MY WORK / CYBER AWARENESS

How to Build a Strong Security Awareness Culture Across Your Workforce

A practical guide to building a security awareness culture where employees understand risk, report concerns early, reinforce secure behaviour and see cyber security as part of everyday work rather than an annual compliance exercise.

Quick answer: A strong security awareness culture is created when secure behaviour is relevant to people’s real work, reinforced continuously, supported by leaders and managers, and made psychologically safe enough that employees report mistakes and suspicious activity early. Training matters, but culture is built through repeated behaviours, conversations, feedback and trust.

Cyber awareness and workforce collaboration image

What is a security awareness culture?

A security awareness culture is the shared set of behaviours, expectations and habits that shape how people recognise, discuss and respond to cyber risk. It goes beyond completing annual training. In a healthy culture, employees understand why security matters, know what secure behaviour looks like in their role, feel comfortable asking questions and report mistakes or suspicious activity early.

Security awareness training is an activity. Security awareness culture is the environment that makes secure behaviour normal. Training can introduce knowledge, but culture is reinforced through leadership behaviour, manager conversations, role-specific examples, simple reporting routes and repeated feedback.

Six pillars of a strong security awareness culture

  1. Relevance: connect security to the work people actually do and the risks they personally encounter.
  2. Repetition: reinforce behaviour continuously instead of relying on one annual module.
  3. Psychological safety: make it safe to admit uncertainty, report mistakes and ask for help quickly.
  4. Leadership visibility: managers and executives should model the same secure behaviours expected from everyone else.
  5. Role-based context: finance, HR, engineering, sales and leaders should see scenarios relevant to their responsibilities.
  6. Feedback loops: use incidents, questions, phishing reports and recurring mistakes to decide what to teach next.

My favourite aspect of cyber security is the human element in cyber security because an increase in cyber awareness culture pays the highest dividends over time, in comparison to any technical control. When embarking on a cyber awareness journey with employees, we are in a unique but advantageous position since employees can use what they learn both at work and at home.

Covid-19 greatly blurred the lines between home and work as now many employees regularly work away from corporate buildings and internet connections in their chosen environment. This presents new challenges but also opportunities as we can simultaneously push people-focused cyber security for the home and the office as a result.

Despite this, building a cyber awareness culture within your workforce can be challenging. Employees may resist security messages when they do not understand what is in it for them or when security feels disconnected from their daily work. So, how do we make cyber security relevant enough that people want to engage with it?

Security awareness culture becomes stronger when the message matters outside work too

Social engineering attacks gathered great momentum during the pandemic, both at work and at home. Social Engineering is an online and offline technique used to trick users into compromising their security, divulging sensitive information or parting with funds. For example, phishing, impersonation of a person or company, or pharming with the aim of obtaining sensitive information.

Many employees were busy balancing work with home schooling responsibilities which naturally meant many of our guards were down. There was a huge uptick in phishing scams related to accounts such as Disney+, Netflix and Amazon.

Why this matters: Cyber awareness becomes much easier to “sell” when employees see that the same knowledge protects their finances, accounts, devices, and families outside of work too.

Use real social engineering threats to build security awareness culture

During this time, I increased the number of phishing simulations at work sent via email to employees with the intent of demonstrating how easy it was to click, following up with phishing-specific training and weekly newsletters showing case studies of similar phishing attacks mainly related to accounts.

By making it related to accounts that many employees had it really drove the point home that social engineering is everywhere and they must be vigilant. This was effective in engaging employees with the cyber awareness programme at the company and increasing participation, many employees completed training modules alongside their families as they understood exactly how it could help them out away from work.

More importantly, it built a culture where employees felt comfortable approaching the cyber security team with anything they were unsure of which brought about many insightful conversations but crucially, built trust. By cultivating a culture of education, staff felt comfortable admitting mistakes made like clicking on links or engaging with phishing emails, which allows us to investigate rather than be painfully unaware.

For more examples of social engineering attacks, see IT Governance and Terranova Security.

What changes when security awareness culture is working?

A stronger culture shows up in everyday behaviour. Employees are more likely to pause before acting on suspicious requests, ask questions earlier, report incidents faster and involve security sooner in projects or technology decisions.

  • People report suspicious emails and requests instead of silently deleting them.
  • Employees feel safe admitting when they clicked a link or made a mistake.
  • Managers reinforce secure behaviours during normal team conversations.
  • Higher-risk teams receive examples connected to their real workflows.
  • Security is invited earlier into projects instead of being treated as a final approval gate.
  • Lessons from incidents and near misses become future training material.

Turn security awareness into workforce capability

Cyber security should be an enabling function for departments across an organisation but over time I have found that many project leads and managers perceive cyber security as “ red tape” that delays their plans, especially when taking on new technology. For this, I like to approach this with a people development focus aiming to build a security capability away from the main security team.

How do you do this? Speak to people. Build relationships where you help people understand cyber security’s benefits and how critical it is. For example, if cyber security experts are not involved in the start of software design then the go live date could be delayed. Or from a legal standpoint if clients are told that their data is stored on premise and not in the cloud, deviation from this could have legal implications.

Understand who could have a natural interest in cybersecurity, there’s usually at least one person who is itching to try something new and broaden their existing skill set. Before going out to market, understand who in the organisation may be interested in trying an entry level cyber security course. To generate interest, consider hosting internal events where you showcase the work of the security team, people from other business functions are always curious to learn about something new and it goes very far in building a rapport.

Hiring internally is almost ALWAYS a better idea as the employee understands the context far better than a new hire. Internal cyber security hiring also has the added benefit of leveraging existing relationships within the organisation. This also has the unintended consequence of sometimes reigniting their passion for the organisation as things become new and varied again, making them less likely to look elsewhere for a new challenge.

Over the years, I’ve found that people have been the best when it comes to evangelising cyber security and as a cyber security consultant, I have found that when I’m able to connect with people I’ve been the most successful in executing my role. People make up the business, more times than not provide the best insights beyond any technical control has ever.

Talk to your people, nurture your people, retain your people.

How to measure security awareness culture

Completion rates are useful for governance, but they do not tell you whether culture is changing. A better measurement approach combines training evidence with behavioural signals and feedback from the workforce.

Useful security awareness culture signals

  • Reporting rate: whether employees are escalating suspicious activity.
  • Time to report: how quickly concerns are raised after a suspicious event.
  • Repeat mistakes: where the same risky behaviour continues after reinforcement.
  • Quality of questions: whether employees are asking more specific, contextual security questions.
  • Role coverage: whether higher-risk teams receive relevant awareness activity.
  • Manager participation: whether leaders reinforce security in team meetings and operational routines.
  • Security involvement: whether teams bring security into projects earlier.

How to improve security awareness culture in practice

  1. Start with real behaviour: identify the risky decisions, incidents and near misses you want to change.
  2. Make the message relevant: connect cyber security to people’s work, finances, accounts, devices and home life where appropriate.
  3. Segment by role: adapt scenarios for finance, HR, engineering, customer-facing teams and leaders.
  4. Keep security visible: use short, repeated communications rather than one-off campaigns.
  5. Make reporting easy: reduce friction and make it safe to report uncertainty or mistakes.
  6. Use feedback: turn recurring questions and incidents into the next awareness activity.
  7. Build internal advocates: identify people outside the security team who are interested in helping reinforce good practice.

Security awareness culture FAQs

What is security awareness culture?

Security awareness culture is the shared set of behaviours, expectations and habits that influence how employees recognise and respond to cyber risk. It includes training, but also leadership behaviour, reporting confidence, role-specific reinforcement and everyday decision-making.

How is security awareness culture different from security awareness training?

Training is one method used to teach knowledge or reinforce behaviour. Culture is broader: it reflects what employees actually do, what leaders model, how teams talk about risk and whether people feel able to report mistakes or concerns early.

How do you build a strong security awareness culture?

Start with the behaviours you want to change, make the message relevant to real work, reinforce it continuously, adapt scenarios by role, make reporting safe and simple, involve managers and use incidents or questions as feedback for future activity.

How do you measure security awareness culture?

Use completion data alongside behavioural indicators such as reporting rate, time to report, repeat mistakes, role coverage, manager participation, quality of questions and whether security is involved earlier in business decisions.

Who owns security awareness culture?

Security may coordinate the programme, but culture is shared across the organisation. HR, communications, managers, senior leaders and employees all influence whether secure behaviour becomes normal.

Why is psychological safety important for cyber security culture?

Employees are more likely to report suspicious activity or mistakes quickly when they do not expect blame or embarrassment. Earlier reporting gives security teams a better chance to investigate and reduce impact.

Build a stronger security awareness culture.

Explore practical frameworks, workshops and resources for building security awareness, role-specific behaviour and stronger cyber culture across the workforce.