Skip to content
atlas

Don't confuse these

Nudging vs Security policy

Why they differ

A policy sets rules that must be followed; a nudge steers behaviour without any rule or penalty.

Nudging

People, culture & awareness

Small, gentle prompts that make the safe choice the easy one, without forbidding anything.

Formal

Shaping the setting in which people make choices - reminders, sensible default settings, well-timed messages - so the secure option becomes the natural one, while every option stays open.

In plain English

Like painting footsteps on the floor leading to the stairs - nobody is forced, but most people follow them.

In practice

In a municipal job centre, a sticker on every screen reads “Leaving? Windows key + L”, and the mail system shows a yellow banner at the top of every message from outside.

Why it matters

Training is easily forgotten at the moment of choice; a nudge appears right at that moment, so habits change at low cost and without the resistance that new rules meet.

Security policy

Fundamentals

A document that sets out an organisation's goals, responsibilities and principles for information security.

Formal

A leadership-approved statement of the organisation's intent for information security - its goals, who is responsible for what, and the rules everyone must follow. It is reviewed at set times and backed by more detailed rules for specific topics.

In plain English

Like the house rules on a fridge - short, agreed by the grown-ups, and meant to settle arguments before they start.

In practice

A new case worker at a Danish municipality reads and accepts the security policy on day one; among other things it says that work files may only be stored in approved places, never on a private cloud account.

Why it matters

It turns leadership's intent into something written and shared, which every later rule, control and audit can point back to.

Shared connections

Atlas is in beta.