Security Culture > Leadership Culture
The good people at CISO Tradecraft® recently published a piece entitled "How to create a leadership culture." Since this veers directly into our typical behavioral cybersecurity lane, we thought it was worth reviewing.
The start is promising: "In the high-stakes world of cybersecurity, many organizations mistake “security theater”, the endless checklists, mandatory slide decks, and annual compliance box-checking, for actual security. But security isn’t a checklist; it’s a force field. And that force field is generated by your organizational culture."
Great!
Indeed, culture is a "force field" as we endorse this view. Thank you CISO Tradecraft!
But then we diverge.
Effective behavioral cybersecurity is not about a "leadership culture" per se, it's about creating a security culture.
Here's the distinction. A security culture is a force field because culture governs what behavior gets tolerated among and between team members. When behavior that impairs, threatens, or weakens security gets a pass, the force field collapses. In an always-on threat environment, that collapse is expensive, as in you could lose your job and the organization could lose a lot of money.
CISO Tradecraft gets part-way there. Their strongest section describes a CISO who throws a barbecue and hands out an award to the department with the best phishing-reporting scores, explicitly to enlist people outside security in caring about it. That's a real attempt at building shared behavior, and it deserves credit. But it's still top-down: the leader recognizes, the leader rewards, the leader sets the tone. The piece's actual conclusion makes that top-down framing explicit: it closes by urging every CISO to write a personal "Command Philosophy" and hand it to new hires on day one.
Very few things are as pathetic in an organization as a leader who has no idea how they want to lead, and we endorse having a command philosophy on those grounds. But a command philosophy answers the "why" of leadership, not the "why" of cybersecurity. It's a force field for the leader.
Build a department around it and you get a leader culture, not a security culture.
You do not want a leader culture.
You want a security culture because that explains why we balance risks, which directly enlists every single employee in balancing risks -- not going for the phishing attack, not giving out passwords, not ignoring system vulnerabilities, etc.
A leader culture asks people to follow someone. A security culture asks people to understand something, and act on that understanding whether or not the leader is in the room.
If you lack a culture of balancing risks then you have a function that is the keeper of the rituals -- the checklists, programs, annual security training, etc we all hate.
If you have a security culture, you have a team that focuses on operations, not rituals.
Ask us how you can build the security culture you need.

Comments
Post a Comment