Customising Cyber Security Culture

Customising Cyber Security Culture

I recently met up with someone in the Information Privacy sector, and we had a great chat about how our two industries are so closely related and beneficial to one another. This person's company was already implementing cyber security awareness training, and was also starting on cultural change (i.e. keeping awareness front of mind for staff).

One of the initiatives was particularly interesting for me, because it highlights how cultural change must never be a cookie cutter approach, and what works for one company may not work for another.

They started by picking a slogan: "Security is everyone's responsibility". It's a popular choice, because it's true! The next initiative is something that worked for them, but I could equally see it failing in other companies.

Basically the message was that they all needed to support one another, and that meant highlighting when someone could be doing better. So they introduced stickers that could be placed on monitors where the computer was unlocked, or for unlocked office doors, messy desks etc.

IT began placing the stickers, but the process was quickly adopted by staff and Management, keen to jump on the bandwagon and point out where others could be doing better. Due to the culture of this organisation it was never a shaming exercise, more of a bit of light-hearted fun. However the outcome was that behaviour was modified, there was no push back towards the initiative, and everyone had a bit of fun.

Now an exercise like this could be a total disaster in a different organisation, depending on the people and how they interact. But in this case it was a great call, because they thought about their people and what would work for them!

If you want to change your cyber security culture, it must be done properly! There are some great frameworks available to guide you through the process (or people like me), and if you do it right the staff will be along for the ride and produce massive benefits for the organisation!

Find out more: https://www.websafestaff.com.au/other-services/cultural-change


Michael Harris

CAPM | CISM | E8 | SecOps | Surf & Drink Coffee

6 年

My time working in government- when you left a computer unlocked your colleges would email all team members from your account advising them that you failed to lock the computer and the social club penalty that was imposed ( buy the team coffee the next work day). Wondering what your thoughts are on team culture for cyber practices?

Ben Thorn

Intellectual Property, Trade Marks & Commercial Lawyer | Mirai Legal

6 年

Leaving little post it notes with Clippy "?? Looks like you left your desktop unlocked."

Deana Scott

Founder | Health Informatician | Certified Health Manager | #healthcareleadership #remoteworkforce #digitalhealth #coach #entrepreneur #womenintech

6 年

are there green cards for good behaviour ;-)

要查看或添加评论,请登录

Mike Ouwerkerk的更多文章

  • How to get staff to watch awareness videos

    How to get staff to watch awareness videos

    Cyber security awareness is not a one off initiative. People will slowly forget information they are taught, that's a…

    1 条评论
  • Compliance Does Not Equal Security

    Compliance Does Not Equal Security

    I train a lot of people, and I always like to ask whether they have done this type of training before. Largely people…

    3 条评论
  • 10 Hard Truths About Cyber Security Awareness

    10 Hard Truths About Cyber Security Awareness

    I've been in the trenches of cyber security awareness for quite a few years now. In that time I've made a lot of…

    3 条评论
  • How do we spot deep fakes? Don’t bother!

    How do we spot deep fakes? Don’t bother!

    If you haven’t heard of deep fakes, it’s the use of technology to pretend to be someone. You can recreate someone’s…

  • Conversations with a Romance Scammer

    Conversations with a Romance Scammer

    OK, I'm out - "She" wants to have a voice chat. For the last week or so I've been chatting to a romance scammer.

    17 条评论
  • "Human Error" in Cyber Security - It's not what you think!

    "Human Error" in Cyber Security - It's not what you think!

    It's a constant message in cyber security - companies are being breached, and they blame "human error" for about 90% of…

    8 条评论
  • Cyber Security Cultural Change for SMEs

    Cyber Security Cultural Change for SMEs

    The war with cyber criminal scumbags wages on, and unfortunately the battle is still being lost by the good guys…

    5 条评论
  • Toot Toot Here Comes the Deep Fake Pain Train

    Toot Toot Here Comes the Deep Fake Pain Train

    The Scam Picture this: The receptionist gets to work, and there's a voicemail from the IT Manager saying that cleaners…

    2 条评论
  • The Benefits of Cyber Crime

    The Benefits of Cyber Crime

    Yeah I'm gonna go there. Doom and gloom is all we hear, the global economy is losing trillions, companies are getting…

    18 条评论
  • It's All About the Lightbulb Moments

    It's All About the Lightbulb Moments

    Metrics in cyber security awareness can be a bit of an art form, and will need to vary between organisations. But I…

社区洞察

其他会员也浏览了