Cultivating Security Culture

Explore top LinkedIn content from expert professionals.

  • View profile for Kevin Walker

    Helping schools and smaller organisations know what to fix first | Practical cyber security. Plain English. No scare tactics. | Founder, Black Swan Cyber Security Solutions

    2,243 followers

    39% of UK workers wouldn't report a cyber attack to their cyber security teams. The reason isn't lack of knowledge, (79% can identify attacks). It's psychology. A recent article by Craig Hale (TechRadar) reveals employees stay silent due to: ➡️ Fear of blame (17%) ➡️ Getting into trouble (17%) ➡️ Not wanting to cause a fuss (15%) ➡️ Preferring to "fix it themselves" (11%) IBM data shows this silence costs organisations an average of $2.03 MILLION more per breach. This connects to our earlier research on social engineering psychology. The same vulnerabilities that make us susceptible to attacks also prevent us from seeking help when we need it most. The solution isn't always better technology. It's psychological safety. Organisations with strong incident reporting cultures achieve: ✅ 58% lower breach costs ✅ 61-day faster incident resolution ✅ $1M savings from internal detection ✅ 75% reduction in successful cyber incidents Do your staff feel safe admitting mistakes? Building trust-based security cultures requires: ▶️ Framing incidents as learning opportunities, not failures ▶️ Leaders modelling vulnerability and admitting their own mistakes ▶️ Separating incident response from disciplinary processes ▶️ Celebrating reporters as security champions, not problems The human element shouldn't be seen or treated as your weakest link - it's your strongest defence when properly supported. What psychological barriers have you observed in cyber security incident reporting? Please share your experiences in the comments 👇 Read our full thoughts and analysis: https://lnkd.in/eEUNDjmc #Cybersecurity #PsychologicalSafety #IncidentResponse #Leadership #CyberResilience #SecurityCulture Source: Craig Hale, TechRadar - https://lnkd.in/ekG5xVBm

  • View profile for Alvin Rodrigues
    Alvin Rodrigues Alvin Rodrigues is an Influencer

    I help organisations turn their people into their strongest security asset | Cybersecurity Awareness Trainer | Keynote Speaker | Author | Human Firewall Builder and Behaviour Change Specialist

    10,715 followers

    Your Employees Know the Risks. That's Not the Problem. Most companies have a CISO. Very few have a cyber culture. There's a difference. A CISO can build controls. Write policies. Run phishing simulations. Tick the compliance boxes. What a CISO cannot do alone is change how 3,000 people think and behave every single day. That's not a security problem. That's a human behaviour problem. And human behaviour change is not a security skill. It's a people skill. Here's what the research actually points to. The CEO sets the tone. According to the UK's National Cyber Security Centre, if senior leaders ignore security policies or ask for special treatment, it signals to everyone else that bypassing them is acceptable. Culture flows from the top. Always. The CISO drives the strategy. Research from Commvault's SHIFT conference found that a strong security culture, where employees genuinely understand their role, delivers more value than adding tools or headcount. But that culture doesn't build itself. HR holds the keys to behaviour change at scale. UpGuard's research points directly to HR as the function best placed to build and monitor a cybersecurity programme across the organisation, working in partnership with the CISO. Not instead of. Alongside. And ENISA, the European Union Agency for Cybersecurity, is unambiguous. Without active, vocal support from the CEO or board, no cybersecurity culture programme will succeed. Full stop. But here's the uncomfortable truth most organisations still refuse to sit with. Awareness without action is not a safety net. It's a gap. And cyber criminals know exactly where to find it. Verizon's Data Breach Investigations Report has said it for years. The overwhelming majority of breaches involve a human element. Not because people don't know better. Because knowing and doing are two completely different things. That gap, between understanding the risk and actually changing behaviour, is precisely what attackers exploit. Time and time again. Across industries. Across geographies. Across company sizes. Training tells people what to do. Culture makes them do it without being told. Until organisations stop measuring awareness and start measuring behaviour, they will keep funding the same programmes and wondering why the breaches keep happening. The vulnerability isn't in the system. It's in the gap between knowing and doing. --- ♻️ Share this if it made you think twice. 🔔 Follow me for more on cybersecurity and human behaviour. Your people are not your weakest link. With the right habits, they become your first and last line of defence. I help people build the conviction and cyber habits that drive real protection against real threats. Curious about your risk exposure? Let's talk. No pitch, just a straight conversation. #AlvinSRatwork#AlvinSRCyberGuy#CyFiSafe#HumanFirewallBuilder ✦ #ExecutiveDirector#CyberCulture ✦ #CyberAwareness#BusinessTechnologist#CyberHabits

  • View profile for Volodymyr Semenyshyn
    Volodymyr Semenyshyn Volodymyr Semenyshyn is an Influencer

    President at SoftServe, PhD, Lecturer at MBA

    23,078 followers

    In the U.S. alone, cybercrime caused $16 billion in damages in 2024 - a 33% increase from the year before. And most of these breaches weren’t due to complex hacks or advanced malware. They happened because of simple human errors: misconfigured systems, unsecured devices, careless behavior, or being tricked by a convincing phishing email. That’s why the human factor is often the weakest link in cybersecurity, but also where the biggest gains can be made. So how do we build a human-centered security culture? It’s about shaping behavior and habits. A proven approach is Neidert’s Core Motives Model, which helps leaders guide employees toward secure behavior through three stages: 🔹 Connect – Build trust and rapport. People follow leaders they like and feel connected to. Gamified training sessions, team bonding, and small acts of reciprocity go a long way. 🔹 Reduce Uncertainty – Show credibility and social proof. When senior leaders take part in security efforts, or when teams see peers taking security seriously, they’re more likely to follow suit. 🔹 Inspire Action – Reinforce commitments. Use nudges, timely reminders, and even friendly competitions to encourage continuous attention to cybersecurity practices. A collective mindset where everyone feels responsible for protecting company assets, and each other. Security doesn’t live in IT alone. It lives in everyone’s daily choices.

  • View profile for Rajeev Mamidanna Patro

    Fixing what Tech founders miss out - Brand Strategy, Market Positioning & Unified Messaging | Build your foundation in 90 days

    7,882 followers

    Yesterday my daughter made an observation that’s relevant to all mid-market CISOs. While speaking to her on voice call, my father-in-law struggled to switch the WhatsApp call to video to show their dog’s antics. He asked my mother-in-law to help. While on the call, my mother-in-law needed to transfer money via UPI to someone. So they had to cut the call - because my father-in-law needed to step in! My daughter came to me with this question: Two people. Same house. Same everyday things. Yet their skill levels are so different. Now, imagine this inside a company with hundreds or thousands of employees. - Some struggle to identify phishing emails - Some don’t understand the risk of weak passwords - Some click on malicious links without a second thought - Some approve payment requests based on text messages - Some download & install unauthorized software - Some share sensitive information over email without realizing - Some upload company secrets into ChatGPT for projects Yet, many CISOs run just 𝙤𝙣𝙚 𝙤𝙧 𝙩𝙬𝙤 cyber awareness simulations per year & think it’s enough. It’s not. Cyber awareness needs to be continuous, personalized & measurable. A strong cyber awareness program should: 𝟭) 𝗧𝗲𝘀𝘁 𝗲𝗺𝗽𝗹𝗼𝘆𝗲𝗲𝘀 𝘄𝗶𝘁𝗵 𝗿𝗲𝗮𝗹-𝘄𝗼𝗿𝗹𝗱 𝗮𝘁𝘁𝗮𝗰𝗸 𝘀𝗰𝗲𝗻𝗮𝗿𝗶𝗼𝘀 Phishing, smishing, vishing, and deepfake attacks that mimic what attackers actually do. 𝟮) 𝗔𝗱𝗮𝗽𝘁 𝘁𝗿𝗮𝗶𝗻𝗶𝗻𝗴 𝗯𝗮𝘀𝗲𝗱 𝗼𝗻 𝗶𝗻𝗱𝗶𝘃𝗶𝗱𝘂𝗮𝗹 𝘀𝗸𝗶𝗹𝗹 𝗹𝗲𝘃𝗲𝗹𝘀 A finance executive needs different training than a new intern. 𝟯) 𝗢𝗳𝗳𝗲𝗿 𝗲𝗻𝗴𝗮𝗴𝗶𝗻𝗴, 𝗶𝗻𝘁𝗲𝗿𝗮𝗰𝘁𝗶𝘃𝗲 𝘁𝗿𝗮𝗶𝗻𝗶𝗻𝗴 Gamification, role-based training, and bite-sized learning improve retention. 𝟰) 𝗧𝗿𝗮𝗰𝗸 𝗶𝗺𝗽𝗿𝗼𝘃𝗲𝗺𝗲𝗻𝘁𝘀 & 𝗿𝗶𝘀𝗸𝘆 𝗯𝗲𝗵𝗮𝘃𝗶𝗼𝗿 Identify employees who need extra training instead of treating everyone the same. 𝟱) 𝗥𝘂𝗻 𝗰𝗼𝗻𝘁𝗶𝗻𝘂𝗼𝘂𝘀 𝘀𝗶𝗺𝘂𝗹𝗮𝘁𝗶𝗼𝗻𝘀, 𝗻𝗼𝘁 𝗼𝗻𝗲-𝘁𝗶𝗺𝗲 𝗲𝘃𝗲𝗻𝘁𝘀 Cyber threats evolve daily; training should too. 𝟲) 𝗚𝗶𝘃𝗲 𝘁𝗵𝗲 𝗰𝘆𝗯𝗲𝗿 𝗮𝘄𝗮𝗿𝗲𝗻𝗲𝘀𝘀 𝗽𝗼𝘀𝘁𝘂𝗿𝗲 𝗮𝘁 𝘁𝗵𝗲 𝗰𝗹𝗶𝗰𝗸 𝗼𝗳 𝗮 𝗯𝘂𝘁𝘁𝗼𝗻 Department-wise reports of people & the potential learning gaps Awareness is not running a simulation & calling it a day. It's the actions & the next steps: - for improvement - knowing the awareness posture of everyone - for building a culture where employees become security assets If you’re a CISO evaluating solutions that train employees further based on their actual responses, DM me. My team works with a platform designed to make cyber awareness practical, engaging & effective. -- Hi, I’m Rajeev Mamidanna. I help mid-market CISOs strengthen their Cyber Immunity.

  • View profile for AJ Yawn

    GRC Engineering at Rippling | Advisor | Author | Founder of GRC Engineering Club on Patreon | Veteran | LinkedIn Learning Instructor | SANS Instructor | Mental Health Advocate | The Work, Works |

    53,650 followers

    Risk culture is not a poster in the break room. It is the difference between an engineer flagging a near-miss in Slack and an engineer hoping nobody noticed. Culture is built in those small decisions, not in the annual training video. Three shifts that move the needle: - Policing to partnering. When business units see GRC as a help, not a tax, they start engaging early. - Blame to learning. If a near-miss report leads to punishment, the reports stop. Psychological safety is the multiplier. - Annual to continuous. Once-a-year training is theater. Embed risk in team meetings, project kickoffs, and post-incident reviews. - Risk champions in every department, not just on the GRC org chart. - Storytelling from leadership about real incidents prevented, not hypothetical ones avoided. Plan for 12 to 18 months minimum. Measure engagement, not compliance. A risk-aware culture is what your program looks like the day you stop being in the meeting. #GRCEngineering

  • View profile for Lora Vaughn

    Fractional CISO for Community Banks, Fintech & SaaS | Post-Incident Advisory | 2x CISO | FFIEC, GLBA, SOC 2, PCI | Speaker

    11,876 followers

    This is how you handle a security incident 👏 Sophos just published a detailed analysis of how one of their senior employees fell for a phishing attack that bypassed MFA. But here's what impressed me most: ✅Transparency:They didn't hide it. They published a full root cause analysis for everyone to learn from. ✅Culture: The employee immediately reported they'd been phished. No fear, no shame, no trying to hide it. ✅Mindset: Quote from their post: "We don't reprimand or discipline users who click on phishing links... we try to foster a culture in which the predominant focus is solving the problem and making things safe, rather than apportioning blame." This is exactly right. Anyone can fall for a well-crafted phish given the right circumstances. The difference between a minor incident and a catastrophic breach often comes down to: ❓Will people report when something feels wrong?❓ If your employees are afraid of getting in trouble for clicking a suspicious link, they won't tell you. They'll hope it goes away. That's when small problems become big problems. Sophos contained the threat because: • Their employee felt safe reporting the incident immediately • Their controls worked in layers • Their teams cooperated without blame • They learned and improved afterward More companies should follow this model: psychological safety + defense in depth + continuous learning. Great writeup, Sophos. The security community is stronger when we share our failures AND our lessons. Link: https://lnkd.in/eSN4xPBc What's the best example you've seen of positive security culture in action? #CyberSecurity #IncidentResponse #SecurityCulture #Transparency #Sophos

  • View profile for Nur Imroatun Sholihat

    Learning IT and auditing? Let’s do it together

    8,651 followers

    One of the most dangerous cybersecurity risks is not always the newest attack technique. Sometimes, it is the accumulation of small decisions we keep postponing. Recently, I read ISACA’s publication “Security Debt: The Unseen Risk Undermining Cyber Resilience.” And one idea stayed in my mind: Security debt is often created with “good intentions”. Move faster, deliver quicker, stretch limited resources, or meet deadlines. Those are normal in our professional life, right? But over time, deferred fixes, outdated systems, weak governance, and ignored vulnerabilities compound into something much bigger. Just like financial debt, security debt charges “interest.” The longer organizations delay addressing it, the more expensive, complex, and disruptive it becomes. What makes this topic important is that security debt is not purely a technical issue. It is also a leadership, governance, prioritization, or even a cultural issue. Many organizations already know their vulnerabilities. The real challenge is often unclear ownership, recurring exceptions, siloed monitoring, delayed remediation, and treating cybersecurity as “someone else’s responsibility.” Some actionable reflections I think organizations can start applying today: 1. Treat security debt like business debt → Track it formally in risk registers, governance forums, and leadership discussions. If it impacts resilience, operations, trust, or compliance, it deserves executive visibility. 2. Focus on patterns, not isolated findings → Recurring audit findings, repeated vulnerabilities, and long-open exceptions often signal systemic issues rather than individual mistakes. 3. Prioritize based on business impact → Not every vulnerability carries the same risk. Focus on systems tied to critical operations, customer trust, and regulatory exposure. 4. Reduce “invisible risk” → Shadow IT, unmanaged integrations, and AI tools without governance are becoming major contributors to modern security debt. 5. Build a culture of shared accountability → Cybersecurity maturity improves when security is treated as everyone’s responsibility, not only the security team’s job. Reference: Security Debt: The Unseen Risk Undermining Cyber Resilience White Paper (ISACA, 2026) #ITaudit #internalaudit #digitaltransformation

  • View profile for Gayle Lantz
    Gayle Lantz Gayle Lantz is an Influencer

    Founder - WorkMatters.com | Executive Advisor | Podcast Host of CEO on the Go | Reinvention Practitioner | Keynote Speaker

    6,693 followers

    I've witnessed firsthand how cyberattacks and ransomware incidents have disrupted my clients' organizations. The impact is real, costly, chaotic--and can bring business operations to a standstill. Cybersecurity might not be your expertise, but as a leader, it needs to be on your radar. That's why I wanted to bring this topic into the spotlight in a way that's accessible to leaders without technical backgrounds. I enjoyed speaking with Mary D'Angelo, Cyber Threat Intelligence Solutions Lead at Filigran. What's most impressive about Mary's approach is her emphasis on the need for a top-down cultural shift to make cyber intelligence work--it's not just “an IT issue.” ⭐️A key takeaway:  One of the most important acts a leader can do is help people feel comfortable enough to share when they realize they may have inadvertently done something that could put the business at risk. This episode isn't a deep technical dive. It’s designed to be a helpful primer for leaders who want to get smarter about cyber risks without feeling overwhelmed. We cover: ✅The fundamentals of cyber threat intelligence (CTI) ✅Why social engineering is the biggest threat across all industries  ✅How to create a "culture of cyber psychological safety"  ✅The importance of embedding cyber intelligence across your organization  ✅Practical first steps leaders can take immediately to better protect their organizations Whether you're leading a company, managing a team, or just trying to stay one step ahead, this episode will help you understand what CTI is, why it matters, and how it can help you make smarter, safer decisions. ***What's been YOUR experience when it comes to cyber threats? *** Any lesson learned? Feel free to share.👇 Enjoy the conversation! Find link to the episode in the comments below. #leadership #Cybersecurity #cyberthreats #intelligence #CEOontheGoPodcast

  • View profile for David Samuel

    Co-Founder / CEO | AI-Hyperautomated Modular Cybersecurity @ Peris.ai

    3,186 followers

    In the blink of an eye, what you hold sacred can be breached. 💔 Imagine this: You’re a leader at a financial institution and in one click, a decade of customer trust evaporates. A cyber-attack doesn’t just hit your systems; it shatters confidence, relationships, and your bottom line. Cybersecurity isn't just about firewalls and passwords. It’s about culture. 🛡️ It’s about realizing that the most sophisticated technology can fail if a single employee clicks on a malicious link. Today, let’s not talk about tools. Let’s talk about people. Your team. The beating heart of your organization. 🏢🧡 - Empower your staff with knowledge. Regular training isn't just good practice; it's a lifeline. - Foster a culture of vigilance. Phishing scams evolve daily. Staying ahead means staying aware. - Celebrate the wins. When someone reports a potential threat, make it a teachable moment for all. Cyber threats are the modern Pandora's box – once opened, they can wreak havoc. But unlike the myth, we have the power to close the lid. 📦💪 Leaders, let's shift focus from fear to empowerment. Investing in a cybersecurity-aware culture isn't an option; it's a necessity. This is about safeguarding more than data; it's about protecting our future. Share your experiences, encourage dialogue, and let’s strengthen our defenses through unity and knowledge. Because when it comes to cyber threats, education is just as powerful as encryption. #CyberSecurity #Leadership #RiskManagement #InformationSecurity #CorporateCulture

  • View profile for Michael Collins

    Cyber Cognition® I help people and businesses think better about cyber security with systems thinking #cybercognition

    4,026 followers

    💡 The CISO's 2025 Challenge: Why Systems Trump Checklists Every few months, I see another "CISO priorities for 2025" list making the rounds. They all highlight important areas, but most miss what I've consistently observed building security programs at a number of financial institutions: checklists don't keep you safe, understanding systems does. 😕 The Problem: Security By Checklist Doesn't Work When security teams focus solely on ticking boxes without understanding connections between controls, people, and processes, they create: - Siloed security measures that fail when threats cross boundaries - Conflicting priorities between security and business objectives - Solutions that look perfect on paper but collapse under real-world pressure - Resource waste on controls that don't address your specific risk landscape 🧐 The Solution: Apply Systems Thinking to Your Security Program The difference between security programs that thrive versus merely survive comes down to understanding these systemic connections: • **Security direction** must align with and support business vision, not compete with it • **Risk management** needs to recognise feedback loops and dynamic threats, not just static point-in-time assessments • **Basic controls** require coordination across environments, they don't work in isolation • **Incident response** effectiveness depends on strong relationships across organisational boundaries • **Board communications** succeed when built on shared mental models between security and leadership • **Compliance** delivers value when integrated into processes, not layered on top • **Security culture** emerges from system interactions and relationships, not mandates • **Vendor management** treats suppliers as extensions of your security system, not isolated entities • **Future planning** focuses on adaptability and sensing capabilities, not rigid roadmaps • **Delegation** builds interconnected networks of responsibility, not isolated task assignments 💎 The Benefits: Real-World Security That Actually Works When you approach security through a systems lens, you can: - Identify previously hidden relationships between vulnerabilities - Anticipate cascading failures before they happen - Align security initiatives with business objectives to gain executive support - Build resilience that adapts to changing threats - Create more efficient programs that don't waste resources on ineffective controls I've applied these principles when scaling security programs, and the difference is clear: organisations that understand and leverage these connections consistently outperform those treating security as a checklist exercise. What connections or patterns have been critical in your own experience? 👇 I'm always keen to hear how other leaders are thinking systemically about security. #cybercognition #systemsthinking #ciso #vmcl #cybersecurity

Explore categories