Towards a Security-Oriented Culture
It is a wise and advisable action that business owners and tech operations managers proactively invest in cybersecurity services. Just like any insurance-based expense (health insurance, car insurance, fraud insurance) cyber-insurance is no different. Companies must give active thought towards ensuring online assets and digital property are adequately protected.
However, such investments are not sufficient. It is common, even after considerable precautions, that you find passwords like “123456” or “ABC123”, or birth days or the like. You will also find employees, with complete good intentions, will click on links or respond to emails they should not. This can render all the built protections useless.
Businesses need to realize the most important line of defense are people themselves. It is very important that people possess a security-oriented mindset and develop healthy digital habits that do not lead to unnecessary compromising of our digital assets. This is synonymous with people actively choosing not to leave their wallets lying around, or not leaving their bags unattended. This is done instinctively and naturally with no second thought. It is very important the same applies when it comes to cybersecurity.
Building a cybersecurity culture is critical because it is very difficult to control the behavior of every single person. As long as that person has access to our assets, that person is a potential liability. There are certain things that can be done to foster such a cybersecurity culture:
- Leadership: Nothing substantial happens in any organization without leadership conviction. Company leadership must demonstrate complete buy-in so that this buy-in naturally transfers into employees’ convictions and behaviors.
- Not an IT Problem: Well-managed companies always emphasize that customer satisfaction is everyone’s responsibility, not just customer service or marketing. The same with cybersecurity. Every person must accept that he plays a role in protecting the company and that it’s not merely an IT problem
- Integration in Process: Cybersecurity should be naturally woven into all of the company’s processes and operations. This is the essence of implementing and enforcing GRC. All executed protocols must include the necessary steps and actions that cover cybersecurity.
- Psychological Safety: People will make mistakes. This is a fact, and good management entails being aware of such mistakes to take precautionary actions. Leaders must ensure employees feel safe to admit mistakes (without repercussions) in order for vulnerabilities to be pushed to the surface and dealt with. The alternative is people being silent until the problem turns into a catastrophe.
Even with such steps, this does not mean everything will be smooth. There will be some common challenges encountered such as:
- Resistance to change: People are naturally resistant to change, and different ways of doing work will often be perceived as a “waste of time” or “a productivity drain” without any perceived value. This is where the role of leadership is critical to ensure bad cyber-habits are killed and positive cyber-hygiene is promoted.
- Burnout and alert fatigue: Like any new change being undergone, cybersecurity measures can give the false perception that people are burned out or undergoing alert fatigue. This perception is compounded when conviction with the protection protocols is low. No one feels burnout or alert fatigue from activating house alarms, or car alarms, or locking their doors leaving their houses.
In fact, the two points of objection above can be seen as indicators of hour cyber-maturity. The more people object and express cyber-fatigue, the more this could be an indication your culture has not yet reached its peak cyber-maturity. In all cases, there is no alternative towards starting your cyber-maturity journey and continuously improving and evolving along the way.