No Result
View All Result
SUBSCRIBE | NO FEES, NO PAYWALLS
MANAGE MY SUBSCRIPTION
NEWSLETTER
Corporate Compliance Insights
  • Home
  • About
    • About CCI
    • CCI Magazine
    • Writing for CCI
    • Career Connection
    • NEW: CCI Press – Book Publishing
    • Advertise With Us
  • Explore Topics
    • See All Articles
    • Compliance
    • Ethics
    • Risk
    • FCPA
    • Governance
    • Fraud
    • Internal Audit
    • HR Compliance
    • Cybersecurity
    • Data Privacy
    • Financial Services
    • Well-Being at Work
    • Leadership and Career
    • Opinion
  • Vendor News
  • Library
    • Download Whitepapers & Reports
    • Download eBooks
    • New: Living Your Best Compliance Life by Mary Shirley
    • New: Ethics and Compliance for Humans by Adam Balfour
    • 2021: Raise Your Game, Not Your Voice by Lentini-Walker & Tschida
    • CCI Press & Compliance Bookshelf
  • Podcasts
    • Great Women in Compliance
    • Unless: The Podcast (Hemma Lomax)
  • Research
  • Webinars
  • Events
  • Subscribe
Jump to a Section
  • At the Office
    • Ethics
    • HR Compliance
    • Leadership & Career
    • Well-Being at Work
  • Compliance & Risk
    • Compliance
    • FCPA
    • Fraud
    • Risk
  • Finserv & Audit
    • Financial Services
    • Internal Audit
  • Governance
    • ESG
    • Getting Governance Right
  • Infosec
    • Cybersecurity
    • Data Privacy
  • Opinion
    • Adam Balfour
    • Jim DeLoach
    • Mary Shirley
    • Yan Tougas
No Result
View All Result
Corporate Compliance Insights
Home Cybersecurity

Working With Human Nature to Build a Strong Security Culture

Unsuccessful Cybersecurity Measures Often Ask Too Much of Employees.

by Perry Carpenter
October 11, 2021
in Cybersecurity
Illustration of a professional with a maze for a brain.

Cybersecurity failures can happen to any company and anyone. But tactics that fight human nature increase the chances of failure. The best defense strategies meet employees where they are, measure outcomes, and update accordingly.

Sponsored

For beleaguered IT and security leaders, there’s some comfort in knowing that even the biggest and best companies fall prey to various hacking and data security attacks. But it’s a very fleeting sense of comfort that quickly fades to uncertainty. Microsoft, Facebook, LinkedIn, Twitter are just a few of the many companies impacted by significant security breaches. If it can happen to them, it can happen to any organization.

Every breach has a root cause. And despite the significant investments made in security-related technologies to prevent breaches, the root cause is less likely to be lack of such systems than it is to be people-related. People represent the greatest risk to data security for any organization—employees to be more precise.

And because employees represent up to 85% of data breach risk, it’s critically important for us all to understand how to work with—not against—human nature to build a strong security culture.

The core question then becomes: what are you doing to equip your employees to be effective agents from a security standpoint?

Putting a Focus on Human Nature

Here’s the thing – and it’s a point I emphasize every time I make a presentation or work with a security leader: If you try to work against human nature, you will fail. We humans are wired in very specific ways. And part of that wiring makes us averse to doing things that we feel are difficult, or awkward, or that require change.

Just giving people good security tools isn’t the answer. I’m sure that each of the companies mentioned earlier all gave their employees plenty of good security information. They were still breached.

Human behavior matters. Organizations need to understand how they can leverage some simple principles of human nature to help employees to habitually understand, care about and practice good security hygiene.

If your goal is to change the hearts, minds, beliefs, instincts, and behaviors of employees to join voluntarily in your efforts to protect your data and systems (and we’re sure it is), then you need to think broadly and incorporate practices from fields proven to impact human behavior: practices in the fields of marketing, public relations, communication theory, behavior, desire, culture management, and more.

Gain Clarity Around the Behaviors You Want to Encourage or Discourage

Changing human nature requires an absolutely clear understanding of exactly what behaviors you wish to change. Simply saying that you want to “build a strong security culture” won’t cut it. It doesn’t provide the clarity needed to help you begin to change actual behaviors. Instead, get clear on the exact behaviors you want people to do. Start by asking questions like these:

  • What precise behaviors, if adopted, would provide the most security benefits for your organization?
  • Is this a group of behaviors, or is this a single behavior?
  • Is this a behavior that you have the appetite to take on right now?
  • Is this a behavior that can be modeled and rewarded when observed?

Related: 7 Considerations When Launching a Security Awareness Training Program

Once you have clarity around the behaviors you wish to change, you need to think about whose behavior you wish to change and then take steps to understand these people so you can get the right message to the right person at the right time.

Get the Right Message to the Right Person at the Right Time

Everyone in your organization doesn’t need to receive the same messages at the same time. And yet, that’s what we tend to do when we communicate about security (and other) issues. We create an organization-wide memo, training session or policy and send it out to everyone. And then we consider our job done. Far from it.

Effective communication – communication that will actually impact human behavior – requires us to segment our audience, understand each of these segments (often accomplished through the creation of personas) and identify the appropriate communication channels for each of those segments.

Create Campaigns

Security awareness isn’t a one and done event; at least it shouldn’t be. Effective security awareness needs to be an ongoing campaign. Yet far too many organizations take an event approach to communicating about security awareness. They do it once or twice a year. But human nature isn’t impacted by once- or twice-a-year messages. Opinions and behaviors are swayed by hearing information over and over again, in different ways. Your marketing colleagues will attest to that; in fact, they can be a great source of support for helping you understand your audience segments and creating campaigns that will resonate with them.

Track and Measure Results

Just as security awareness communication needs to be ongoing to achieve desired results, so does monitoring and measuring the impacts of communication. You will want to understand to what extent your target audiences are exposed to your messaging; to what extent they are engaged with your messaging; and to what extent they are influenced by your messaging to do (or not do) whatever it is you’re asking of them.

Repeat

Effective security communication isn’t an event, it’s a process. That process needs to be repeated over and over again, with new iterations informed by the results you’re monitoring.

Again, these five steps are the broad strokes – the tip of the iceberg – when it comes to changing human behavior and shaping culture. But these broad steps should give you an idea of the framework within which you will develop and implement specific strategies and tactics, based on a solid understanding of human nature, to effect change over time.

Stop thinking that the technology fixes you have in place to protect your data systems are enough. They’re not. Just ask Microsoft, Facebook, LinkedIn, Twitter.

You need to put ‘people fixes’ in place if you want to build and maintain a strong security culture.

About KnowBe4

KnowBe4, the provider of the world’s largest security awareness training and simulated phishing platform, is used by more than 37,000 organizations around the globe. Founded by IT and data security specialist Stu Sjouwerman, KnowBe4 helps organizations address the human element of security by raising awareness about ransomware, CEO fraud and other social engineering tactics through a new-school approach to awareness training on security. Kevin Mitnick, an internationally recognized cybersecurity specialist and KnowBe4’s Chief Hacking Officer, helped design the KnowBe4 training based on his well-documented social engineering tactics. Tens of thousands of organizations rely on KnowBe4 to mobilize their end users as the last line of defense.

 


Tags: Cyber Risk
Previous Post

As WPP Grew, FCPA Violations Followed. Then Came SEC Enforcement.

Next Post

A Tale of Two Crises: What 2008 Foreclosures Can Teach Us About Attorney General Enforcement Following COVID-19

Perry Carpenter

Perry Carpenter

Perry Carpenter is an award-winning author, podcaster and speaker, with over two decades in cybersecurity focusing on how cybercriminals exploit human behavior. He is the chief human risk management strategist at KnowBe4. His latest book, “FAIK: A Practical Guide to Living in a World of Deepfakes, Disinformation and AI-Generated Deceptions” (2024 Wiley), explores AI's role in deception.

Related Posts

news roundup green bars

In-House Counsel Salary Increases Slow

by Staff and Wire Reports
May 2, 2025

Majority of execs predict rise in fincrime in ’25

data abstract green purple

66% of CISOs Worry Cyber Threats Are More Advanced Than Companies’ Defenses

by Staff and Wire Reports
April 25, 2025

US business sector falling behind in adoption of renewable energy

robot hand pointing to sky

Agentic AI Can Be Force Multiplier — for Criminals, Too

by Steve Durbin
April 21, 2025

How polymorphic malware and synthetic identities are creating unprecedented attack vectors

data abstract pixelated

GenAI Adoption Surging in Professional Services

by Staff and Wire Reports
April 18, 2025

Fewer than 1 in 3 organizations consistently meet cyber compliance standards

Next Post
real estate listings sit in a store front window.

A Tale of Two Crises: What 2008 Foreclosures Can Teach Us About Attorney General Enforcement Following COVID-19

No Result
View All Result

Privacy Policy | AI Policy

Founded in 2010, CCI is the web’s premier global independent news source for compliance, ethics, risk and information security. 

Got a news tip? Get in touch. Want a weekly round-up in your inbox? Sign up for free. No subscription fees, no paywalls. 

Follow Us

Browse Topics:

  • CCI Press
  • Compliance
  • Compliance Podcasts
  • Cybersecurity
  • Data Privacy
  • eBooks Published by CCI
  • Ethics
  • FCPA
  • Featured
  • Financial Services
  • Fraud
  • Governance
  • GRC Vendor News
  • HR Compliance
  • Internal Audit
  • Leadership and Career
  • On Demand Webinars
  • Opinion
  • Research
  • Resource Library
  • Risk
  • Uncategorized
  • Videos
  • Webinars
  • Well-Being
  • Whitepapers

© 2025 Corporate Compliance Insights

Welcome to CCI. This site uses cookies. Please click OK to accept. Privacy Policy
Cookie settingsACCEPT
Manage consent

Privacy Overview

This website uses cookies to improve your experience while you navigate through the website. Out of these, the cookies that are categorized as necessary are stored on your browser as they are essential for the working of basic functionalities of the website. We also use third-party cookies that help us analyze and understand how you use this website. These cookies will be stored in your browser only with your consent. You also have the option to opt-out of these cookies. But opting out of some of these cookies may affect your browsing experience.
Necessary
Always Enabled
Necessary cookies are absolutely essential for the website to function properly. These cookies ensure basic functionalities and security features of the website, anonymously.
CookieDurationDescription
cookielawinfo-checbox-analytics11 monthsThis cookie is set by GDPR Cookie Consent plugin. The cookie is used to store the user consent for the cookies in the category "Analytics".
cookielawinfo-checbox-functional11 monthsThe cookie is set by GDPR cookie consent to record the user consent for the cookies in the category "Functional".
cookielawinfo-checbox-others11 monthsThis cookie is set by GDPR Cookie Consent plugin. The cookie is used to store the user consent for the cookies in the category "Other.
cookielawinfo-checkbox-necessary11 monthsThis cookie is set by GDPR Cookie Consent plugin. The cookies is used to store the user consent for the cookies in the category "Necessary".
cookielawinfo-checkbox-performance11 monthsThis cookie is set by GDPR Cookie Consent plugin. The cookie is used to store the user consent for the cookies in the category "Performance".
viewed_cookie_policy11 monthsThe cookie is set by the GDPR Cookie Consent plugin and is used to store whether or not user has consented to the use of cookies. It does not store any personal data.
Functional
Functional cookies help to perform certain functionalities like sharing the content of the website on social media platforms, collect feedbacks, and other third-party features.
Performance
Performance cookies are used to understand and analyze the key performance indexes of the website which helps in delivering a better user experience for the visitors.
Analytics
Analytical cookies are used to understand how visitors interact with the website. These cookies help provide information on metrics the number of visitors, bounce rate, traffic source, etc.
Advertisement
Advertisement cookies are used to provide visitors with relevant ads and marketing campaigns. These cookies track visitors across websites and collect information to provide customized ads.
Others
Other uncategorized cookies are those that are being analyzed and have not been classified into a category as yet.
SAVE & ACCEPT
No Result
View All Result
  • Home
  • About
    • About CCI
    • CCI Magazine
    • Writing for CCI
    • Career Connection
    • NEW: CCI Press – Book Publishing
    • Advertise With Us
  • Explore Topics
    • See All Articles
    • Compliance
    • Ethics
    • Risk
    • FCPA
    • Governance
    • Fraud
    • Internal Audit
    • HR Compliance
    • Cybersecurity
    • Data Privacy
    • Financial Services
    • Well-Being at Work
    • Leadership and Career
    • Opinion
  • Vendor News
  • Library
    • Download Whitepapers & Reports
    • Download eBooks
    • New: Living Your Best Compliance Life by Mary Shirley
    • New: Ethics and Compliance for Humans by Adam Balfour
    • 2021: Raise Your Game, Not Your Voice by Lentini-Walker & Tschida
    • CCI Press & Compliance Bookshelf
  • Podcasts
    • Great Women in Compliance
    • Unless: The Podcast (Hemma Lomax)
  • Research
  • Webinars
  • Events
  • Subscribe

© 2025 Corporate Compliance Insights