Skip to main content
Stop Trying to "Build" Security CultureGovernance & Roles
4 min readFor Information Security Officers

Stop Trying to "Build" Security Culture

The Conventional Wisdom

Security culture programs often follow a predictable routine: quarterly phishing simulations, mandatory awareness training, gamified challenges with leaderboards, and occasional all-hands presentations. Success is measured by click rates, training completion percentages, and quiz scores, repeated annually. If your metrics improve, you're told you're building a strong security culture.

This approach treats security culture as something you construct through education and reinforcement. The assumption is that if people know better, they'll do better. Just keep teaching, testing, and tracking until the culture shifts.

Why We Disagree

You can't build culture. You can only measure and shape the decisions people already make.

Culture isn't about what people know or what they claim they'd do in a survey. It's the pattern of actual choices made under real constraints, with real consequences, when nobody's watching. Phishing test results measure performance on phishing tests, not decision-making competence when someone's CEO texts them at 11 PM asking for urgent access to a system.

The conventional approach conflates awareness with culture and lacks a framework for what "good" looks like beyond compliance theater. What specific decision-making competencies does your organization actually need? What trade-offs should a product manager make when a security control threatens a launch deadline? How should your finance team balance access convenience against segregation of duties requirements?

If you can't answer those questions specifically, you're not shaping culture. You're just hoping for acceptable outcomes.

The Evidence

A competency-based approach developed with Kaplan defined five specific decision-making domains:

Business Focus: Balancing flexibility and agility against effective controls; understanding what's critical; recognizing when compensating controls make sense; knowing when to challenge policy that harms the business more than it protects.

Cyber Risk Awareness & Assessment: Understanding the threat environment and available responses; proactive threat appreciation; assessing cyber needs throughout product and service lifecycles.

Security Policy & Practice: Knowledge of organizational policy; understanding security roles and responsibilities; proactive reporting of concerns; supporting appropriate security investment.

Cyber Security Advocacy: Promoting proactive, values-based cyber culture; collaborative work on cyber issues; challenging poor behavior; ensuring partners and contractors meet requirements.

Personal Practice: Taking personal responsibility for cyber compliance; applying practices inside and outside work; resilient, balanced decision-making; basic security hygiene.

The measurement approach used scenario-based questions with multiple answers, none of which were "correct." Leadership scored each answer against the five competencies, establishing what balance they wanted to see. One scenario: the CEO is in a Chinese hotel, has smashed their phone screen, and asks about getting it fixed locally before leaving in 24 hours. The options ranged from "tell them not to fix it" to "let them fix it and do nothing."

This revealed where staff were "confidently wrong" (high confidence, poor competency alignment) versus "unconfidently competent" (right instincts, low confidence). The organization tested, a highly regulated conservative business, scored strong on personal practice and security policy but weak on cyber risk awareness and business focus. That specific insight drove targeted interventions, not generic training.

What to Do Instead

First, define your deliberate security culture. What decision-making competencies does your organization actually need? Don't copy someone else's framework wholesale. A startup racing to market needs different business focus calibration than a healthcare provider. A remote-first company needs different personal practice expectations than one with physical security perimeters.

Document your competencies with specificity. "Risk awareness" is too vague. "Proactive appreciation of threats and the ability to assess cyber needs throughout product lifecycles" gives your team something concrete to calibrate against.

Second, measure actual decision-making, not knowledge retention. Create scenario-based assessments that reflect real tensions your staff face. Include the CEO's broken phone. Include the vendor who needs temporary elevated access to fix a production issue. Include the marketing team who wants to use a new SaaS tool that isn't on your approved list.

Score each possible response against your competencies. Which answers demonstrate the balance you want? Which reveal gaps? Track confidence levels alongside responses to identify where people need reinforcement versus fundamental re-education.

Third, use the data to target interventions. If your engineering team is confidently wrong about business focus, that's a different problem than unconfident competence in cyber risk assessment. The former needs perspective shift; the latter needs reassurance and reinforcement.

Fourth, accept that different parts of your organization may exhibit different forms of behavior while still delivering consistent decision outcomes. A global business will have regional variations. That's fine as long as the underlying competencies align.

When the Conventional Wisdom Is Right

Awareness training, phishing tests, and policy communications aren't useless. They're necessary but insufficient.

You need baseline security hygiene education. ISO/IEC 27001 Clause 7.2 requires competence, and Clause 7.3 requires awareness. SOC 2 CC1.4 demands that the entity demonstrates commitment to competence. You can't skip foundational training.

Phishing tests work when they're part of a broader competency framework, not the framework itself. Use them to measure one aspect of personal practice, not as a proxy for security culture. The click rate tells you something about reflexive behavior under specific conditions. It doesn't tell you how someone will handle the CEO's broken phone scenario.

Gamification can reinforce desired behaviors if you've already defined what those behaviors are. Leaderboards measuring training completion are theater. Leaderboards measuring scenario performance against defined competencies might actually drive improvement.

The conventional wisdom fails when it becomes the entire strategy. Security culture isn't built through repetition of generic content. It's shaped through deliberate definition of decision-making competencies, measurement of actual decisions against those competencies, and targeted intervention where gaps appear.

Define what you want. Measure what people do. Shape the gap. Everything else is just surfing the folkways and hoping the magic works.

You Might Also Like