Organisations need to address the staff ABC of cybersecurity – Awareness, Behaviour, Culture. While most organisations address the first two, these approaches are often reaching the limits of their effectiveness as they primarily change the behaviour of an individual, so it’s an ongoing task that has to be repeated with every newcomer. In contrast, establishing a security culture is essential to be sustainable and deliver more efficient practices over the long term. The good practices appropriate to your environment need to become embedded so that newcomers will adopt them without needing to be trained.
Discussion Points:
- Why culture change is a long term change process that organisations need to be committed to
- How security champions can be used as an extension of the security team
- Why security teams need to build relations with peer departments to push out their message
- Tailoring approaches to suit different verticals, regions, and sub-cultures such as acquired companies