Security culture
Also known as: cybersecurity culture
The shared habits and attitudes toward security that shape how people act when nobody is checking.
Draft - this entry has not been reviewed yet.
Formal
The unwritten norms, beliefs and everyday routines about security that members of an organisation share, which decide whether the security policy is lived or ignored.
In plain English
Like the difference between a kitchen where everyone washes their hands because “that's just how we do it” and one where people only do it when the boss is watching.
In practice
At a shipping company's head office, colleagues remind each other to lock their screens, and a department head thanks a new starter at a staff meeting for reporting a strange mail.
Why it matters
Rules and training fade quickly unless the group keeps them alive, so culture decides whether security lasts beyond the last campaign.
Technical deep dive
Most security-culture work borrows Edgar Schein's model of organisational culture, which separates three levels: artefacts (visible structures and behaviour, such as clean desks, badge wearing and a report button), espoused values (what policies and leaders say matters) and basic underlying assumptions (the unspoken beliefs that actually steer decisions, such as "deadlines beat security" or "IT will catch it anyway"). Interventions aimed at artefacts are easy to see but shallow; lasting change requires shifting the assumptions, which is slow and mostly happens through what leaders reward, tolerate and do themselves. That is why ISO/IEC 27001:2022 clause 5.1 requires top management to demonstrate leadership and commitment, and why NIS2 Art. 20 makes management bodies approve and oversee cybersecurity risk-management measures and follow training themselves.
Research from usable security explains why culture fails in practice. Beautement, Sasse and Wonham's compliance budget (2008) models each employee as having a finite willingness to absorb security friction; once exceeded, people start bypassing controls, and the bypasses become shared norms. Workarounds such as shared passwords, personal cloud storage and shadow IT are therefore diagnostic signals of friction, not only of misconduct. From safety science comes the idea of a just culture: honest mistakes are reported without punishment, while reckless or malicious behaviour is still sanctioned. Without that distinction, and without psychological safety in Amy Edmondson's sense, near misses go unreported and the organisation loses its best source of early warnings.
Measuring culture is harder than measuring awareness. Instruments combine surveys of attitudes and perceived norms, interviews and observation, and behavioural indicators such as reporting rates, time from mistake to self-report, the number and age of policy exceptions, and whether security is raised early in projects or only at go-live. NIST SP 800-50 Rev. 1 (§1.4) treats culture as the outcome that a learning programme should support, not as a module in itself, and ENISA's report Cyber Security Culture in Organisations (2018), drawing on organisational science, psychology and law, offers methodological tools and step-by-step guidance for starting or improving a culture programme.
Culture should not be confused with its neighbours. Security awareness is what each individual knows and can do; culture is the group-level set of norms that decides whether that knowledge is applied when it is inconvenient. A security policy states the rules; culture determines whether they are lived. The human firewall is one visible expression of a strong culture, and subcultures matter: a development team, a hospital ward and a finance department in the same organisation can have very different security norms and need different interventions.
What to learn first
Everything this builds on, foundations first.
- Security policy
- →Threat
- →Security awareness
- →Security culture
Relationships
- Kinds
- Human firewall
- Part of
- Governance
- Unlocks
- Awareness maturity
- Don't confuse with
- Security awareness
- Mitigates
- Shadow IT
- Used with
- Human factorLessons learned
Sources & further reading
Official documentation
Course material
- Cyber Security Fast Track - Ordliste
Where this data comes from
This entry was drafted by an AI from the sources above and has not yet been checked by a person. Treat it as a starting point, and check anything important against the sources.
See the review queueSuggest a correction on GitHubThis term as JSON
Check yourself
Loading…