?? Security awareness isn’t enough—it's time to focus on culture. On Cloud Security Today, Lance Spitzner joins Matthew Chiodi to share his journey from military tank officer to cybersecurity pioneer. He breaks down why security culture matters more than awareness, how AI can transform engagement, and what security teams can do to drive real change. If you're rethinking how to approach security awareness in your organization, this is a must-listen. ??
Most security teams think they’re solving the human risk problem. In reality, they’re just running an expensive check-the-box training program that employees ignore. Lance Spitzner has spent years shifting the security conversation from "awareness" to "culture"—the difference is everything. ?? Security awareness = Training employees on security rules. ?? Security culture = Creating an environment where security is a shared value. Why does this matter? Because what people believe matters more than what they’re told. ? If security teams are viewed as helpful and approachable, employees will engage. ? If security teams are viewed as punitive and bureaucratic, employees will hide mistakes. Example: If someone clicks on a phishing email, do they report it? Or do they stay silent out of fear? A strong security culture means people feel safe speaking up and acting in the best interest of the organization—not just to protect themselves. So, is your security team building trust? Or just enforcing rules? You can listen to the interview by looking for Cloud Security Today wherever you listen to podcasts or in your browser at Cloud Security Today dot com (formatted like this since LinkedIn loves to penalize external content). #SecurityCulture #Cybersecurity #HumanRisk #Leadership #SecurityAwareness #Infosec #TrustMatters SANS Institute