so, however, is to start by determining whether or not your organization has a successful cyber security culture in place. Here are 6 ways to tell if you are on the right path:   

  1. Belief: Organizations successful in creating a security culture have educated their users to the point users understand and believe that their participation in security is necessary and paramount to the success of the organization. Without belief, there is no adoption. And without user adoption, the culture is dead.

  2. Attitude: It’s one thing to believe; it’s entirely another to act upon it. Somewhere in the middle is the employee’s attitude towards their participation in the security culture. Users should have a positive attitude, wanting to assist with doing their part to secure the organization, rather than seeing it as a distraction from their job and a nuisance.

  3. Assumption: You can tell the user is security-minded when they do the same that you do every day when opening emails, visiting web pages, etc.; there’s an assumption of scrutiny necessary to be certain what you’re interacting with is legitimate.

  4. Behavior: Users who have bought into the security culture begin to change the way they act; less impulsive clicking, more checking domain names and email addresses, and more verification of who’s asking or offering.

  5. Ways of doing things: Users are less likely to work around IT and seek to ensure data and access remain protected. Purposeful steps are taken, going out of their way, to uphold culture principles, and maintain the needed state of security.

  6. A Pattern: this is critical. All of the above indicators are not a one-time or temporary thing; they are a continual way of doing business within your organization.

By establishing a true benchmark of your security culture, enterprises can then determine whether or not they need security awareness training or a culture rethink. On a recent web seminar, Carpenter provided examples of mental manipulation in every day life, in order to ethically educate users in the cyber security community.

Carpenter said, “Security awareness and secure behavior are not the same thing.” In other words, just because users are aware, doesn’t mean that actually care. And so creating a secure culture is so critical.

To learn more about the three realities of security awareness, hear real-world examples including a BEC hack, W2 fraud, an invoice phish and more — listen to the full on-demand session.

 

 


Upcoming Events

16th Automotive Cybersecurity Summit 2026

March 18 - 19, 2026

Sheraton Ann Arbor Hotel, Ann Arbor, Michigan

16th Automotive Cybersecurity Summit 2026

Digital Identity Week

1st - 2nd September 2026

Sydney, Australia

Digital Identity Week

Latest Webinars

From Dependencies to Defences: Navigating Software Supply Chain Security

2025-09-24

11:00 AM - 12:00 PM SGT

Learn how to defend your software supply chain from dependency threats and build resilient security...

Unpacking global regulatory frameworks to enhance third-party operational resilience

2024-11-14

11:00 AM - 12:00 PM EST

Join this webinar to explore the resilience-focused requirements of DORA, NIS2 and other global regu...

Preventing financial and reputational risk with process intelligence

2024-05-23

11:00 AM - 12:00 PM EDT

Learn how to manage risk stemming from poorly controlled processes in a collaborative way

Recommended

info@cshub.com/r/n

We hope you enjoy All Access from CS Hub!!<\/p>\r\n<p>Best Regards,<\/p>\r\n<p><a href=https://www.cshub.com/"https:////www.cshub.com///" target=\"_blank\">CS Hub Team<\/a><\/p>\r\n<p>P.S. Be sure to check out our other upcoming <a href=https://www.cshub.com/"https:////www.cshub.com//events?filter_format=ONLINE\%22 target=\"_blank\">All Access events here<\/a>.<\/p>\r\n<p>--------------------------------<\/p>\r\nConnect with us on Social Media: <a href=https://www.cshub.com/"https:////www.linkedin.com//groups//12067996///" target=\"_blank\">LinkedIn<\/a> | <a href=https://www.cshub.com/"https:////twitter.com//CSHubUSA/" target=\"_blank\">Twitter<\/a><\/p>\r\n<p>--------------------------------<\/p>\r\n<p>FAQS<\/p>\r\n<p><b>Can I invite my colleagues?<\/b><br>Yes of course! Please send them this link so they can register for free! [WebUrl]<\/p>\r\n\r\n<p><b>How do I access the sessions?<\/b><br>\r\nAll Access is run on Zoom Events. You should receive an email shortly from Zoom Events with your unique All Access link to the event lobby. Please hold on to that email ahead of the event. We\u2019ll also send you a reminder 24 hours before we go live!<\/p>\r\n\r\n<p><b>Will the agenda be updated?<\/b><br>\r\nYes, the agenda will be continuously updated on the website with the latest sessions & speakers. As we get closer to the event, also look out for our weekly updates which will also include the latest updates information and link to access the event.<\/p>\r\n<p><b>Can I access the sessions On Demand?<\/b><br>\r\nEvery session will be available after the event via the event lobby. We\u2019ll also send you a reminder about the On Demand sessions which will be sent to you after the event is over.<\/p>\r\n<p>--------------------------------<\/p>\r\n<p>RELATED RESOURCES TO READ BEFORE YOUR EVENT<\/p>\r\n<ul>\r\n <li><a href=https://www.cshub.com/"https:////www.cshub.com//executive-decisions//reports//cs-hub-mid-year-market-report-2022?utm_source=eco-event-confirmation-email&utm_medium=email&utm_campaign=eco-event-confirmation-email\%22 target=\"_blank\">CS Hub Mid-Year Market Report 2022<\/a><\/li>\r\n <li><a href=https://www.cshub.com/"https:////www.cshub.com//security-strategy//reports//ciso-strategies-for-proactive-threat-prevention?utm_source=eco-event-confirmation-email&utm_medium=email&utm_campaign=eco-event-confirmation-email\%22 target=\"_blank\">CISO strategies for proactive threat prevention<\/a><\/li>\r\n <li><a href=https://www.cshub.com/"https:////www.cshub.com//security-strategy//reports//how-to-strengthen-email-security-and-protection-against-advanced-ransomware-attacks?utm_source=eco-event-confirmation-email&utm_medium=email&utm_campaign=eco-event-confirmation-email\%22 target=\"_blank\">How to strengthen email security and protection against advanced ransomware attacks<\/a><\/li>\r\n<\/ul>","event_registration_srs_confirmation_email":null,"assets_from_cdn":true},"bant_disabled":null,"sponsorship_disclaimer":null,"sponsorship_disclaimer_text":null,"sponsorship_disclaimer_checkbox_disabled":null,"ext_treat_id":null,"recording_url":null,"file_attachment":null,"ingo_enabled":null,"ingo_activator_id":null,"ingo_autofiller_id":null,"ingo_amplifier_id":null,"ingo_authorizer_id":null,"restricted_content":0,"featured_events_embedded":[],"featured_content_embedded":[],"featured_content_portal_embedded":null}" >