How to create a security-focused culture in your company

A cyber-aware organization requires open dialogue, incisive action and empowered employees. Here are five tenets to consider when building an adaptive, security-first company culture.

 

Key takeaways

Security culture must evolve with the business. Employees play a critical role in protecting the company and should continuously build their knowledge. Keep these points in mind to be part of the solution:

  • Lean on existing company culture. The language used in sales, operations, human resources and business functions reflects the company culture. Security should be no different. It should be discussed in terms that are consistent with how the business at large promotes and evaluates itself.
  • Align security with business goals. Employees should think of security in terms of the company’s overall success. Leaders should take every opportunity to connect good security habits with successful outcomes.
  • Remember that security must always evolve. As the means of doing business change, the methods in which employees are trained and tested must adapt to reflect those changes. Regularly revisit the exercises used to evaluate employee readiness and use all communication channels to keep new and changing security threats on the radar.

Cybersecurity is a technical challenge for any business, but a more comprehensive view of cybersecurity involves considering the human factor.

 

According to one authoritative study, the majority of data breaches involve people and the choices they make.1 Another study found that 71% of users admitted to taking risky actions online, and nearly all did so knowingly—often rating their behavior as highly risky.2

 

Making security an essential part of company culture can positively impact overall business success. Encouraging employees to think about security helps shift the focus beyond technology and highlights the important role people play through ongoing, open dialogue.

 

While a cultural shift requires leadership support, a top down approach isn’t enough. Employees at every level need to think about cybersecurity as a business objective — one that requires their cooperation and focus. All employees should approach their responsibilities, processes and tasks with security in mind—and understand that security must adapt as cyber threats and business objectives evolve.

 

Key areas of opportunity can help elevate cybersecurity awareness across any culture. While these areas often overlap, defining them can help employees better understand their role—or inspire them to become security advocates among their colleagues.

Five pillars of an adaptive security culture

A framework based on the following five tenets can provide a good starting point, no matter how mature a company’s cybersecurity culture may be:

 

Capabilities. For a company culture to be truly adaptable and responsive, it requires tools that not only enable employees to work securely but also adapt to how and where they work.

 

For instance, if a company allows hybrid or fully remote work, employees need tools and processes that aid secure sign on, up to date device management and effective tracking and protection of data. If the culture is collaborative and security conscious, it will be easier for workers to see how well these capabilities are serving them, and for leaders and experts to gauge how familiar the workers are with available protections. The capabilities should always be developed in line with business objectives.

 

Collaboration. Businesses rely on repeatable processes, but sound processes often originate in informal brainstorming sessions. Employees who work together should be given the opportunity to discuss what they need to securely perform their jobs and support each other’s roles.

 

In part, this means fostering greater transparency and openness around mistakes with security implications, as well as sharing up to date information about industry cyber trends. Where security processes are already in place, teams can support one another by organizing regular discussions — such as informal lunches or internal messaging threads — to openly explore the benefits and limitations of those processes.

 

Collaboration can also help remove barriers that keep security experts in the company siloed from other employees. Rather than one way communication focused on experts telling employees what not to do, companies of all sizes can encourage dialogue where non experts can ask questions and discuss the limitations of current practices.

 

Communication. As with any business objective, security must be discussed in language that is consistent with the organization, its priorities and the industry in which it operates. It must also be a regular topic of communication for company leaders, who should pair security with overall company health and success in their messaging.

 

Leadership can emphasize the cultural importance of security by making training courses and test exercises a regular part of performance reviews. Employees should also be reassured that they will be valued for speaking up, even if it means confessing to mistakes or giving constructive feedback about security oversights or flawed processes.

 

Education. There are few areas that afford companies a better opportunity to emphasize cultural shifts and security priorities than education and training exercises. Training must be highly specific to the company’s workforce and business function to be effective. It should be tailored to employees’ savviness about technology and security and reflective of how the majority makes decisions — and it must be updated regularly to reflect emerging threats.

 

Businesses can also consider tabletop exercises or simulated events that help employees visualize how a genuine cyber event might occur and think through the steps of their specific response. Leadership can reinforce training with regular updates about security practices and industry specific threats, or through surveys that gauge the extent of employees’ knowledge of cybersecurity without the pressure that comes from a formalized test.

 

Empowerment. When employees believe security is a secondary consideration, or someone else’s responsibility, they are not well positioned to be responsible participants. Since any employee has the potential to unknowingly precipitate a cyber incident, each needs to understand the importance of their role and how they contribute to a secure work and business environment.

 

Because distraction and fatigue are often cited as causes of cyber incidents, employees should feel that slowing down is justified and valuable when they receive suspicious emails or requests.Employees should be encouraged to ask security focused questions, or to reach out to a security expert with their concerns. Most of all, they should feel empowered to report an incident, even if it involves a mistake they’ve made, such as responding to a phishing email.

1 Verizon 2025 Data Breach Investigations Report

2 Proofpoint State of the Phish Report 2024

Back to Cybersecurity Journal
How to create a security-focused culture in your company

Fraud & Cybersecurity

New threats emerge every day that can negatively impact transactions and businesses. Explore the latest insights and resources to help prepare and protect you and your business.