How To Build A Security Culture



In my previous post I made the case for building a security culture instead of a leadership culture. The goal of a security culture is to bring all employees and business units, or as many as possible, into the mindset of balancing risks, understanding and supporting trade-offs, and thus enabling performance that relies on a positive view of cybersecurity instead of cybersecurity rituals.

So, you may ask, how does that happen?

A good place to start is in the CISO Tradecraft® piece we mentioned entitled "How to create a leadership culture." The trick is that you need to focus on security culture, not leadership (or worse, leader) culture. 

Here are six approaches that work:

Master your communication about security. Tell us why, and then you can tell us how as long as we understand why.

How does your program stack up against peers? If your program stinks, how does your proposed security culture move the needle? If it's good, how does your proposed security culture enable greater organizational performance?

Celebrate wins beyond the SOC. This is the barbecue example from the source post.

Everybody is a teacher. A focus on peer mentoring and upholding expectations, works.

Dignity & respect for all. If your function has a relentless focus on the four pillars of a successful cybersecurity function -- hire for talent, structure, engagement, development -- then everyone has unity of purpose. When they lack those, then it's everyone for themselves.

Consequences. The way you know whether there is a security culture and not security theater is when something goes wrong. And something will go wrong. What happens then? If you sacrifice someone to the security gods then you get fear. If you do a thorough root cause analysis (see Brendan's posts) on a strict timeline you get accountability and context and better security. (Scapegoats make bad offerings to the security gods.)

I used to work for a 3-star admiral, one of whose sayings was that he wasn't a broken record, he was just consistent in his messaging. That's perfect. Your security culture should be part of every briefing and business unit function you have. Your peers may not get it but remember they too lead (or work in) functions and they too need a culture. Seeing that you're 100% invested in security for the good of the organization is a force multiplier for security throughout the organization.

Ask us how we can help you can scale the security culture in your organization.

(image credit: Mikhail Nilov)

Comments