Culture

Wonderful!

Security culture will fix everything (apparently). Increasingly (so the story goes), managers are realising the crucial benefits of a security culture. And they’re rushing to get one. Whatever it is.

According to the UK Government:

Organisations with a successful security culture deliver security strategies and solutions that work for their employees: they meet people where they are in order to achieve the mutual goal of being more secure. They have an agreed understanding of what kind of security culture the organisation wants, and a dynamic, positive, and business-focused security team that aims to help everyone do their job.”

Wow. Sounds great. I’d love to be met where I am. I’ve tried meeting people in places where they weren’t, and it really didn’t work for me.

All in all, I think it’s fair to ask: what is a security culture? Supplemental question: how do I get one? A good one, nothing shabby.

Practitioners

You’d expect the cyber practitioner community to have a shared understanding of what a cyber security culture is, right? After all, it’s the practitioner community that’s pushing the idea.

A survey of security managers conducted by Forrester bracketed their responses into five broad categories:

  • 29% of respondents saw it as strict compliance with security policies
  • 24% defined it as awareness and understanding of risks
  • 22% saw it as a situation involving shared responsibility for security
  • 14% saw it as management influencing security choices
  • 12% thought it was about security being seamlessly embedded into the business

So… over 50% think it’s about raising awareness and getting users to do as they’re told. BAU security, in other words.

About a third see it as foisting the problem onto others, particularly users and managers. And a small minority, about one in eight, think it might have something to do with business operations.

Not exactly a ground-breaking idea then, being mostly based around improving compliance and/or shifting responsibility. And not exactly a shared vision. The survey covered 1200 cyber practitioners, who collectively provided something like 750 different definitions.

The weird thing for me is that compliance is seen as both a precursor to, and an outcome of, an effective security culture. That is, if you can get people to comply with the security rules, then you have a good security culture. And if you have a good security culture, then the outcome is that people comply with the security rules. Um…

Credit: Shutterstock

Academics

Oost and Chew reviewed the evidence for the thing formerly known as security culture, and concluded that:

A review of published research on the topic suggests that it is not the information security panacea that has been suggested.

Instead it tends to refer to a range of existing techniques for addressing the human aspect of information security, oversimplifying the link between culture and behaviour, exaggerating the ease with which a culture can be adjusted, and treating culture as a monolith, set from the top. Evidence for some of the claims is also lacking.

Ouch.

Nasir et al. found over 100 research and discussion papers on the subject of security culture. Only about 5% of the papers they examined were based on experimental results, meaning the rest were either theory or conjecture.

Dugo examined the relationship between the strength of a prevailing security culture and people’s attitudes towards deliberately contravening security policies. The study showed no significant link. That is, even where there were factors supposedly driving a ‘good’ security culture, attitudes towards security were no different.

“Interestingly, despite strong recommendations from information security scholars that the cultivation of positive [Information Security Culture] will influence employees’ security behavior in line with [Information Security Policy], there is actually lack of empirical findings to confirm this relationship.

Karlsson et al. looked at the available evidence, and noted that “… existing research has focused on a broad set of research topics, but with limited depth”. I’d say that’s more polite than necessary, personally. Karyda similarly concluded that “… the academic field of information security culture has been described as immature, lacks empirical validation, while the constituents of the concept as well as methods, tools, frameworks and metrics for fostering and evaluating it within organisations remain elusive”.

Outcomes

According to Nasir, if you gather together the factors that supposedly go into a good security culture, and then eliminate the duplicates and combine similar-sounding concepts, you get a list of nearly fifty papers drawing on 26 issues that various people use to define their particular view. Uchendu also found a large number of factors supposedly making up a security culture, with no common definition, no metrics, and a strong emphasis on theorising. Da Veiga specifically, proposed a total of five external factors making up a security culture, plus another twenty internal ones.

I wouldn’t be the first to point out that a list of twenty five parameters underpinning a social construct isn’t really helpful in defining the construct. It means that when security practitioner ‘A’ is talking to you about security culture, they’re unlikely to be thinking about the same thing as practitioner ‘B’ when they’re talking to you about security culture.

David Lacey (as ever) sums up the situation concisely: “Many security practitioners would like to introduce a better ‘security culture’ into their organizations, but few can define precisely what that actually means”.

And before you start aligning it with a safety culture, let me quote Dekker, whose argument is that the desire to implement a safety culture stems mostly from a requirement to offload responsibility rather than to improve safety.

Benefits

There’s the usual guff all over the place about security culture achieving miraculous results, most of which is from people trying to sell you the idea of a security culture. That can safely be discounted. The rest of the noise can be suppressed by deleting any claims involving ‘could’, ‘might’ and ‘research shows’ (without citing any actual research).

Thing is, in the absence of a definition, you can’t identify the benefits of a ‘good’ security culture. Nothing illustrates this more than the definition of security culture as “the way security is done around here”. If you’ll excuse the mixed metaphor, that’s about as much use as a chocolate firewall.

Most of the other definitions that you’ll see reference ‘shared values’ etc.. Also guff, because they too provide no basis for telling a ‘good’ culture from a bad one.

And that, right there, is the problem. Security culture is put forward as a means of improving security behaviours – solving the ‘human cyber risk problem’. But the industry then ducks the question of what ‘improved’ behaviours look like. If you ignore the woolly pap regarding ‘shared values’, what you’re left with is compliance.

So is that it – security culture is about improving compliance?

Reality

Here’s a trolley problem for you. Someone falls for a scam involving the transfer of money, supposedly authorised by a company director. It costs the organisation £5k. The individual concerned is mortified. How could I have been so gullible? A week later there’s another, more sophisticated attack, this time looking for a £50k transfer. The individual, having been sensitised, checks with the director, and prevents the scam from going ahead. Now, was the original decision a ‘bad’ one? Because without that initial mistake, the second and more costly attack would have succeeded.

While you’re thinking about that – Alter points to the possibility of “beneficial non-compliance” i.e. it’s not always in the best interests of the organisation for people to unthinkingly follow the rules. The idea is that sometimes, considered (i.e. deliberate) non-compliance leads to an overall benefit for the organisation. Consequently, a ‘good’ security decision might be one that goes against the prevailing guidance. Suck that up.

And here’s the irony. If indeed there were such a thing as security culture, as a set of behaviours “aligned with the values of the company”, then such a set of behaviours would inevitably lead to occasional instances of deliberate non-compliance with the security rules.

Options

As pointed out elsewhere on this very web site, it’s not possible to write security guidance that will cover every set of circumstances. As a result, people will necessarily and inevitably employ their judgment when making the vast majority of security decisions. So I’m thinking that it might be better to support their judgment, rather than to put your faith in security culture – i.e. something that has no definition, shows no link to positive outcomes, and which doesn’t even seem to exist.

Here’s an alternative. The likelihood of people falling for a phishing attack can be reduced from the default of 23% to about 7%, by employing the concept of mindfulness. Yep, that’s right. Just by asking individuals to step back from the decision, and ask themselves “why would anyone want me to click that?”. No concept of culture required, good or bad. Just some simple steps to increase engagement, and foster the use of more considered decision-making.

In a similar vein, Isler found that by explaining cognitive biases such as confirmation bias, not as faults but as something to be aware of, and by adding a simple rule of thumb to overcome it (such as using a “pre-mortem”), together with a call to action, people made more considered decisions. That’s not necessarily always going to be a decision with a positive outcome, but it’s more likely to be a decision that can be justified after the fact. Which I would say is a reasonable basis for a ‘good’ security decision, whether or not it’s compliant with the rules.

Crass and Offensive Conclusion

It depends who you ask, but the phrase “Wenn ich Kultur höre…” (when I hear the word ‘culture’) is usually concluded with “entsichere ich meinen Browning” (I take the safety catch off my pistol). It’s been variously attributed to Goebbels, Himmler and Göring, but it was actually a Nazi playwright (Hanns Johst). Not much of a difference in the morality stakes there, to be honest. So I won’t quote that version. Not worth getting the Gen Z’s all hot and sweaty.

Instead, I’ll quote the version that goes “When I hear the word ‘culture’, I reach for my chequebook”. Because that reaction, I think, is the target behaviour for those practitioners who trumpet the idea of a security culture.

It really is all about the Benjamins. Because why else sell pixie dust, when there are actual solutions available?

Selected Sources

  1. Government Security. Improving security culture. Available from: https://www.security.gov.uk/policy-and-guidance/improving-security-culture/
  2. KnowBe4. Security Culture Report 2020. Available from: https://www.knowbe4.com/hubfs/Security-Culture-Report.pdf
  3. Alnatheer, M.A. Information security culture critical success factors.12th International Conference on Information Technology-New Generations. 2015. IEEE
  4. Oost, D. and E.K. Chew, Investigating the concept of information security culture. Strategic and practical approaches for information security governance: Technologies and applied solutions, 2012: p. 1-12.
  5. Nasir, A., A.A. Ruzaini, and A.H. Rashid, Information security culture guidelines to improve employee’s security behavior: a review of empirical studies. Journal of Fundamental and Applied Sciences, 2018. 10(2S): p. 258-283.
  6. Dugo, T., The insider threat to organizational information security: a structural model and empirical test. 2007.
  7. Karlsson, F., J. Åström, and M. Karlsson, Information security culture–state-of-the-art review between 2000 and 2013. Information & Computer Security, 2015. 23(3): p. 246-285.
  8. Karyda, M., Fostering Information Security Culture In Organizations: A Research Agenda. 2017.
  9. Uchendu, B., et al., Developing a cyber security culture: Current practices and future needs. Computers & Security, 2021: p. 102387.
  10. Lacey, D., Understanding and transforming organizational security culture. Information Management & Computer Security, 2010.
  11. Alter, S., Beneficial noncompliance and detrimental compliance: Expected paths to unintended consequences. 2015.
  12. Zheng, S. Y., & Becker, I. (2023, October). Phishing to improve detection. In Proceedings of the 2023 European Symposium on Usable Security (pp. 334-343).
  13. Isler, O., O. Yilmaz, and B. Dogruyol, Activating reflective thinking with decision justification and debiasing training. Judgment & Decision Making, 2020. 15(6)

First published 15th July 2026