Building a Cyber Culture for your Business

Last month was Cyber Awareness Month, but of course, cyber security isn’t just a ‘once and done’ thing, it’s an ongoing challenge that evolves on a near-daily basis, meaning that technical mitigations, policy and process are very often behind the curve, even in the most diligent of organisations.

This is where having a strong cyber security culture comes in. The National Cyber Security Centre define Cyber Security Culture as “the collective understanding of what is normal and valued in the workplace with respect to cyber security”, and it speaks strongly to people, behaviours and expectations. This means that where people identify activities that could indicate threats, they feel empowered to act upon those things; they get better at spotting something out of the ordinary and are accustomed to reporting these things.

Leadership

A good cyber security culture starts with the leadership team. Leaders should talk openly about cyber security challenges, both those within the organisation, and those coming from outside. The NCSC did just this a number of years ago, when a senior member of staff almost responded to a phishing email, and explained in a blog post the whole thinking process that they went through in establishing it was not a genuine email. Whilst the article is no longer available, it demonstrates how transparency can provide an excellent learning opportunity, showing that anyone can be a target. Leaders need to demonstrate their commitment to improving cyber security posture, by taking personal measures such as undertaking training, and by investing in cyber security teams and technology as appropriate. Cyber security needs to be seen as a business investment, not an annoying bolt-on that needs to be ticked off for compliance purposes. Senior staff members should lead by example – they shouldn’t be given special privileges or ‘work-arounds’, which could set the tone that shadow IT is acceptable practice.

Avoid a Blame Culture

Creating a culture of fear or blame is highly ineffective. If a member of staff is concerned that a breach has occurred, it is vital that they feel comfortable in reporting their concerns as soon as possible, even if they believe they may be at fault.  It is much better to know about potential incidents and deal with them appropriately, than find out too late that people knew something was wrong but were too afraid to report it. Again, leaders have a role to play here, by praising staff for reporting weaknesses in cyber resilience and cyber incidents, and by being proactive themselves.

Make Security Everyone’s Job

In building a strong cyber security culture, we make security everyone’s job. Just like with Health & Safety, we want every single person in an organisation to be accountable for their own best practice, and to contribute to the cyber resilience of each aspect of the organisation they interact with. Whilst the tech teams are responsible for technical mitigations, individuals in all areas have a responsibility to ensure they are adhering to guidance, using due diligence in their working day and reporting anomalies. This contributes towards the Defence in Depth approach, where layers of defence contribute greatly to the overall cyber maturity of the organisation.

Personal security icons

Continuous Reinforcement

Whilst annual training is useful, it doesn’t do enough to build a cyber culture. Typically with one-off videos, staff will see them as a job to tick off, rather than buying into a more holistic approach to cyber security. Instead, opt for more regular short and engaging training and reminders. Phishing simulations can be useful, but should be used with caution, short quizzes and tips in internal newsletters can also be beneficial, acting as regular reminders to be diligent.

Conclusion: Security as a Shared Value

A strong cyber culture is driven by trust, communication, and a sense of shared responsibility. Tech plays an important part, but can only go so far: your people are those who are at the heart of protecting your organisation and data. So, as cyber security awareness month comes to an end, it’s worth taking a moment to ask yourself “what role do we each play in keeping our organisation secure, and what can I do to improve this?”.

There’s a lot to consider when it comes to building a strong cyber security culture for your organisation. Whether you need help in configuring your IT infrastructure, building a cyber strategy, or training and tabletop activities for your teams, we support businesses with a range of cyber professional services. As your cyber security partner, we can support you in identifying your gaps and advise on how to improve your cyber security posture.

 

Dr Clare Johnson is a Capability Lead with over 20 years’ experience managing a range of IT and information security programmes. With a particular interest in skills development and linking industry to education, Clare is an advocate for improving access and diversity in the sector.

More Articles