What are the building blocks of security culture?
by Kai Roer - Senior Partner, The Roer Group
- Friday, 20 December 2013.
Why do we think we do not need all three components when it comes to corporate security culture? We expect our employees to use the technology with a minimum of training, to actually understand and pay attention to all the policies and regulations we put in place, and all that with a bare minimum of security training.
Instead, we should incorporate training designed to work in our organization - on all levels. The training should be adapted to our needs, risk acceptance level, and current and target security behavior. That means we have to learn how to adopt a holistic approach to security culture, and not to rely just on the yearly mandatory phishing training we send employees out for, knowing in advance that the results will be poor.