Close Menu
  • Home
  • Articles
    • Attacks
      • BEC
      • Data Breach
      • DDoS
      • Evasion Attacks
      • Injection
      • Malware
      • MITM
      • Phishing
      • Ransomware
      • RCE
      • Social Engineering
      • Spoofing
      • Spyware
    • Business and Policy
      • BCP and DRP
      • GRC
      • Regulations
    • Data Protection
      • DLP
      • DRM
      • Encryption
      • IAM
    • Future, Trends and Insight
      • AI
      • Events & Community
      • Emerging Tech
      • Expert Panel
      • Interviews With Experts
      • Insights
      • Study & Research
    • Resources
      • Guides
      • Tools
      • Training & Education
    • Security
      • API
      • Apps
      • Cloud
      • Critical Infrastructure
      • Endpoint
      • Hardware
      • IoT
      • Mobile
      • Network
      • OT
      • Port Security
      • Security Architecture
      • Software Development
      • Supply Chain
      • Zero Trust
    • Threats and Vulnerabilities
      • Emerging Threats
      • Insider Threats
      • Risk Management
      • Threat Intelligence
      • Zero Day
  • News and Exclusives
    • Latest News
    • ISB Exclusive
    • Positive News
  • Who We Are
    • About Us
    • Information Security Buzz Expert Panel​
    • Write for Us
    • Media Pack
  • Contact Us
  • Newsletter
Facebook X (Twitter) LinkedIn
Facebook X (Twitter) LinkedIn
Information Security BuzzInformation Security Buzz
  • Home
  • Articles
    • Attacks
      • BEC
      • Data Breach
      • DDoS
      • Evasion Attacks
      • Injection
      • Malware
      • MITM
      • Phishing
      • Ransomware
      • RCE
      • Social Engineering
      • Spoofing
      • Spyware
    • Business and Policy
      • BCP and DRP
      • GRC
      • Regulations
    • Data Protection
      • DLP
      • DRM
      • Encryption
      • IAM
    • Future, Trends and Insight
      • AI
      • Events & Community
      • Emerging Tech
      • Expert Panel
      • Interviews With Experts
      • Insights
      • Study & Research
    • Resources
      • Guides
      • Tools
      • Training & Education
    • Security
      • API
      • Apps
      • Cloud
      • Critical Infrastructure
      • Endpoint
      • Hardware
      • IoT
      • Mobile
      • Network
      • OT
      • Port Security
      • Security Architecture
      • Software Development
      • Supply Chain
      • Zero Trust
    • Threats and Vulnerabilities
      • Emerging Threats
      • Insider Threats
      • Risk Management
      • Threat Intelligence
      • Zero Day
  • News and Exclusives
    • Latest News
    • ISB Exclusive
    • Positive News
  • Who We Are
    • About Us
    • Information Security Buzz Expert Panel​
    • Write for Us
    • Media Pack
  • Contact Us
  • Newsletter
Subscribe
Information Security BuzzInformation Security Buzz
Home - Articles - Creating A Culture Of Cybersecurity
Articles

Creating A Culture Of Cybersecurity

Julien EscribeBy Julien EscribeAugust 17, 2022Updated:December 15, 20224 Mins Read
Share LinkedIn Twitter Facebook Copy Link Email
Share
Facebook Twitter LinkedIn Email Copy Link
Quick AI Summary
ChatGPTClaudeGeminiGrokPerplexityDeepSeekCopilot

Cybersecurity is a top priority for all organisations, but any system will only be as strong as the people who use it.

In a world where data breaches can cost millions in fines and disrupt entire countries, it’s more important than ever that companies implement a systematic Security by Design approach, thinking of the security implications of everything they do, including the habits of their employees.

Analysing the culture and behaviour of an organisation, not just the physical and virtual security systems, provides a clearer idea of where vulnerabilities might lie. Addressing the human dimension of cybersecurity often involves significant culture change, with the goal of reinforcing security as a priority for all employees, not just the IT team.

How do you build a culture of security?

1. Change the language and training around security

Businesses need to help their employees learn how to do things differently and train them to think of security as a business priority. Researchers have found that our working memory capacity is between three and five ‘chunks’ of information. This number starts to decline in our 30s, so a safe working figure is probably four chunks of information that the majority of your employees are able to keep in their short-term memory at any point.  

What does this mean for security? Basically, we need to keep things simple and easy to remember.

Factsheets and training days may have their place, but on their own they’re not enough. Consider instead a strategy that uses a combination of continual awareness testing and roleplaying worse-case scenarios, to make security something that’s embedded as a mindset.

2. Make security training and reinforcement part of regular meetings

In the manufacturing industry, it’s standard practice for daily or weekly team meetings to start with a section on safety. This is the kind of behaviour we should adopt for security practices, too. A regular update on new threats, suspicious activity, and a reminder of best practice is a great way to constantly remind people of their role in the organisation’s security. Engagement and repetition are effective ways to continue guiding a change in behaviour.

Consider new and different ways to train users. People respond in different ways to learning, so consider creating more engaging learning tools, such as short videos, showing real-life security situations. Humour can work well, too. The best training materials transform concepts into something more personal and relatable. They can be coupled with some broader training, such as IT-controlled phishing attempts, that can provide measurable results over time, showing the resilience of the global organisation to widely distributed attacks.

3. Invest in proactive, not reactive defence 

Organisations need to get more proactive when it comes to defending their systems. Threat intelligence should cover the internet as a whole, including the Deep and Dark Nets.

Find out who’s interested in the company. Look for entities that are buying and selling the organisation’s credentials. Businesses need to know where the potential threats are coming from and how they’ll know when they’re being attacked. With this information, the business can give employees the information and training they need to modify their behaviour and learn positive security habits.

4. Establish a cybersecurity centre of excellence (CoE) and communities of practice (CoP) 

CoEs act as sparring partners, allowing businesses to test solutions and assumptions around products, services and solutions.

CoPs take this work to a larger audience, allowing employees to form communities to keep them up to date on the latest threats and remind them about their responsibility in keeping the network safe.

You could consider activities like workshops featuring security professionals with expertise in specific areas, to drive collaboration and discussion around security concerns.

5. Stress-test your preparedness

Tech teams are used to stress-testing systems against online threats. In a culture of security, these tests include employees to account for human behaviour and error. Run regular simulations of cyberattacks to identify problems with the tech response and see how people respond.

Businesses can see how well their new culture is working by simulating something like a social engineering or spear-phishing attack.

No matter how much you prepare, someone, at some point, will make a mistake. We’re human. But with the right culture, where employees put security at the heart of everything they do, you can reduce the risk of a catastrophic security breach. 

Julien Escribe

Julien is a partner at ISG and leads its digital practice in the South Europe and Middle East Region. Having been involved in more than 80 successful engagements in IT performance assessment and sourcing strategy, Julien brings his clients long-term experience and insight that draws from working with ten of ISG’s largest global clients.

  • Julien Escribe
    Developing Trends In Cybersecurity
  • Julien Escribe
    The Changing Trends In Cyber Security

The opinions expressed in this post belong to the individual contributors and do not necessarily reflect the views of Information Security Buzz.

Share. Facebook Twitter LinkedIn Email Copy Link

Related Posts

Exploited Faster, Patched Slower: Verizon DBIR 2026 Shows Security Teams Losing Ground

May 20, 20265 Mins Read

Security’s Blind Spot: The Threats Hiding in “Low-Severity” Alerts

May 6, 20265 Mins Read

Why OSINT deserves the same status as other intelligence disciplines

March 17, 20266 Mins Read
ISB-Bora-Side-Bar

No se ha podido establecer conexión. Error 429

 
ISB-Bora-Side-Bar
Black ISB Logo

Information Security Buzz is an independent resource that provides the experts’ comments, analysis, and opinion on the latest Cybersecurity news and topics

X (Twitter) LinkedIn Facebook RSS

Working With Us

  • About Us
  • Advertise With Us
  • Contact Us

Write For Us

  • How To Contribute

The Pages

  • Privacy Policy
  • Cookie Policy
  • AI Policy
  • Terms & Conditions
  • Copyright Notice

Information Security Buzz and all its contents are copyright © 2014-2025. All rights reserved. All third-party trademarks are recognized.

Type above and press Enter to search. Press Esc to cancel.

Manage Consent
To provide the best experiences, we use technologies like cookies to store and/or access device information. Consenting to these technologies will allow us to process data such as browsing behavior or unique IDs on this site. Not consenting or withdrawing consent, may adversely affect certain features and functions.
Functional Always active
The technical storage or access is strictly necessary for the legitimate purpose of enabling the use of a specific service explicitly requested by the subscriber or user, or for the sole purpose of carrying out the transmission of a communication over an electronic communications network.
Preferences
The technical storage or access is necessary for the legitimate purpose of storing preferences that are not requested by the subscriber or user.
Statistics
The technical storage or access that is used exclusively for statistical purposes. The technical storage or access that is used exclusively for anonymous statistical purposes. Without a subpoena, voluntary compliance on the part of your Internet Service Provider, or additional records from a third party, information stored or retrieved for this purpose alone cannot usually be used to identify you.
Marketing
The technical storage or access is required to create user profiles to send advertising, or to track the user on a website or across several websites for similar marketing purposes.
  • Manage options
  • Manage services
  • Manage {vendor_count} vendors
  • Read more about these purposes
View preferences
  • {title}
  • {title}
  • {title}